Alarm studying and judging method, device and equipment for network security, medium and program product
By combining multi-strategy processing with rule analysis, algorithm analysis and semantic analysis, the problems of low accuracy and coverage of network security alarm events are solved, and efficient alarm event handling is achieved.
Patent Information
- Application Number
- CN202410486768.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-22
- Publication Date
- 2025-10-24
AI Technical Summary
In the existing technology, the accuracy and coverage of network security alarm events are low, making it difficult for operation and maintenance personnel to handle alarm events quickly and accurately.
By obtaining the alarm category of the network security alarm event, determining the target analysis strategy, and combining multiple strategies (rule analysis, algorithm analysis, and semantic analysis) for processing, we can obtain the target analysis results and ensure that each alarm event is analyzed using an adapted strategy.
It improves the accuracy and coverage of network security alarm analysis and judgment, and improves the efficiency of operation and maintenance personnel in handling alarm incidents.
Smart Images

Figure CN120834933A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to methods, devices, equipment, media, and program products for analyzing and judging network security alarms. Background Art
[0002] With the continuous development of network technology, data transmission over the network is becoming more and more frequent, so maintaining network security is particularly important. By deploying network or terminal protection equipment on the Internet, users can promptly detect abnormal or harmful network data transmission over the network, so that operation and maintenance personnel can immediately interrupt, adjust or isolate the detected abnormal or harmful transmission behavior to ensure the security of data transmission.
[0003] Currently, network or terminal protection devices and terminals that need to be protected are deployed in the network. The network or terminal protection devices can detect that the protected terminal is attacked, and generate corresponding alarm events when the protected terminal is attacked. The alarm events are sent to the analysis and judgment platform, so that the analysis and judgment platform can judge the alarm events according to pre-established rules, so that the operation and maintenance personnel can determine whether the attack behavior indicated by the alarm event generated by the network or terminal protection device is valid, so that the operation and maintenance personnel can quickly and accurately handle the alarm events.
[0004] In related technologies, operations and maintenance personnel can pre-set fixed rules and use them to analyze and assess alarm events to determine if they are valid. However, this rule-based approach to analyzing alarm events cannot cover all alarm events. Sometimes, the attack behavior indicated by an alarm event is not recorded by the rules, resulting in low accuracy and coverage of alarm event analysis. Summary of the Invention
[0005] The embodiments of the present application provide a network security alarm analysis method, device, equipment, medium and program product, which ensure the accuracy and coverage of the analysis of alarm events, thereby improving the efficiency of network security alarm analysis.
[0006] In the first aspect, the present application provides a network security alarm analysis method, the method comprising: obtaining a network security alarm event; the alarm event includes an alarm category to which the network security anomaly belongs, and the alarm category is used to indicate at least one attack method against the network security; determining a target analysis strategy corresponding to the alarm event; wherein, if the alarm category meets the preset alarm category, the target analysis strategy is the analysis strategy corresponding to the preset alarm category; if the alarm category does not meet the preset alarm category, the target analysis strategy includes at least two analysis strategies; according to the target analysis strategy, the alarm event is processed to obtain a target analysis result, and the target analysis result is used to indicate whether the alarm event is established.
[0007] It can be understood that after obtaining the alarm event of network security, since the alarm event includes the alarm category corresponding to the attack mode generating the alarm, the target research and judgment strategy corresponding to the alarm event can be determined according to the alarm event. If the alarm category matches the preset alarm category, the research and judgment strategy corresponding to the preset alarm category can be determined as the target research and judgment strategy. If the alarm category does not match the preset alarm category, at least two research and judgment strategies can be used as the target research and judgment strategy. Then, the alarm event is processed according to the target research and judgment strategy to obtain a target research and judgment result, so that each alarm event can use a research and judgment strategy suitable for it, the accuracy of research and judgment on the alarm event is ensured as much as possible, and the efficiency of alarm research and judgment on network security is improved.
[0008] In a possible implementation, processing the alarm event according to the target research and judgment strategy to obtain a target research and judgment result includes: if the alarm category corresponding to the alarm event does not match the preset alarm category, the alarm event is researched and judged according to at least two research and judgment strategies respectively to obtain at least two research and judgment results respectively corresponding to the at least two research and judgment strategies; and the target research and judgment result is determined according to the at least two research and judgment results respectively corresponding to the at least two research and judgment strategies.
[0009] It can be understood that by researching and judging the alarm event according to at least two research and judgment strategies respectively and combining the research and judgment results to obtain the target research and judgment result, the accuracy of research and judgment on the alarm event can be ensured.
[0010] In a possible implementation, if the research and judgment result is used to indicate the probability that the alarm event is established, and the target research and judgment result is determined according to the at least two research and judgment results respectively corresponding to the at least two research and judgment strategies, the method includes: obtaining weights respectively corresponding to the at least two research and judgment strategies; and performing weighted summation average calculation on the at least two research and judgment results respectively corresponding to the at least two research and judgment strategies according to the weights to obtain the target research and judgment result, where the target research and judgment result indicates that the alarm event is not established when a probability corresponding to the target research and judgment result is less than a specified threshold, and the target research and judgment result indicates that the alarm event is established when the probability corresponding to the target research and judgment result is greater than or equal to the specified threshold.
[0011] It can be understood that the weighted summation average calculation is used to combine each research and judgment result into the target research and judgment result, so that the accuracy of research and judgment on the alarm event can be ensured.
[0012] In a possible implementation, processing the alarm event according to the target research and judgment strategy to obtain a target research and judgment result includes: if the alarm category corresponding to the alarm event matches the preset alarm category, the alarm event is researched and judged according to the research and judgment strategy corresponding to the preset alarm category to obtain the target research and judgment result.
[0013] In a possible implementation, the target research and judgment strategy corresponding to the alarm event is determined, including: in the case that the preset alarm category is not set, each research and judgment strategy is determined as the target research and judgment strategy.
[0014] In a possible implementation, if the target research and judgment strategy includes a rule research and judgment strategy, the alarm event is processed according to the target research and judgment strategy, including: the alarm event is compared with preset rule content; in the case that the alarm event is consistent with the preset rule content, the research and judgment result of the alarm event under the rule research and judgment strategy is determined as the research and judgment result corresponding to the preset rule content.
[0015] In a possible implementation, if the target research and judgment strategy includes an algorithm research and judgment strategy, the alarm event is processed according to the target research and judgment strategy, including: feature information is obtained by performing feature extraction on the alarm event; the feature information is input into the target algorithm, and the alarm event is clustered or classified to obtain the research and judgment result of the alarm event under the algorithm research and judgment strategy; wherein the feature information includes source IP information of the alarm, http protocol information of the alarm, information of the alarm name, the number of alarms generated by the same source IP in a specified period, the number of alarms generated by the same destination IP in a specified period, the number of alarm categories generated by the same source IP in a specified period, the number of alarm categories generated by the same destination IP in a specified period, the number of alarms of the same alarm category and capable of triggering blocking in a specified period, the number of alarms triggered by the same traffic, the number of alarm categories triggered by the same traffic, the number of protection devices accessed by the same destination IP, and the number of protection devices accessed by the same source IP.
[0016] In a possible implementation, if the target research and judgment strategy includes a semantic research and judgment strategy, the alarm event is processed according to the target research and judgment strategy, including: the keyword of the alarm event is obtained by performing keyword extraction on the alarm event; the keyword is input into a neural network model, and the keyword is analyzed by the neural network model to obtain the research and judgment result of the alarm event under the semantic research and judgment strategy.
[0017] In a possible implementation, before the target research and judgment strategy corresponding to the alarm event is determined, the method further includes: semantic information in the preset rule content is extracted, the semantic information includes feature information and keywords; the target algorithm and the neural network model are updated according to the semantic information to obtain an updated algorithm research and judgment strategy and an updated semantic research and judgment strategy.
[0018] In a possible implementation, the alarm event is processed according to the target research and judgment strategy to obtain a target research and judgment result, including: if the alarm category of the alarm event does not conform to the preset alarm category of the algorithm research and judgment strategy and the preset alarm category of the semantic research and judgment strategy, the alarm event is processed according to the updated algorithm research and judgment strategy and the updated semantic research and judgment strategy respectively to obtain the target research and judgment result.
[0019] In a second aspect, the embodiments of the present application provide an alarm research and judgment device for network security, which is used to execute the alarm research and judgment method for network security provided in the first aspect.
