Cloud-based container host attack automatic processing method and device, medium and equipment
By installing the Agent intelligent protection module on the cloud container host, generating alarm logs and training alarm rules, and combining it with SIEM and the linkage defense platform, the automatic handling of cloud container host attacks is realized, improving the accuracy of identification and the efficiency of handling, and solving the problem of low efficiency of manual handling in existing technologies.
Patent Information
- Application Number
- CN202510800056.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-10-31
AI Technical Summary
In existing technologies, there is a lack of efficient and automated methods for handling cloud container hosts after they have been compromised. Relying on manual handling is inefficient and its accuracy depends on work experience.
By installing the Agent intelligent protection module on the container host, attack alarm logs are generated, alarm rules are generated using large models, and the attack process is handled automatically or manually by combining the Security Monitoring System (SIEM) and the linkage defense platform, and defensive operations such as blocking container IPs are performed.
It improves the accuracy of identifying and handling container host attack incidents, and realizes a fast and accurate automated handling process, reducing the reliance on manual intervention.
Smart Images

Figure CN120880689A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet technology, and in particular to an automatic method, apparatus, medium and equipment for handling cloud-based container host attacks. Background Technology
[0002] With the rapid development of cloud computing in recent years, the use of public and hybrid cloud containers has become a trend, including common providers such as Alibaba Cloud, Tencent Cloud, Huawei Cloud, and Amazon Web Services (AWS) container clusters. As enterprises fully containerize their production operations, they also face a series of security issues, including how to quickly respond and handle situations and narrow the attack scope after a container host in the cloud is compromised.
[0003] Currently, most attacks on cloud-based container hosts rely on manual handling, which is inefficient and the accuracy of verification depends on the experience of the staff on duty. Therefore, there is an urgent need for an automated method for handling cloud-based container host attacks. Summary of the Invention
[0004] In view of the above problems, the present invention is proposed to provide a cloud-based container host attack automatic handling method, apparatus, medium and device that overcomes or at least partially solves the above problems.
[0005] Other features and advantages of the invention will become apparent from the following detailed description, or may be learned in part by practice of the invention.
[0006] According to a first aspect of the present invention, an automatic handling method for cloud-based container host compromise is provided, the method comprising:
[0007] After receiving a compromise event reported by the Agent intelligent protection module on the container host, a compromise alarm log corresponding to the compromise event is generated;
[0008] Based on the historical data of the attack alarm log, alarm rules for attack events are generated after training a large model.
[0009] The attack alarm logs are obtained through the Security Monitoring System (SIEM), and the attack handling process is matched based on the attack alarm logs and the alarm rules of the attack event. The manual attack handling process is executed, or the automatic attack handling process is executed based on the alarm information and host attack instructions obtained by the linkage defense platform. The alarm information is generated by the Security Monitoring System (SIEM), and the host attack instructions are generated by the manual attack handling process.
[0010] In some embodiments of the present invention, the attack handling process based on the attack alarm log and the attack event alarm rule matching, which executes both manual and automatic attack handling processes, includes:
[0011] The attack alarm log is parsed based on the alarm rules to determine whether the attack event meets the alarm conditions. If the alarm conditions are met, the attack handling process is matched.
[0012] Determine the type of the attack event, and execute either a manual or automatic attack handling process based on the type of attack event.
[0013] In some embodiments of the present invention, the manual handling and breaching process includes:
[0014] Based on the aforementioned attack alarm log, an alarm notification message is simultaneously triggered on the smart terminal;
[0015] The smart terminal identifies the user's operation commands, determines the input blocked container IP, and sends the blocked container IP to the manual secondary review process.
[0016] After the manual secondary review process is passed, a host attack command is sent to the linked defense system, and an automatic attack handling process is executed.
[0017] In some embodiments of the present invention, the automatic attack handling process includes:
[0018] After the joint defense system receives the alarm information generated by the security monitoring system SIEM or the host attack instruction generated by the manual attack handling process, it obtains the basic information corresponding to the blocked container IP.