[0020] In a possible implementation, the embodiments of the present application can divide the alarm research and judgment device for network security into functional modules according to the method provided in the first aspect. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. For example, the alarm research and judgment device for network security can be divided into an acquisition module, a processing module, and a research and judgment module according to functions. The possible technical solutions and beneficial effects of each functional module described above can be referred to the technical solutions provided in the first aspect or the corresponding possible implementation of the first aspect, which will not be described here.
[0021] In a third aspect, the embodiments of the present application provide a computing device, which includes a processor and a memory, and the processor is coupled to the memory. The memory is used to store computer instructions, which are loaded and executed by the processor to enable the computing device to implement the alarm research and judgment method for network security as described in the above aspects.
[0022] In a fourth aspect, the embodiments of the present application provide a computing device cluster, which includes at least one computing device. Each computing device includes a processor and a memory. The processor of the at least one computing device is used to execute the instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the alarm research and judgment method for network security provided in the various optional implementation of the first aspect.
[0023] In a fifth aspect, the embodiments of the present application provide a computer readable storage medium, which stores at least one computer program instruction. The computer program instruction is loaded and executed by a processor to implement the alarm research and judgment method for network security as described in the above aspects.
[0024] In a sixth aspect, an embodiment of the present application provides a computer program product, which comprises computer instructions stored in a computer readable storage medium. A processor of a computing device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to enable the computing device cluster to perform the network security alarm judgment method provided in various optional implementation manners of the first aspect.
[0025] The specific description of the second aspect to the sixth aspect and various implementation manners thereof in the present application can refer to the detailed description in the first aspect and various implementation manners thereof, and the beneficial effects of the second aspect to the sixth aspect and various implementation manners thereof can refer to the beneficial effect analysis in the first aspect and various implementation manners thereof, which will not be described herein again.
[0026] These aspects or other aspects of the present application will be more apparent in the following description. BRIEF DESCRIPTION OF DRAWINGS
[0027] Figure 1 is a scene diagram of attack alarm generation and judgment under IDS monitoring according to an exemplary embodiment;
[0028] Figure 2 is a scene diagram of attack alarm generation and judgment under IPS monitoring according to an exemplary embodiment;
[0029] Figure 3 is a scene diagram of attack alarm generation and judgment under terminal protection device monitoring according to an exemplary embodiment;
[0030] Figure 4 is a schematic diagram of an alarm judgment system according to an exemplary embodiment;
[0031] Figure 5 is a schematic diagram of a hardware structure of a computing device according to an exemplary embodiment;
[0032] Figure 6 is a flowchart of a network security alarm judgment method according to an exemplary embodiment;
[0033] Figure 7 is Figure 6 is a flowchart of an algorithm judgment strategy and a semantic judgment strategy updating process involved in the embodiment shown in the figure;
[0034] Figure 8 is Figure 6 is a flowchart of a multi-judgment strategy cooperative judgment process involved in the embodiment shown in the figure;
[0035] Figure 9 is Figure 6A flowchart of a multi-item research and judgment strategy cooperative research and judgment involved in the embodiment shown;
[0036] Figure 10 Figure 6 A flowchart of a multi-item research and judgment strategy cooperative research and judgment involved in the embodiment shown;
[0037] Figure 11 A structural diagram of an alarm research and judgment device for network security according to an exemplary embodiment;
[0038] Figure 12 A schematic diagram of a computing device according to an exemplary embodiment;
[0039] Figure 13 A schematic diagram of a computing device cluster according to an exemplary embodiment;
[0040] Figure 14 A schematic diagram of a connection mode between computing device clusters according to an exemplary embodiment. DETAILED DESCRIPTION
[0041] In order to make the purpose, technical scheme and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the drawings.
[0042] In this paper, "a plurality of" refers to two or more. "And / or" describes the association between the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean: A exists alone, A and B exist together, and B exists alone. The character " / " generally represents that the associated objects before and after are a "or" relationship.
[0043] Also, in the description of the present application, unless otherwise specified, "a plurality of" means two or more. "At least one of the following" or its similar expression means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b, or c can mean: a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, c can be single or multiple.
[0044] In addition, in order to facilitate clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the terms "first", "second", etc. are used to distinguish the same or similar items with basically the same function and role. Those skilled in the art can understand that the terms "first", "second", etc. do not limit the quantity and execution order, and the terms "first", "second", etc. also do not necessarily mean different. Meanwhile, in the embodiments of the present application, the words "exemplary" or "for example" are used to represent as an example, illustration or explanation. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the words "exemplary" or "for example" are intended to present the relevant concept in a specific manner for understanding.
[0045] First, the application scenarios of the embodiments of the present application are exemplarily introduced.
[0046] In the Internet, a protection device for maintaining network security can be deployed, and the protection device for maintaining network security can include a boundary protection device and a terminal protection device. The boundary protection device can include, but is not limited to, a firewall, an intrusion detection system (IDS), an intrusion prevention system (IPS), and a web application firewall (WAF). The terminal protection device can include, but is not limited to, an endpoint detection and response (EDR) and a runtime application self-protection (RASP).
[0047] IDS is a network security device that monitors network transmission in real time and issues an alarm or takes proactive response measures when suspicious transmission is found. IPS is a network security device that can interrupt, adjust or isolate some abnormal or harmful network data transmission behavior in real time on the basis of IDS. WAF is a website application level intrusion prevention system, which is a product specially designed for website application protection by executing a series of security policies for hypertext transfer protocol (HTTP) or hypertext transfer protocol over secure socket layer (HTTPS). EDR is an endpoint security protection solution, which can record the behavior on the endpoint, detect anomalies and malicious activities using data analysis and context-based information, and record data about malicious activities, so that the security team can investigate and respond to incidents. Endpoints can be user terminals, laptops, servers, cloud systems, mobile devices or Internet of Things devices, etc. RASP can monitor and block attack behaviors against application security in real time by integrating protection functions into the application. Through a small number of key functions, RASP can observe the internal situation during program execution in real time. When the application exhibits suspicious behavior, RASP can accurately identify attack events according to the current context and give real-time blocking, so that the application has self-protection capability without human intervention.
[0048] During the process of transmitting data through the network, there may be attack behaviors against the network, which can be monitored by the protection device deployed in the network and the corresponding alarm event can be generated. An analysis and judgment platform can also be deployed in the network, which is used to analyze and judge the generated alarm event to determine whether the alarm content indicated by the alarm event is true, thereby facilitating subsequent operation and maintenance personnel to dispose the related alarm event. The alarm event can be divided into types such as internal host loss, external network attack success, attempted attack and false alarm. After receiving the alarm event through the analysis and judgment platform, the operation and maintenance personnel need to analyze and judge the alarm event. Since IDS or IPS can generate a large number of alarm events, the operation and maintenance personnel can usually automatically analyze and judge the alarm event through the analysis and judgment platform. Therefore, the accuracy and coverage of automatic analysis and judgment determine whether the operation and maintenance personnel can quickly and accurately respond to and dispose the alarm event, thereby ensuring the normal and smooth operation of the user's network security.
[0049] An exemplary Figure 1 An IDS monitoring attack alarm generation and judgment scene schematic diagram provided by an embodiment of the present application is shown. As Figure 1As shown, if the internal network receives external attack traffic or internal attack traffic, for example, attack traffic is received through the switch, the switch can forward the transmitted data to the network server attacked by the attack traffic, the IDS can acquire the mirror traffic of the attack traffic, detect the mirror traffic, generate the alarm event corresponding to the attack behavior indicated by the attack traffic, and send the alarm event to the analysis and judgment platform, so that the analysis and judgment platform analyzes and judges the alarm event to determine whether the alarm event is true, so that the subsequent operation and maintenance personnel can dispose the alarm event.
[0050] In addition, Figure 2 An attack alarm generation and judgment scenario under IPS monitoring provided by the embodiment of the present application is shown. As shown in Figure 2 As shown, if the internal network receives external attack traffic or internal attack traffic, for example, attack traffic is received through the switch, the switch can forward the transmitted data to the network server attacked by the attack traffic, the IDS can acquire the mirror traffic of the attack traffic, detect the mirror traffic, generate the alarm event corresponding to the attack behavior indicated by the attack traffic, and send the alarm event to the analysis and judgment platform, so that the analysis and judgment platform analyzes and judges the alarm event to determine whether the alarm event is true, so that the subsequent operation and maintenance personnel can dispose the alarm event.
[0051] In addition, Figure 3 An attack alarm generation and judgment scenario under terminal protection device monitoring provided by the embodiment of the present application is shown. As shown in Figure 3 As shown, if the internal network receives external attack traffic or internal attack traffic, for example, the attacked network server receives attack traffic and infects the server, when the attacked network server contains a terminal protection device, the terminal protection device can collect and analyze the information of processes, file operations, user behaviors, registries, memories and external communications on the terminal, find attack behaviors, generate alarm events corresponding to the attack behaviors, and send the generated alarm events to the analysis and judgment platform, so that the analysis and judgment platform analyzes and judges the alarm events to determine whether the alarm events are true, so that the subsequent operation and maintenance personnel can dispose the alarm events.
[0052] After receiving the alarm event, the analysis and judgment platform can display the alarm event to the operation and maintenance personnel, and the operation and maintenance personnel can analyze and judge the alarm event according to the artificial experience in one case; in another case, the analysis and judgment platform can automatically analyze and judge the alarm event through fixed judgment strategies.
[0053] The fixed judgment strategy used by the analysis and judgment platform for automatically judging the alarm event can include a rule judgment strategy, an algorithm judgment strategy, and a semantic analysis judgment strategy.
[0054] Specifically, the rule judgment strategy is a strategy based on expert rules and user scenario customization. In the scenario of automatically judging the alarm event by the rule judgment strategy, the coverage of the alarm judgment according to the rule is relatively small due to the limited pre-prepared rules, and the use scenario has limitations.
[0055] For example, if the password of the host with the IP address 10.10.10.10 in the user's intranet is updated, and other devices remotely logging into the host do not synchronize the new password, a large number of brute force cracking type alarm events will be generated. In this case, the network security expert can formulate corresponding rules to make the operation and maintenance personnel ignore the alarm event. Therefore, the expert can pre-prepare rules that the target IP is 10.10.10.10 and the alarm type is a brute force cracking alarm event, determine that the alarm event does not need to be handled by the operation and maintenance personnel, and can be ignored. The pre-prepared rules are stored, so that the subsequent analysis and judgment platform receives alarm events that meet the rules and directly ignores this type of alarm according to the disposition mode indicated by the rules.
[0056] Alternatively, if the external IP initiates a Trojan horse type attack on the intranet IP, an alarm is generated. Since the Trojan horse type attack payload is clear, the expert can formulate corresponding rules. Therefore, the expert can pre-prepare rules that automatically judge the alarm event as an attempt attack for the Trojan horse type alarm initiated by the external network and without successful echo, and store the pre-prepared rules, so that the subsequent analysis and judgment platform receives alarm events that meet the rules and disposes this type of alarm according to the disposition mode indicated by the rules.
[0057] That is, the first rule above only applies to brute force cracking type alarms for the user's destination IP 10.10.10.10. The second rule only applies to Trojan horse type alarms without successful echo from the external network to the intranet. It cannot cover other users and alarm types, such as SQL injection type alarms that are prone to false positives for normal business of the user, and the like.
[0058] Specifically, the algorithm research and judgment strategy is a strategy of machine learning and deep learning based on alarm attributes and features. First, after receiving an alarm event, the attributes and features of the alarm event can be analyzed, such as alarm type, protocol used, number of occurrences of this type of alarm in the past event, etc. Then, through machine learning algorithms (such as random forest algorithm) and deep learning algorithms (such as neural network algorithm), the alarm event is clustered and classified, so as to achieve the purpose of research and judgment. The process of research and judgment of alarm events by algorithm research and judgment strategy has a certain probability of research and judgment false alarm, that is, the accuracy of research and judgment is not high.
[0059] For example, if a certain destination IP is subjected to multiple different proxy IP initiated structured query language (SQL) injection attacks with UNIOM SELECT attack payloads, the protection device can generate a corresponding alarm event. Similarly, if the query phrase used by the normal user in the SQL query is UNIOM SELECT, the protection device can also generate a corresponding alarm event. When the alarm events generated in the above two cases are judged according to the algorithm research and judgment strategy, since the attributes and features of the alarm events generated in the above two cases are the same or similar, the algorithm research and judgment strategy cannot distinguish the alarm events generated in the above two cases, resulting in a research and judgment error of the alarm event triggered by the normal user.
[0060] Specifically, the semantic research and judgment strategy is a research and judgment strategy for semantic analysis of alarm attack payloads and traffic packets. That is, through the semantic research and judgment strategy, the attack semantics in the data traffic packet can be recognized, and the attack payload can be confirmed again. That is, the semantic research and judgment strategy first performs word segmentation, filters irrelevant symbols, and extracts each word in the attack payload or traffic packet, and then can use a neural network model to perform semantic analysis on the extracted words to obtain a research and judgment result output by the neural network model. The research and judgment result can include internal host compromise, external attack success, attempted attack, and false alarm.
[0061] However, if the traffic packet contained in the alarm event is an encrypted traffic packet or a traffic packet that does not include an attack payload, the semantic research and judgment strategy cannot successfully research and judge the alarm event, or if the length of the traffic packet contained in the alarm event exceeds the threshold specified by the detection product, the truncation when researching and judging by the semantic research and judgment strategy may result in the loss of attack payloads, resulting in research and judgment failure. Therefore, the use scenario of the semantic research and judgment strategy for alarm research and judgment has limitations.
[0062] For example, for SQL type alarms, attack payloads contain attack semantics, such as "database()" and "version()" in the attack payload, which can be used to obtain the name and version number of the database, respectively. The data traffic packets generated by normal user behavior contain business-related content, such as data traffic packets generated by the relevant business of the financial department of a sales company, which do not contain attack payloads such as "database()" and "version()".
[0063] After a large number of alarm events are generated by the security protection device, the workload of operating the network increases dramatically. In related technologies, the analysis and judgment platform uses one of the three judgment strategies described above to analyze and judge each alarm event, that is, a single rule judgment strategy can be used to analyze and judge each alarm event, a single algorithm judgment strategy can be used to analyze and judge each alarm event, and a single semantic analysis strategy can be used to analyze and judge each alarm event. This results in that the analysis and judgment of alarm events by a single judgment strategy cannot adapt to all alarm events, and there is a situation that the accuracy of the attack behavior judgment indicated by the single judgment strategy used for alarm events is low, thereby affecting the efficiency of the alarm judgment of network security.
[0064] Therefore, after obtaining the alarm events of network security, since the alarm events include the alarm category corresponding to the attack mode that generates the alarm, the target judgment strategy corresponding to the alarm event can be determined according to the alarm event. If the alarm category meets the preset alarm category, the judgment strategy corresponding to the preset alarm category can be determined as the target judgment strategy, and if the alarm category does not meet the preset alarm category, at least two judgment strategies can be used as the target judgment strategy. Then, the alarm event is processed according to the target judgment strategy to obtain the target judgment result, thereby ensuring that each alarm event can use a judgment strategy that adapts to it, and the accuracy of the judgment of the alarm event is ensured as much as possible, and the efficiency of the alarm judgment of network security is improved.
[0065] Figure 4 A schematic diagram of an alarm judgment system provided by an example embodiment of the present application is shown. As shown in the figure, the alarm judgment system includes a computing device 10 and a security protection device 11. Figure 4
[0066] The computing device 10 is configured to run the analysis and judgment platform, and the computing device 10 at least includes a processor and a memory. For example, the computing device 10 can be a server, a computer device, or the like. The security protection device 11 can be a terminal protection device or a boundary protection device. For example, the boundary protection device can include, but is not limited to, a firewall, an IDS, an IPS, and a WAF. The terminal protection device can include, but is not limited to, an EDR and a RASP.
[0067] In a possible implementation, the security protection device 11 can detect data flow packets transmitted in a network. If it is detected that the data flow packets are abnormal, the security protection device can generate a corresponding alarm event, and send the generated alarm event to the computing device 10. The computing device 10 can analyze and judge the alarm event by running the analysis and judgment platform.
[0068] Figure 5 A hardware structure schematic diagram of a computing device provided by an embodiment of the present application is shown. As shown in the figure, the computing device 10 can include a central processing unit (CPU) 104, a memory 106, and a bus 102. The CPU 104 and the memory 106 can be connected to each other through the bus 102. Figure 5
[0069] The CPU 104 is configured to run the analysis and judgment platform. The CPU 104 can determine a target judgment strategy corresponding to the alarm event according to an alarm category of the alarm event, and process the alarm event according to the target judgment strategy to obtain a target judgment result. The memory 106 can store a preset alarm category and a corresponding judgment strategy.
[0070] The memory 106 can be hardware for realizing a storage function, for example, can be a volatile memory, a non-volatile memory, a hard disk, or a flash drive. The memory 106 can also be a database. The memory 106 can be used to store instructions or programs of the network security alarm judgment method.