[0019] Based on the basic information corresponding to the blocked container IP, the corresponding cloud API interface is called to perform attack and defense operations on the container host corresponding to the blocked container IP.
[0020] According to a second aspect of the present invention, a cloud-based container host attack automatic handling device is provided, the cloud-based container host attack automatic handling device comprising:
[0021] The alarm identification module is used to generate an attack alarm log corresponding to the attack event after receiving an attack event reported by the Agent intelligent protection module on the container host.
[0022] The rule generation module is used to generate alarm rules for attack events after training a large model based on the historical data of the attack alarm log;
[0023] The attack handling module is used to obtain the attack alarm logs through the security monitoring system SIEM, and match the attack handling process based on the attack alarm logs and the alarm rules of the attack event. It executes the manual attack handling process or the automatic attack handling process based on the alarm information and host attack command obtained by the linkage defense platform. The alarm information is generated by the security monitoring system SIEM, and the host attack command is generated by the manual attack handling process.
[0024] In some embodiments of the present invention, the breach handling module includes:
[0025] The attack alarm log is parsed based on the alarm rules to determine whether the attack event meets the alarm conditions. If the alarm conditions are met, the attack handling process is matched.
[0026] The type of the attack event is determined, and a manual or automatic attack handling process is executed according to the type of the attack event.
[0027] In some embodiments of the present invention, the breach handling module performs a manual breach handling process including:
[0028] Based on the aforementioned attack alarm log, an alarm notification message is simultaneously triggered on the smart terminal;
[0029] The smart terminal identifies the user's operation commands, determines the input blocked container IP, and sends the blocked container IP to the manual secondary review process.
[0030] After the manual secondary review process is passed, a host attack command is sent to the linked defense system, and an automatic attack handling process is executed.
[0031] In some embodiments of the present invention, the attack handling module performs an automatic attack handling process including:
[0032] After the joint defense system receives the alarm information generated by the security monitoring system SIEM or the host attack instruction generated by the manual attack handling process, it obtains the basic information corresponding to the blocked container IP.
[0033] Based on the basic information corresponding to the blocked container IP, the corresponding cloud API interface is called to perform attack and defense operations on the container host corresponding to the blocked container IP.
[0034] According to a third aspect of the present invention, a computer-readable storage medium is provided, wherein computer program instructions are stored therein, the computer program instructions being loaded and executed by a processor to perform the operations performed by the method described in any of the preceding claims.
[0035] According to a fourth aspect of the present invention, an electronic device is provided, including a processor and a memory, the memory storing computer program instructions executable by the processor, wherein when the processor executes the computer program instructions, it implements the instructions of any of the methods described above.
[0036] The technical solutions provided in the embodiments of the present invention have at least the following technical effects or advantages:
[0037] This invention provides a cloud-based container host attack automatic handling method, apparatus, medium, and device. The cloud-based container host attack automatic handling method described in this invention automatically identifies and confirms whether an alarm needs to be issued and executes subsequent attack handling procedures based on attack events reported by the Agent intelligent protection module on the container host. Furthermore, it executes corresponding attack handling procedures for different types of attack events, which not only greatly improves the accuracy of attack event identification but also enhances the efficiency of event handling. On the other hand, the alarm rules extracted from historical data in the attack alarm logs further improve the accuracy of attack event identification.
[0038] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0040] Figure 1 A flowchart illustrating an automated method for handling cloud-based container host attacks, provided in an embodiment of the present invention.
[0041] Figure 2 This is a schematic diagram of the principle structure of an automatic handling device for cloud-based container host attacks provided in an embodiment of the present invention. Detailed Implementation
[0042] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings.