[0071] It should be noted that the application scenarios and system architectures described in the embodiments of the present application are used to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0072] In order to facilitate understanding, the network security alarm judgment method provided by the present application is exemplarily introduced below in combination with the accompanying drawings. The network security alarm judgment method is applicable to the computing device shown in the figures. Figure 4 , Figure 5
[0073] Figure 6 A flowchart of a network security alarm research and judgment method provided by an example embodiment of the present application is shown. The network security alarm research and judgment method can be executed by a computing device, which can be the computing device 10 shown in FIG. 1. Figure 4 Figure 5 The network security alarm research and judgment method includes the following steps:
[0074] S101, the computing device acquires a network security alarm event.
[0075] The alarm event includes an alarm category to which an abnormal network security situation occurred belongs. The alarm category can be used to indicate at least one attack mode against network security.
[0076] For example, the alarm category can include command injection, code execution, sensitive information leakage, SQL injection, brute force, scanning, directory traversal, botnet, cross-site scripting (XSS), Trojan, worm, buffer overflow, ransomware, etc. The attack mode against network security includes SQL injection, XSS attack, cross-site request forgery (CSRF) attack, web Trojan attack, file inclusion vulnerability attack, directory traversal attack, challenge collapsar (CC) attack, denial of service (DOS) attack, etc.
[0077] Among them, SQL injection is to insert SQL commands into web form submission or input domain name or page request query string, and finally deceive the server to execute malicious SQL commands. XSS attack refers to exploiting the vulnerabilities left during web development by injecting malicious instruction code into web pages to make users load and execute malicious web programs created by attackers. CSRF attack refers to using a trusted website to perform malicious operations by disguising as a trusted user's request. Web Trojan attack refers to disguising as a normal web file or inserting malicious code directly into a normal web file. When the user accesses, the web Trojan can automatically download the configured Trojan server to the visitor's computer and automatically execute it. File inclusion vulnerability attack refers to not properly filtering user-controlled file paths or file names and other inputs in the implementation of the application, allowing attackers to control file loading behavior. File inclusion vulnerability attack allows attackers to read, execute or include files controlled by maliciously constructed requests, causing security problems. Directory traversal attack refers to that an attacker can make the system crash by accessing the root directory and sending a series of characters to traverse the upper directory and execute system commands. CC attack refers to that an attacker generates a legitimate request to a victim host through a proxy server to achieve denial of service and disguised attack. DOS attack refers to that an attacker interferes with the server to reduce or lose its availability.
[0078] In order to complete one or more businesses, data transmission of data related to the business needs to be performed through the network. During the data transmission process, external attack traffic or internal attack traffic may attack one or more devices in the network, so as to achieve the purpose of destroying the normal operation of the business or leaking the business data, or the virus transmitted through the universal serial bus (USB) into the device will also destroy the normal operation of the business processed by the device or leak related business data. Therefore, in order to protect network security, a protection device needs to be deployed in the network, so as to detect or block the attack behavior on the device in the network through the protection device. Among them, the protection device will generate an alarm event after detecting a suspected attack behavior. The alarm event can include the attack mode of the attack behavior judged by the protection device, that is, the alarm category. The alarm event can also include the data content of the attack traffic, that is, the code related to the attack traffic. The alarm event can also include various attributes and characteristics of the attack traffic, such as the source IP, target IP, used protocol, number of occurrences of this type of alarm in a period of time in the past, etc.
[0079] That is, the protection device deployed in the network can generate multiple alarm events. The protection device will send the generated multiple alarm events to the analysis and judgment platform. After the analysis and judgment platform obtains the alarm events, it will in turn judge each alarm event.
[0080] In S102, the computing device determines a target research strategy corresponding to the alarm event.
[0081] In the implementation, if the alarm category matches the preset alarm category, the target research strategy is a research strategy corresponding to the preset alarm category; if the alarm category does not match the preset alarm category, the target research strategy includes at least two research strategies.
[0082] In a possible implementation, the alarm category included in the alarm event is obtained, the alarm category is compared with the preset alarm category, it is determined whether the alarm category included in the alarm event belongs to the preset alarm category, if the alarm category belongs to the preset alarm category, a research strategy corresponding to the preset alarm category can be determined as the target research strategy; if the alarm category does not belong to the preset alarm category, at least two research strategies can be determined as the target research strategy.
[0083] In the implementation, a corresponding relationship between the preset alarm category and the research strategy corresponding to the preset alarm category can be stored in advance. For example, when the preset alarm category is brute force cracking and sensitive file access, the corresponding research strategy can be an algorithm research strategy; when the preset alarm category is SQL injection with attack payload, the corresponding research strategy can be a semantic research strategy.
[0084] That is, if the alarm category included in the alarm event is brute force cracking and sensitive file access, a target research strategy corresponding to the alarm event can be determined as an algorithm research strategy, that is, the alarm event is researched by using the algorithm research strategy subsequently; if the alarm category included in the alarm event is SQL injection with attack payload, a target research strategy corresponding to the alarm event can be determined as a semantic research strategy.
[0085] In another possible implementation, attributes and features of the alarm event are obtained, it is determined whether the alarm event matches a preset condition, if the alarm event matches the preset condition, a target research strategy corresponding to the alarm event is determined as a research strategy corresponding to the preset condition.
[0086] In the implementation, a corresponding relationship between the preset condition and the corresponding research strategy can be stored in advance. For example, the preset condition can be that the alarm event supports extraction of attributes or features covered by a preset rule, and the attributes and features match the preset rule, a research strategy corresponding to the preset condition can be a rule research strategy. The preset condition can be that the alarm event supports clear and complete extraction of attributes and features, a research strategy corresponding to the preset condition can be an algorithm research strategy. The preset condition can be that semantics in the alarm event have explicit attack information and have explicit attack payload, a research strategy corresponding to the preset condition can be a semantic research strategy.
[0087] That is, after the analysis and judgment platform obtains the alarm event, it can be determined whether the attributes or characteristics covered by the preset rule can be extracted and whether the extracted attributes or characteristics are consistent with the preset rule. If the above preset conditions are met, the target judgment strategy corresponding to the alarm event can be determined as the rule judgment strategy, that is, the alarm event is judged by the rule judgment strategy in the subsequent; it can also be determined whether the alarm event supports clear and complete extraction of each attribute and characteristic. If it supports clear and complete extraction of each attribute and characteristic, the target judgment strategy corresponding to the alarm event can be determined as the algorithm judgment strategy, that is, the alarm event is judged by the algorithm judgment strategy in the subsequent; it can also be determined whether the semantics in the alarm event has clear attack information and has clear attack load. If it has the above conditions, the target judgment strategy corresponding to the alarm event can be determined as the semantic judgment strategy, that is, the alarm event is judged by the semantic judgment strategy in the subsequent. The order of the determination methods of the above three target judgment strategies is not limited here, and in the case where any one of the preset conditions is met, the comparison process of other preset conditions can not be performed.
[0088] Exemplarily, the features extracted from the alarm event for algorithm judgment can include but are not limited to the features in Table 1.
[0089] Number Feature Extraction source 1 Source IP location information of the alarm Alarm attribute 2 Protocol used by the alarm Alarm attribute 3 Whether the alarm name belongs to the attack whitelist Alarm attribute 4 Number of alarms generated by the same source IP in the past specified time Number statistics between alarms 5 Number of alarms generated by the same destination IP in the past specified time Number statistics between alarms 6 Number of alarm categories generated by the same source IP in the past specified time Number statistics between alarms 7 Number of alarm categories generated by the same destination IP in the past specified time Number statistics between alarms 8 Number of alarms of the same attack category and triggering protection equipment blocking the flow in the past specified time Number statistics between alarms 9 Number of alarms generated by the same source IP, destination IP, destination port, and alarm name in the past specified time Number statistics between alarms 10 Number of alarms triggered by a flow Number statistics between alarms 11 Number of alarm categories triggered by a flow Number statistics between alarms 12 Number of protection equipment accessing the same destination IP Graph relationship constituted by IP access 13 Number of protection equipment accessed by the same source IP Graph relationship constituted by IP access
[0090] Table 1
[0091] In a possible implementation, the computing device can determine at least two judgment strategies as the target judgment strategy.
[0092] Optionally, if it is determined that the alarm event does not meet the preset alarm category or the preset condition after judging by the preset alarm category or the preset condition, at least two judgment strategies can be determined as the target judgment strategy.
[0093] Exemplarily, in the case where it is determined that the alarm event does not meet the preset alarm category or the preset condition after judging by the preset alarm category or the preset condition, the rule judgment strategy, the algorithm judgment strategy and the semantic judgment strategy can be determined as the target judgment strategy.
[0094] In a possible implementation, before determining the target judgment strategy of the alarm event, the algorithm judgment strategy and the semantic judgment strategy can be updated.
[0095] Specifically, the computing device extracts semantic information in the preset rule content, and updates the target algorithm and the neural network model according to the semantic information to obtain the updated algorithm judgment strategy and the updated semantic judgment strategy. The semantic information includes feature information and keywords.
[0096] Exemplarily,Figure 7 is a kind of algorithm research and judgment strategy and semantic research and judgment strategy update flowchart that the embodiment of the application relates to. As shown in Figure 7 The preset rule in the rule research and judgment strategy is semantically analyzed, and the semantic information (S11) in it is extracted, for example, if the preset rule is an alarm generated by the scanning initiated by the external network to the internal network, it is determined that the research and judgment result is to confirm the attack behavior. Then, the computing device integrates the extracted semantic information into the algorithm research and judgment strategy or the semantic research and judgment strategy, thereby updating the algorithm research and judgment strategy or the semantic research and judgment strategy (S12). For example, the above-mentioned preset rule can convert whether the alarm is initiated by the external network to the internal network into feature 1, and whether the alarm category is scanning category into feature 2. Feature 1 and feature 2 are added to the attributes or features of the alarm event that need to be extracted in the algorithm research and judgment strategy, thereby achieving the purpose of updating the algorithm research and judgment strategy. Or the source IP, destination IP and alarm category can be taken as the content of semantic analysis, as the sample output of the neural network model of the semantic research and judgment strategy, to realize the update of the neural network model of the semantic research and judgment strategy, thereby achieving the purpose of updating the semantic research and judgment strategy.
[0097] S103, according to the target research and judgment strategy, the alarm event is processed to obtain the target research and judgment result.
[0098] The target research and judgment result is used to indicate whether the alarm event is established, that is, the target research and judgment result can be determined after research and judgment that the alarm indicates the attack behavior, and whether the attack behavior indicated by the alarm is a false alarm.
[0099] In one possible implementation, if the alarm category corresponding to the alarm event does not conform to the preset alarm category, the alarm event is respectively researched and judged according to at least two research and judgment strategies to obtain at least two research and judgment results corresponding to the at least two research and judgment strategies respectively; according to the at least two research and judgment results corresponding to the at least two research and judgment strategies respectively, the target research and judgment result is determined.
[0100] That is, the alarm event is respectively researched and judged according to at least two research and judgment strategies to obtain the research and judgment results of the alarm event according to at least two research and judgment strategies respectively, and the target research and judgment result is obtained by combining each research and judgment result.
[0101] Specifically, if the research and judgment result is used to indicate the probability of the alarm event being established, the computing device can obtain the weight of at least two research and judgment strategies respectively, and the weighted sum average calculation is performed on the research and judgment results corresponding to the at least two research and judgment strategies according to the weight, to obtain the target research and judgment result.
[0102] Wherein, when the probability corresponding to the target research and judgment result is less than a specified threshold, the target research and judgment result indicates that the alarm event does not exist, and when the probability corresponding to the target research and judgment result is greater than or equal to the specified threshold, the target research and judgment result indicates that the alarm event exists.
[0103] The weights of at least two analysis and judgment strategies may be pre-set, or may be calculated through a back-propagation algorithm.
[0104] For example, Figure 8 This is a flow chart of a collaborative analysis of multiple analysis strategies involved in the embodiment of this application. Figure 8 As shown, if the target analysis strategy includes the rule analysis strategy, the algorithm analysis strategy, and the semantic analysis strategy, the weight w1 corresponding to the rule analysis strategy, the weight w2 corresponding to the algorithm analysis strategy, and the weight w3 corresponding to the semantic analysis strategy are obtained, and the alarm event is analyzed according to the rule analysis strategy, the algorithm analysis strategy, and the semantic analysis strategy respectively, to obtain the analysis result 1 output according to the rule analysis strategy, the analysis result 2 output according to the algorithm analysis strategy, and the analysis result 3 output according to the semantic analysis strategy. Among them, the corresponding analysis result when it is determined to be an attack behavior after analysis is a value of 1, and the corresponding analysis result when it is determined to be a false alarm after analysis is a value of 0. If the analysis result 1 output according to the three analysis strategies is a value of 1, the analysis result 2 is a value of 1, and the analysis result 3 is a value of 0, the target analysis result r can be (1*w1+1*w2+0*w3) / 3. If the specified threshold is set to 0.5, then if r>0.5, the target analysis result may indicate that the alarm event is determined to be an attack behavior after analysis; if r<0.5, the target analysis result may indicate that the alarm event is determined to be a false alarm after analysis.
[0105] In addition, when no preset alarm category or preset condition is set, each analysis and judgment strategy can be determined as a target analysis and judgment strategy.
[0106] That is, after obtaining the alarm event, the alarm event can be directly analyzed according to each analysis and judgment strategy to obtain respective analysis and judgment results, and the target analysis and judgment strategy can be obtained by combining the various analysis and judgment results.
[0107] In a possible implementation, if the alarm category corresponding to the alarm event meets the preset alarm category, the alarm event is analyzed and judged according to the analysis and judgment strategy corresponding to the preset alarm category to obtain a target analysis and judgment result.
[0108] That is to say, if the target analysis strategy is any one of the rule analysis strategy, algorithm analysis strategy, and semantic analysis strategy, the alarm event is analyzed according to the target analysis strategy to obtain the target analysis result.
[0109] For example, Figure 9 This is a flow chart of a collaborative analysis of multiple analysis strategies involved in the embodiment of this application. Figure 9As shown, if there are a large number of alarm events to be judged, the computing device can first judge the alarm events covered by the preset rules according to the rule judgment strategy to obtain the target judgment result corresponding to the alarm events covered by the preset rules (S21). Then, the computing device determines the alarm categories to which each alarm event not yet judged belongs, that is, classifies each alarm event not yet judged according to the alarm category (S22), for example, if the alarm category is brute force cracking and sensitive file access, the alarm event can be determined as a category 1 alarm event; if the alarm category is SQL injection with attack payload, the alarm event can be determined as a category 2 alarm event; and the alarm events of the remaining alarm categories are determined as category 3 alarm events. The category 1 alarm events are judged according to the algorithm judgment strategy to obtain the target judgment result corresponding to the category 1 alarm events, and the category 2 alarm events are judged according to the semantic judgment strategy to obtain the target judgment result corresponding to the category 2 alarm events (S23). Then, the category 3 alarm events are respectively judged according to the algorithm judgment strategy and the semantic judgment strategy to obtain the judgment result 1 output by the algorithm judgment strategy and the judgment result 2 output by the semantic judgment strategy (S24), and the judgment result 1 and the judgment result 2 are comprehensively judged to obtain the target judgment result of the category 3 alarm events (S25).
[0110] Among them, the judgment method of comprehensive judgment can be weighted sum average calculation of the judgment result 1 and the judgment result 2 according to the weight to obtain the target judgment result of the category 3 alarm events. The specific calculation process is as shown in Figure 8 The weighted sum average calculation process.
[0111] For example, if the target research strategy includes a rule research strategy, the computing device can compare the alarm event with preset rule content; in the case of matching the alarm event with the preset rule content, the research result of the alarm event under the rule research strategy is determined as the research result corresponding to the preset rule content. If the target research strategy includes an algorithm research strategy; the computing device can extract features of the alarm event to obtain feature information; input the feature information into the target algorithm to cluster or classify the alarm event, and obtain the research result of the alarm event under the algorithm research strategy. The feature information includes source IP information of the alarm, http protocol information of the alarm, information of the alarm name, number of alarms generated by the same source IP in a specified period, number of alarms generated by the same destination IP in a specified period, number of alarm categories generated by the same source IP in a specified period, number of alarm categories generated by the same destination IP in a specified period, number of alarms of the same alarm category and capable of triggering blocking in a specified period, number of alarms triggered by the same traffic, number of alarm categories triggered by the same traffic, number of protection devices accessed by the same destination IP, and number of protection devices accessed by the same source IP. If the target research strategy includes a semantic research strategy; the computing device can extract keywords of the alarm event to obtain the keywords of the alarm event; input the keywords into a neural network model, and perform semantic analysis on the keywords through the neural network model to obtain the research result of the alarm event under the semantic research strategy.
[0112] In a possible implementation, if the alarm category of the alarm event does not conform to the preset alarm category of the algorithm research strategy and the preset alarm category of the semantic research strategy, the alarm event is processed according to the updated algorithm research strategy and the updated semantic research strategy respectively to obtain the target research result.