[0043] The accompanying drawings illustrate various structural schematics according to embodiments of the present disclosure. These drawings are not to scale, and some details have been enlarged for clarity, and some details may have been omitted. The shapes of the various regions and layers shown in the drawings, as well as their relative sizes and positional relationships, are merely exemplary and may deviate from reality due to manufacturing tolerances or technical limitations. Furthermore, those skilled in the art can design regions / layers with different shapes, sizes, and relative positions as needed.
[0044] In the context of this disclosure, when a layer / component is referred to as being "above" another layer / component, that layer / component may be directly above the other layer / component, or there may be an intermediate layer / component between them. Additionally, if a layer / component is "above" another layer / component in one orientation, then when the orientation is reversed, that layer / component may be "below" the other layer / component. In the context of this disclosure, similar or identical components may be denoted by the same or similar reference numerals.
[0045] To better understand the above technical solutions, the following will describe the above technical solutions in detail with reference to specific implementation methods. It should be understood that the embodiments of this disclosure and the specific features in the embodiments are detailed descriptions of the technical solutions of the present invention, rather than limitations on the technical solutions of the present invention. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0046] Figure 1 This is a flowchart illustrating an automated method for handling cloud-based container host attacks, as provided in an embodiment of the present invention. Figure 1 As shown, this cloud-based automated method for handling container host compromise includes the following steps:
[0047] S1. After receiving the attack event reported by the Agent intelligent protection module on the container host, generate the attack alarm log corresponding to the attack event;
[0048] In this embodiment of the invention, the cloud security center HIPS receives the attack events reported by the Agent intelligent protection module on the container host. The cloud security center HIPS is used to monitor the running status of the container host, determine whether the host container has been intruded and infected, and cooperate to realize the security monitoring and attack defense of the cloud host and container. The cloud security center HIPS can be a commercially available cloud security center, such as Tencent Cloud, Alibaba Cloud, Huawei Cloud and VMware private cloud.
[0049] The container host is equipped with an Agent intelligent protection module. This module can automatically or by receiving instructions to execute software or processes for specific tasks. In containerized platforms (such as Kubernetes), Agents are typically services deployed on each node to monitor node status and manage container lifecycles. Agents perform comprehensive security checks on the host and containers, including non-compliant configurations, insecure configurations, intrusion traces, software lists, port lists, process lists, and other information, ensuring the security of the system and the container host. The Agent can ensure the normal operation of the container host and the effective management of resources. In this embodiment of the invention, when the container host is compromised, the Agent intelligent protection module reports the container host breach event to the Cloud Security Center (HIPS). The HIPS generates a breach alarm log corresponding to the breach event and transmits the breach alarm log to the Security Monitoring System (SIEM) for further determination of whether the breach event requires a breach handling process.
[0050] S2. Based on the historical data of the attack alarm log, generate alarm rules for attack events after training a large model;
[0051] To improve the accuracy of identifying the compromise events, this embodiment of the invention collects historical data from the compromise alarm logs and uses this historical data as a training set to input into a large model for model training. Simultaneously, this embodiment of the invention can collaborate with technical personnel to analyze alarm rules using SPL language, extracting fields that may trigger alarm rules as judgment criteria. Based on the actual situation, matching strings, thresholds, or other judgment methods are determined, such as matching the occurrence of a container escape event alarm, entering the alarm handling stage of the linkage platform, and notifying on-duty personnel via DingTalk, thereby generating alarm rules for compromise events. Furthermore, the training set is continuously updated to maintain the applicability of the alarm rules for compromise events, greatly improving the accuracy of identifying the compromise events in this embodiment of the invention.
[0052] S3. Obtain the attack alarm log through the security monitoring system SIEM, and match the attack handling process based on the attack alarm log and the alarm rules of the attack event. Execute the manual attack handling process or execute the automatic attack handling process based on the alarm information and host attack command obtained through the linkage defense platform. The alarm information is generated by the security monitoring system SIEM, and the host attack command is generated by the manual attack handling process.