[0113] That is, the computing device can integrate the preset rule contained in the rule research strategy into the algorithm research strategy or the semantic research strategy, and obtain the updated algorithm research strategy or the updated semantic research strategy after integrating the semantic information. In the case that the target research strategy corresponding to the alarm event is the updated algorithm research strategy or the updated semantic research strategy, the alarm event is processed according to the updated algorithm research strategy and the updated semantic research strategy to obtain the target research result.
[0114] For example, Figure 10 is a flowchart of a multi-item research strategy cooperative research process related to an embodiment of the present application. As shown in Figure 10As shown, if there are a large number of alarm events to be judged, the computing device determines the alarm category to which each alarm event belongs, that is, classifies each alarm event according to the alarm category (S31), for example, if the alarm category is brute force cracking and sensitive file access, the alarm event can be determined as a category 1 alarm event; if the alarm category is SQL injection with attack payload, the alarm event can be determined as a category 2 alarm event; and the alarm events of the remaining alarm categories are determined as category 3 alarm events. The category 1 alarm event is judged according to the updated algorithm judgment strategy to obtain the target judgment result corresponding to the category 1 alarm event, and the category 2 alarm event is judged according to the updated semantic judgment strategy to obtain the target judgment result corresponding to the category 2 alarm event (S32). Then, the category 3 alarm event is judged according to the updated algorithm judgment strategy and the updated semantic judgment strategy respectively to obtain the judgment result 1 output by the updated algorithm judgment strategy and the judgment result 2 output by the updated semantic judgment strategy (S33), and the judgment result 1 and the judgment result 2 are comprehensively judged to obtain the target judgment result of the category 3 alarm event (S34).
[0115] Among them, the judgment method of comprehensive judgment can be weighted sum average calculation of the judgment result 1 and the judgment result 2 according to the weight to obtain the target judgment result of the category 3 alarm event. The specific calculation process is as shown in the following weighted sum average calculation process. Figure 8
[0116] In summary, after obtaining the alarm event of network security, since the alarm event includes the alarm category corresponding to the attack mode that generates the alarm, the target judgment strategy corresponding to the alarm event can be determined according to the alarm event, wherein if the alarm category meets the preset alarm category, the judgment strategy corresponding to the preset alarm category can be determined as the target judgment strategy, and if the alarm category does not meet the preset alarm category, at least two judgment strategies can be used as the target judgment strategy. Then, the alarm event is processed according to the target judgment strategy to obtain the target judgment result, and the alarm event is comprehensively judged according to the three judgment strategies, which can fully play the advantages of each judgment strategy, improve the accuracy of automatic judgment, reduce the false alarm situation, and reduce the alarm analysis burden of operation and maintenance personnel. In addition, the preset rule content in the rule judgment strategy is semantically analyzed, and the semantic information is integrated into the algorithm judgment strategy and the semantic judgment strategy, thereby strengthening the adaptability of the algorithm judgment strategy and the semantic judgment strategy to specific user scenarios, further improving the accuracy of alarm judgment, and thereby improving the efficiency of alarm judgment of network security.
[0117] The above describes the scheme of the embodiments of the present application mainly from the perspective of the method. It can be understood that, in order to implement the above functions, the alarm research and judgment device of network security comprises at least one of the hardware structure and the software module for executing the corresponding functions. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of the examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or the combination of hardware and computer software. Whether a certain function is implemented in the form of hardware or computer software driven hardware depends on the specific application of the technical solution and the design constraint conditions. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0118] The embodiments of the present application can divide the functional units of the alarm research and judgment device of network security according to the above method examples. For example, each functional unit can be divided according to each function, or two or more functions can be integrated in one processing unit. The integrated unit can be implemented in the form of hardware or software functional unit. It should be noted that the division of units in the embodiments of the present application is illustrative, and is only a logical function division. In actual implementation, there can be another division method.
[0119] For example, Figure 11 A structural schematic diagram of an alarm research and judgment device of network security 500 provided by an exemplary embodiment of the present application is shown. The alarm research and judgment device of network security 500 is applied to a computing device, or the alarm research and judgment device of network security 500 can be a computing device. The alarm research and judgment device of network security 500 comprises:
[0120] The acquisition module 510 is configured to acquire an alarm event of network security. The alarm event comprises an alarm category to which an abnormal network security situation occurs, and the alarm category is used to indicate at least one attack mode against network security.
[0121] The processing module 520 is configured to determine a target research and judgment strategy corresponding to the alarm event. If the alarm category conforms to a preset alarm category, the target research and judgment strategy is a research and judgment strategy corresponding to the preset alarm category. If the alarm category does not conform to the preset alarm category, the target research and judgment strategy comprises at least two research and judgment strategies.
[0122] The research and judgment module 530 is configured to process the alarm event according to the target research and judgment strategy, to obtain a target research and judgment result. The target research and judgment result is used to indicate whether the alarm event is established.
[0123] For example, in combination with Figure 6 The acquisition module 510 can be configured to perform the functions such as Figure 6The processing module 520 can be configured to perform the following steps S101-S103. Figure 6 The judgment module 530 can be configured to perform the following steps S102-S103. Figure 6 The judgment module 530 can be configured to perform the following steps S102-S103.
[0124] In a possible implementation, the judgment module 530 is further configured to:
[0125] If the alarm category corresponding to the alarm event does not conform to the preset alarm category, the alarm event is judged according to the at least two judgment strategies respectively to obtain a judgment result corresponding to each of the at least two judgment strategies.
[0126] The target judgment result is determined according to the judgment result corresponding to each of the at least two judgment strategies.
[0127] In a possible implementation, if the judgment result is used to indicate a probability that the alarm event is true, the judgment module 530 is further configured to:
[0128] obtain a weight corresponding to each of the at least two judgment strategies;
[0129] perform weighted sum average calculation on the judgment result corresponding to each of the at least two judgment strategies according to the weight to obtain the target judgment result, wherein the target judgment result indicates that the alarm event is not true when a probability corresponding to the target judgment result is less than a specified threshold, and the target judgment result indicates that the alarm event is true when the probability corresponding to the target judgment result is greater than or equal to the specified threshold.
[0130] In a possible implementation, the judgment module 530 is further configured to:
[0131] If the alarm category corresponding to the alarm event conforms to the preset alarm category, the alarm event is judged according to the judgment strategy corresponding to the preset alarm category to obtain the target judgment result.
[0132] In a possible implementation, the processing module 520 is further configured to:
[0133] In a case where no preset alarm category is set, each of the judgment strategies is determined as a target judgment strategy.
[0134] In a possible implementation, if the target judgment strategy includes a rule judgment strategy, the judgment module 530 is further configured to:
[0135] compare the alarm event with preset rule content;
[0136] In a case where the alarm event matches the preset rule content, a judgment result of the alarm event under the rule judgment strategy is determined as a judgment result corresponding to the preset rule content.
[0137] In a possible implementation, if the target judgment strategy includes an algorithm judgment strategy, the judgment module 530 is further configured to,
[0138] extracting features of the alarm event to obtain feature information;
[0139] inputting the feature information into a target algorithm, and performing clustering or classification on the alarm event to obtain a judgment result of the alarm event under the algorithm judgment strategy;
[0140] The feature information includes source IP information of the alarm, http protocol information of the alarm, information of the alarm name, a number of alarms generated by the same source IP in a specified period, a number of alarms generated by the same destination IP in the specified period, a number of alarm categories generated by the same source IP in the specified period, a number of alarm categories generated by the same destination IP in the specified period, a number of alarms of the same alarm category and capable of triggering blocking in the specified period, a number of alarms triggered by the same traffic, a number of alarm categories triggered by the same traffic, a number of protection devices accessing the same destination IP, and a number of protection devices accessed by the same source IP.
[0141] In a possible implementation, if the target judgment strategy includes a semantic judgment strategy, the judgment module 530 is further configured to,
[0142] extracting keywords of the alarm event to obtain the keywords of the alarm event;
[0143] inputting the keywords into a neural network model, performing semantic analysis on the keywords by the neural network model, and obtaining a judgment result of the alarm event under the semantic judgment strategy.
[0144] In a possible implementation, the apparatus further includes:
[0145] an extraction module configured to, before determining the target judgment strategy corresponding to the alarm event, extract semantic information in the preset rule content, the semantic information including feature information and keywords;
[0146] an updating module configured to update the target algorithm and the neural network model according to the semantic information to obtain an updated algorithm judgment strategy and an updated semantic judgment strategy.
[0147] In a possible implementation, the judgment module 530 is further configured to,
[0148] If the alarm category of the alarm event does not conform to the preset alarm category of the algorithm research strategy and the preset alarm category of the semantic research strategy, the alarm event is processed according to the updated algorithm research strategy and the updated semantic research strategy respectively to obtain the target research result.
[0149] The specific description of the optional mode can be referred to the foregoing method embodiments, and will not be described here. In addition, the explanation and beneficial effect of any of the foregoing network security alarm research devices can be referred to the corresponding method embodiments, and will not be described here.
[0150] The acquisition module 510, the processing module 520 and the research module 530 can be implemented by software or hardware. For example, the implementation of the acquisition module 510 will be described below. Similarly, the implementation of the processing module 520 and the research module 530 can be referred to the implementation of the acquisition module 510.
[0151] As an example of a software functional unit, the acquisition module 510 can include code running on a computing instance. The computing instance can include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance can be one or more. For example, the acquisition module 510 can include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the code can be distributed in the same region, or in different regions. Further, the multiple hosts / virtual machines / containers for running the code can be distributed in the same availability zone (AZ), or in different AZs, each AZ including a data center or multiple data centers with similar geographical locations. Generally, one region can include multiple AZs.
[0152] Similarly, the multiple hosts / virtual machines / containers for running the code can be distributed in the same virtual private cloud (VPC), or in multiple VPCs. Generally, one VPC is set in one region, and communication between two VPCs in the same region or between VPCs in different regions needs to be set in each VPC to realize the interconnection between VPCs through a communication gateway.
[0153] As an example of a hardware functional unit, the obtaining module 510 can include at least one computing device, such as a server or the like. Alternatively, the obtaining module 510 can also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), and the like. The PLD can be implemented by a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0154] The multiple computing devices included in the obtaining module 510 can be distributed in the same region or in different regions. The multiple computing devices included in the obtaining module 510 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the obtaining module 510 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0155] It should be noted that, in other embodiments, the obtaining module 510 can be configured to perform any step of the network security alarm research and judgment method, the processing module 520 can be configured to perform any step of the network security alarm research and judgment method, and the research and judgment module 530 can be configured to perform any step of the network security alarm research and judgment method. The steps implemented by the obtaining module 510, the processing module 520, and the research and judgment module 530 can be specified as needed, and the entire function of the network security alarm research and judgment device can be implemented by the obtaining module 510, the processing module 520, and the research and judgment module 530 implementing different steps of the network security alarm research and judgment method. The present application also provides a computing device 100. As shown in Figure 12 The processor 104, the memory 106, and the communication interface 108 communicate through the bus 102. The computing device 100 can be a server or a terminal device. It should be understood that the number of processors and memories in the computing device 100 is not limited in the present application.
[0156] The bus 102 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 12 Only one line is used in the figure to represent a bus, but this does not mean there is only one bus or only one type of bus. The bus 102 can include pathways to transfer information between various components of the computing device 100 (e.g., the memory 106, the processor 104, the communication interface 108).
[0157] The processor 104 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.
[0158] The memory 106 can include a volatile memory, such as a random access memory (RAM), etc. The processor 104 can also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD), etc.
[0159] The memory 106 stores executable program code, and the processor 104 executes the executable program code to respectively implement the functions of the aforementioned acquisition module 510, the processing module 520, and the judgment module 530, thereby implementing the alarm judgment method for network security. That is, the memory 106 stores instructions for executing the alarm judgment method for network security.
[0160] Alternatively, the memory 106 stores executable program code, and the processor 104 executes the executable program code to respectively implement the functions of the aforementioned alarm judgment device for network security, thereby implementing the alarm judgment method for network security. That is, the memory 106 stores instructions for executing the alarm judgment method for network security.
[0161] The communication interface 103 uses a transceiving module such as, but not limited to, a network interface card, a transceiver, to enable communication between the computing device 100 and other devices or communication networks.
[0162] Embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a notebook computer, or a smart phone.
[0163] As shown in Figure 13 , the computing device cluster includes at least one computing device 100. The memory 106 in one or more computing devices 100 in the computing device cluster can have the same instructions for performing the method for alarm judgment of network security.
[0164] In some possible implementations, the memory 106 of one or more computing devices 100 in the computing device cluster can also respectively have partial instructions for performing the method for alarm judgment of network security. In other words, the combination of one or more computing devices 100 can collectively execute the instructions for performing the method for alarm judgment of network security.
[0165] It should be noted that the memory 106 in different computing devices 100 in the computing device cluster can store different instructions for respectively performing partial functions of the alarm judgment device for network security. That is, the instructions stored in the memory 106 in different computing devices 100 can implement the functions of one or more of the acquisition module 510, the processing module 520, and the judgment module 530.
[0166] In some possible implementations, one or more computing devices in the computing device cluster can be connected through a network. The network can be a wide area network or a local area network, etc. Figure 14 A possible implementation is shown. As shown in Figure 14 , two computing devices 100A and 100B are connected through a network. Specifically, the communication interface in each computing device is connected to the network. In this type of possible implementation, the memory 106 in the computing device 100A has instructions for performing the functions of the acquisition module 510. At the same time, the memory 106 in the computing device 100B has instructions for performing the functions of the processing module 520 and the judgment module 530.
[0167] Figure 14The connection manner between the illustrated computing device clusters can be that the network security alarm judgment method provided in the present application requires a large amount of data storage and data calculation, and therefore the functions implemented by the processing module 520 and the judgment module 530 are transferred to the computing device 100B for execution.
[0168] It should be understood that Figure 14 The functions of the computing device 100A illustrated in the above embodiment can also be completed by multiple computing devices 100. Similarly, the functions of the computing device 100B can also be completed by multiple computing devices 100.
[0169] The present embodiment also provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to the connection manner of the computing device cluster Figure 13 and Figure 14 The difference is that the memory 106 in one or more computing devices 100 in the computing device cluster can store the same instructions for executing the network security alarm judgment method.
[0170] In some possible implementations, the memory 106 in one or more computing devices 100 in the computing device cluster can also respectively store part of the instructions for executing the network security alarm judgment method. In other words, the combination of one or more computing devices 100 can collectively execute the instructions for executing the network security alarm judgment method.
[0171] It should be noted that the memory 106 in different computing devices 100 in the computing device cluster can store different instructions for executing part of the functions of the data processing system. That is, the instructions stored in the memory 106 in different computing devices 100 can implement the functions of one or more devices in the network security alarm judgment apparatus.
[0172] The present embodiment also provides a computer program product containing instructions. The computer program product can be a software or program product containing instructions, which can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the network security alarm judgment method.
[0173] The embodiments of the present application further provide a computer readable storage medium. The computer readable storage medium can be any available medium or data storage device that can store the instructions of the computer device, or a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk), etc. The computer readable storage medium includes instructions for instructing the computer device to execute the alarm judgment method for network security, or for instructing the computer device to execute the alarm judgment method for network security.
[0174] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the protection scope of the technical solutions of the embodiments of the present application.
Claims
1. A network security alarm research and judgment method, characterized in that, The method comprises: obtaining an alarm event of network security; the alarm event comprises an alarm category to which an abnormal network security situation occurs, and the alarm category is used to indicate at least one attack mode against network security; determining a target research and judgment strategy corresponding to the alarm event; wherein, if the alarm category conforms to a preset alarm category, the target research and judgment strategy is a research and judgment strategy corresponding to the preset alarm category; if the alarm category does not conform to the preset alarm category, the target research and judgment strategy comprises at least two research and judgment strategies; processing the alarm event according to the target research and judgment strategy to obtain a target research and judgment result, wherein the target research and judgment result is used to indicate whether the alarm event is established.
2. The method of claim 1, wherein, The processing of the alarm event according to the target research and judgment strategy to obtain a target research and judgment result comprises: if the alarm category corresponding to the alarm event does not conform to the preset alarm category, the alarm event is respectively researched and judged according to the at least two research and judgment strategies to obtain a research and judgment result corresponding to each of the at least two research and judgment strategies; determining the target research and judgment result according to the research and judgment result corresponding to each of the at least two research and judgment strategies.
3. The method of claim 2, wherein, If the research and judgment result is used to indicate a probability that the alarm event is established; The determination of the target research and judgment result according to the research and judgment result corresponding to each of the at least two research and judgment strategies comprises: obtaining a weight corresponding to each of the at least two research and judgment strategies; performing weighted summation average calculation on the research and judgment result corresponding to each of the at least two research and judgment strategies according to the weight to obtain the target research and judgment result, wherein, when a probability corresponding to the target research and judgment result is less than a specified threshold, the target research and judgment result indicates that the alarm event is not established, and when the probability corresponding to the target research and judgment result is greater than or equal to the specified threshold, the target research and judgment result indicates that the alarm event is established.