[0053] The security monitoring system SIEM is used to perform rule judgment on the acquired attack alarm logs according to the alarm rules of the attack event, determine whether the attack event meets the alarm rules, and generate alarm information after the attack event meets the alarm rules. The security monitoring system SIEM transmits the alarm information to the linkage defense platform.
[0054] The coordinated defense platform is used to execute attack handling procedures based on the alarm information or host attack instructions, including but not limited to operations such as blocking and eviction of container hosts, and blocking IPs.
[0055] This invention embodiment matches a compromise handling process based on the compromise alarm log and the alarm rules of the compromise event, and executes a manual compromise handling process and an automatic compromise handling process respectively. The process includes: parsing the compromise alarm log based on the alarm rules to determine whether the compromise event meets the alarm conditions, and matching the compromise handling process if the alarm conditions are met; determining the type of the compromise event, and executing a manual compromise handling process or an automatic compromise handling process according to the type of the compromise event.
[0056] Different handling procedures are required for different types of compromise events. Specifically, for compromise events that may result in false alarms, such as password brute-force attacks and logins from other locations, events that may involve newly added IPs and locations that have not been added to the whitelist in a timely manner and require manual confirmation, and alarms triggered by WAF or cloud firewalls, this embodiment of the invention adopts a manual compromise handling procedure. For compromise events that can be handled automatically (such as compromise events that trigger alarms based on HIPS) or compromise events that have already passed the manual compromise handling procedure, such as container escape, container lateral movement attacks, mining and Trojans, internal network port probing, and container host privilege escalation, an automatic compromise handling procedure is executed.
[0057] The manual attack handling process in this embodiment of the invention includes: synchronously triggering an alarm message on a smart terminal based on the attack alarm log; identifying the user's operation command through the smart terminal, determining the input blocked container IP, and sending the blocked container IP to the manual secondary review process; after the manual secondary review process is passed, sending a host attack command to the linkage defense system, and executing the automatic attack handling process.
[0058] In this embodiment of the invention, the smart terminal is a terminal device with wireless communication capabilities, such as a smartphone, tablet computer, or iPad. The smart terminal synchronously acquires the alarm notification message triggered by the attack alarm log through the wireless communication function. On-duty personnel can use the smart terminal to execute subsequent defense procedures. For example, the alarm notification message is transmitted to the on-duty personnel of the smart terminal through an IM communication system (such as DingTalk, WeChat, etc.). After the on-duty personnel confirm that it is an attack event, they select the attack host defense through an IM communication system (such as a DingTalk robot or a WeChat robot), enter the blocked container IP, and submit it to the manual secondary review process. The system administrator conducts a manual review of the manual secondary review process. After the manual secondary review process is passed, a host attack command is sent to the linkage defense system, and the automatic attack handling process is executed.
[0059] The automatic attack handling process in this embodiment of the invention includes: after the coordinated defense system receives the alarm information generated by the security monitoring system SIEM or the host attack instruction generated by the manual attack handling process, it obtains the basic information corresponding to the blocked container IP; based on the basic information corresponding to the blocked container IP, it calls the corresponding cloud API interface to perform attack defense operations on the container host corresponding to the blocked container IP.
[0060] In this embodiment of the invention, after the coordinated defense system receives an alarm message generated by the security monitoring system SIEM or a host attack command generated by the manual attack handling process, it obtains the basic information corresponding to the blocked container IP. The basic information corresponding to the blocked container IP includes, but is not limited to, the container host ID, hostname, the K8S cluster ID, and the bound security group. Based on the basic information corresponding to the blocked container IP, this embodiment of the invention calls the corresponding cloud API interface with the K8S cluster ID as the parameter to obtain the cluster kubeconfig. Using the obtained kubeconfig with the hostname as the parameter, it performs blocking and expulsion of the compromised container host node. At the same time, it calls the corresponding cloud API interface with the container host ID, the isolation security group, and the original security group as parameters to perform binding the container host to the isolation security group and unbinding the original security group, isolating the network and tracing the attack source.