4. The method of claim 1, wherein, The processing of the alarm event according to the target research and judgment strategy to obtain a target research and judgment result comprises: if the alarm category corresponding to the alarm event conforms to the preset alarm category, researching and judging the alarm event according to the research and judgment strategy corresponding to the preset alarm category to obtain the target research and judgment result.
5. The method of claim 1, wherein, The determination of the target research and judgment strategy corresponding to the alarm event comprises: in the case where no preset alarm category is set, determining each research and judgment strategy as a target research and judgment strategy.
6. The method according to any one of claims 1 to 5, characterized in that, If the target research and judgment strategy comprises a rule research and judgment strategy; The processing of the alarm event according to the target research and judgment strategy comprises: comparing the alarm event with preset rule content; in the case where the alarm event is consistent with the preset rule content, determining a research and judgment result of the alarm event under the rule research and judgment strategy as a research and judgment result corresponding to the preset rule content.
7. The method according to any one of claims 1 to 6, characterized in that, If the target research and judgment strategy comprises an algorithm research and judgment strategy; The processing of the alarm event according to the target research and judgment strategy comprises: performing feature extraction on the alarm event to obtain feature information; input the feature information into a target algorithm, cluster or classify the alarm event, and obtain a judgment result of the alarm event under the algorithm judgment strategy; The feature information includes source IP information of the alarm, HTTP protocol information of the alarm, alarm name information, a number of alarms generated by the same source IP in a specified period, a number of alarms generated by the same destination IP in the specified period, a number of alarm categories generated by the same source IP in the specified period, a number of alarm categories generated by the same destination IP in the specified period, a number of alarms of the same alarm category and capable of triggering blocking in the specified period, a number of alarms triggered by the same traffic, a number of alarm categories triggered by the same traffic, a number of protection devices accessing the same destination IP, and a number of protection devices accessed by the same source IP.
8. The method according to any one of claims 1 to 7, characterized in that, If the target judgment strategy includes a semantic judgment strategy; The processing of the alarm event according to the target judgment strategy includes: extracting keywords of the alarm event; inputting the keywords into a neural network model, performing semantic analysis on the keywords by using the neural network model, and obtaining a judgment result of the alarm event under the semantic judgment strategy.
9. The method of claim 8, wherein, Before the determination of the target judgment strategy corresponding to the alarm event, the method further includes: extracting semantic information in the preset rule content, the semantic information including feature information and keywords; updating the target algorithm and the neural network model according to the semantic information to obtain an updated algorithm judgment strategy and an updated semantic judgment strategy.
10. The method of claim 9, wherein, The processing of the alarm event according to the target judgment strategy includes: If the alarm category of the alarm event does not conform to the preset alarm category of the algorithm judgment strategy and the preset alarm category of the semantic judgment strategy, the alarm event is processed according to the updated algorithm judgment strategy and the updated semantic judgment strategy to obtain the target judgment result.
11. A network security alarm judgment device, characterized in that, The apparatus includes: an acquisition module configured to acquire an alarm event of network security; the alarm event includes an alarm category to which an occurred network security abnormality belongs, and the alarm category is used to indicate at least one attack mode against network security; a processing module configured to determine a target judgment strategy corresponding to the alarm event; if the alarm category conforms to a preset alarm category, the target judgment strategy is a judgment strategy corresponding to the preset alarm category; if the alarm category does not conform to the preset alarm category, the target judgment strategy includes at least two judgment strategies; a judgment module configured to process the alarm event according to the target judgment strategy, and obtain a target judgment result, which is used to indicate whether the alarm event is established.
12. The apparatus of claim 11, wherein, The judgment module is further configured to, if the alarm category corresponding to the alarm event does not conform to the preset alarm category, judge the alarm event according to the at least two judgment strategies, and obtain a judgment result corresponding to each of the at least two judgment strategies. According to the judgment result corresponding to each of the at least two judgment strategies, the target judgment result is determined.
13. The apparatus of claim 12, wherein, If the judgment result is used to indicate the probability that the alarm event is established, the judgment module is further configured to, obtain the weight corresponding to each of the at least two judgment strategies; perform weighted sum average calculation on the judgment result corresponding to each of the at least two judgment strategies according to the weight, to obtain the target judgment result, wherein when the probability corresponding to the target judgment result is less than a specified threshold, the target judgment result indicates that the alarm event is not established, and when the probability corresponding to the target judgment result is greater than or equal to the specified threshold, the target judgment result indicates that the alarm event is established.
14. The apparatus of claim 11, wherein, The judgment module is further configured to, if the alarm category corresponding to the alarm event meets the preset alarm category, perform judgment on the alarm event according to the judgment strategy corresponding to the preset alarm category, to obtain the target judgment result.
15. The apparatus of claim 11, wherein, The processing module is further configured to, in the case where no preset alarm category is set, determine each of the judgment strategies as a target judgment strategy.
16. The apparatus of any one of claims 11 to 15, wherein, If the target judgment strategy includes a rule judgment strategy, the judgment module is further configured to, compare the alarm event with preset rule content; in the case where the alarm event is consistent with the comparison with the preset rule content, determine the judgment result of the alarm event under the rule judgment strategy as a judgment result corresponding to the preset rule content.
17. The apparatus of any one of claims 11 to 16, wherein, If the target judgment strategy includes an algorithm judgment strategy, the judgment module is further configured to, perform feature extraction on the alarm event to obtain feature information; input the feature information into a target algorithm, perform clustering or classification on the alarm event, and obtain the judgment result of the alarm event under the algorithm judgment strategy; wherein the feature information includes alarm source IP information, alarm http protocol information, alarm name information, the number of alarms generated by the same source IP within a specified period, the number of alarms generated by the same destination IP within a specified period, the number of alarm categories generated by the same source IP within a specified period, the number of alarm categories generated by the same destination IP within a specified period, the number of alarms of the same alarm category and capable of triggering blocking within a specified period, the number of alarms triggered by the same traffic, the number of alarm categories triggered by the same traffic, the number of protection devices accessed by the same destination IP, and the number of protection devices accessed by the same source IP.
18. The apparatus of any one of claims 11 to 17, wherein, If the target judgment strategy includes a semantic judgment strategy, the judgment module is further configured to, perform keyword extraction on the alarm event to obtain the keyword of the alarm event; input the keyword into a neural network model, perform semantic analysis on the keyword through the neural network model, and obtain the judgment result of the alarm event under the semantic judgment strategy.
19. The apparatus of claim 18, wherein, The device further includes: an extraction module configured to, before determining the target judgment strategy corresponding to the alarm event, extract semantic information in the preset rule content, wherein the semantic information includes feature information and keywords. An updating module is configured to update the target algorithm and the neural network model according to the semantic information, to obtain an updated algorithm research and judgment strategy and an updated semantic research and judgment strategy.
20. The apparatus of claim 19, wherein, The research and judgment module is further configured to, If the alarm category of the alarm event does not conform to the preset alarm category of the algorithm research and judgment strategy and the preset alarm category of the semantic research and judgment strategy, the alarm event is processed according to the updated algorithm research and judgment strategy and the updated semantic research and judgment strategy, respectively, to obtain the target research and judgment result.
21. A computing device, comprising: The computing device includes a processor and a memory, and the processor of the computing device is configured to execute instructions stored in the memory of the computing device, so that the computing device performs the network security alarm research and judgment method according to any one of claims 1 to 10.
22. A cluster of computing devices, characterized in that, The computing device includes a processor and a memory, and the processor of the computing device is configured to execute instructions stored in the memory of the computing device, so that the computing device performs the network security alarm research and judgment method according to any one of claims 1 to 10.
23. A computer-readable storage medium, characterized in that, The computing device includes a processor and a memory, and the processor of the computing device is configured to execute instructions stored in the memory of the computing device, so that the computing device performs the network security alarm research and judgment method according to any one of claims 1 to 10.
24. A computer program product, characterised in that, The computer program product includes instructions that, when executed by a computing device cluster, cause the computing device cluster to perform the network security alarm research and judgment method according to any one of claims 1 to 10. The computer program product includes instructions that, when executed by a computing device cluster, cause the computing device cluster to perform the network security alarm research and judgment method according to any one of claims 1 to 10.
Citation Information
Cited By
Alarm analysis method and device and computer equipment
CN121864497A