[0061] For HIPS-triggered attack events, this embodiment of the invention obtains attack alarm logs generated by the cloud security center in real time through the cloud API interface. Since the server that captures the log data is in the same environment as the security monitoring system SIEM, based on the forwarder function of the security monitoring system SIEM, the general forwarder monitors the attack alarm logs and sends them to the heavy forwarder, and then distributes them to the data storage nodes in the cluster. At this point, the cluster's search head can successfully search for the relevant attack alarm logs through the SPL language. The attack alarm logs are all stored in database files, which can be used for large model training of the aforementioned alarm rules.
[0062] In other embodiments of the present invention, after the automatic attack handling process is executed, the manual attack handling process can still be executed again to further improve the accuracy of the attack handling. The manual attack handling process and the automatic attack handling process can be executed separately, simultaneously, or alternately, depending on the actual application requirements. The embodiments of the present invention do not limit this.
[0063] The cloud-based container host attack automatic handling method described in this invention automatically identifies and confirms whether an alert is needed and executes subsequent attack handling procedures based on attack events reported by the Agent intelligent protection module on the container host. Furthermore, it executes corresponding attack handling procedures for different types of attack events, greatly improving both the accuracy of attack event identification and the efficiency of event handling. On the other hand, the alert rules extracted from historical data in the attack alert logs further improve the accuracy of attack event identification. During the automatic attack handling process, the cloud API interface is called through security and operations-related systems to block and expel attacking nodes, and then bind and unbind security groups to achieve defense, isolate the network, and trace the attack source, resulting in excellent defense performance.
[0064] Based on the above embodiments, as a supplement to the above... Figure 1 The present invention provides an embodiment of a cloud-based container host attack automatic handling device, which is similar to the method described above. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices, see reference. Figure 2 As shown, the cloud-based container host compromise automatic handling device includes:
[0065] The alarm identification module 100 is used to generate an attack alarm log corresponding to the attack event after receiving an attack event reported by the Agent intelligent protection module on the container host.
[0066] The rule generation module 200 is used to generate alarm rules for attack events after training a large model based on the historical data of the attack alarm log.
[0067] The attack handling module 300 is used to obtain the attack alarm log through the security monitoring system SIEM, and match the attack handling process based on the attack alarm log and the alarm rules of the attack event. It executes the manual attack handling process or the automatic attack handling process based on the alarm information and host attack command obtained by the linkage defense platform. The alarm information is generated by the security monitoring system SIEM, and the host attack command is generated by the manual attack handling process.
[0068] In this embodiment of the invention, the attack handling module 300 includes: parsing the attack alarm log based on the alarm rules, determining whether the attack event meets the alarm conditions, and matching the attack handling process after the alarm conditions are met; determining the type of the attack event, and executing the manual attack handling process and the automatic attack handling process according to the type of the attack event.
[0069] In this embodiment of the invention, the attack handling module 300 performs a manual attack handling process including: synchronously triggering an alarm message on a smart terminal based on the attack alarm log; identifying the user's operation command through the smart terminal, determining the input blocked container IP, and sending the blocked container IP to the manual secondary review process; after the manual secondary review process is passed, sending a host attack command to the linkage defense system and executing an automatic attack handling process.
[0070] In this embodiment of the invention, the attack handling module 300 performs an automatic attack handling process including: after the linked defense system receives an alarm message generated by the security monitoring system SIEM or a host attack instruction generated by the manual attack handling process, it obtains the basic information corresponding to the blocked container IP; based on the basic information corresponding to the blocked container IP, it calls the corresponding cloud API interface to perform attack defense operations on the container host corresponding to the blocked container IP.
[0071] The cloud-based container host attack automatic handling device described in this embodiment can execute the cloud-based container host attack automatic handling method provided in the above embodiments. The cloud-based container host attack automatic handling device has the corresponding functional steps and beneficial effects of the cloud-based container host attack automatic handling method described in the above embodiments. For details, please refer to the embodiments of the cloud-based container host attack automatic handling method described above. The embodiments of this invention will not be repeated here.
[0072] This invention also provides an electronic device, which may include a processor and a memory, wherein the processor and memory can be connected via a bus or other means. The processor may be a Central Processing Unit (CPU). The processor may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or combinations thereof. The memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the cloud-based container host attack automatic handling method in this invention embodiment. The processor executes various functional applications and data processing by running the non-transitory software programs, instructions, and modules stored in the memory, thereby implementing the cloud-based container host attack automatic handling method in the above method embodiment.
[0073] The memory may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created by the processor, etc. Furthermore, the memory may include high-speed random access memory and non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. One or more modules are stored in the memory and, when executed by the processor, perform the cloud-based container host attack automatic handling method as described in the above method embodiments. Specific details of the above electronic device can be understood by referring to the corresponding descriptions and effects in the above method embodiments, and will not be repeated here. Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it may include the processes of the embodiments of the above methods. The storage medium may be a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), etc.; the storage medium may also include a combination of the above types of memory.
[0074] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.
[0075] Similarly, it should be understood that, in order to streamline this disclosure and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the invention, various features of the invention are sometimes grouped together in a single embodiment, figure, or description thereof. However, this method of disclosure should not be interpreted as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of the invention.
[0076] It should be noted that the above embodiments are illustrative of the invention and not restrictive of the invention, and that those skilled in the art can devise alternative embodiments without departing from the scope of the appended claims.
Claims
1. An automated method for handling cloud-based container host compromises, characterized in that, The cloud-based container host compromise automatic handling method includes: After receiving a compromise event reported by the Agent intelligent protection module on the container host, a compromise alarm log corresponding to the compromise event is generated; Based on the historical data of the attack alarm log, alarm rules for attack events are generated after training a large model. The attack alarm logs are obtained through the Security Monitoring System (SIEM), and the attack handling process is matched based on the attack alarm logs and the alarm rules of the attack event. The manual attack handling process is executed, or the automatic attack handling process is executed based on the alarm information and host attack instructions obtained by the linkage defense platform. The alarm information is generated by the Security Monitoring System (SIEM), and the host attack instructions are generated by the manual attack handling process.
2. The automatic handling method for cloud-based container host attacks according to claim 1, characterized in that, The attack handling process based on the attack alarm logs and attack events, which matches alarm rules, includes both manual and automatic attack handling processes: The attack alarm log is parsed based on the alarm rules to determine whether the attack event meets the alarm conditions. If the alarm conditions are met, the attack handling process is matched. Determine the type of the attack event, and execute either a manual or automatic attack handling process based on the type of attack event.
3. The automatic handling method for cloud-based container host attacks according to claim 2, characterized in that, The manual handling process for breaching the system includes: Based on the aforementioned attack alarm log, an alarm notification message is simultaneously triggered on the smart terminal; The smart terminal identifies the user's operation commands, determines the input blocked container IP, and sends the blocked container IP to the manual secondary review process. After the manual secondary review process is passed, a host attack command is sent to the linked defense system, and an automatic attack handling process is executed.
4. The automatic handling method for cloud-based container host attacks according to claim 3, characterized in that, The automated attack handling process includes: After the joint defense system receives the alarm information generated by the security monitoring system SIEM or the host attack instruction generated by the manual attack handling process, it obtains the basic information corresponding to the blocked container IP. Based on the basic information corresponding to the blocked container IP, the corresponding cloud API interface is called to perform attack and defense operations on the container host corresponding to the blocked container IP.
5. An automated handling device for cloud-based container host attacks, characterized in that, The cloud-based container host compromise automatic handling device includes: The alarm identification module is used to generate an attack alarm log corresponding to the attack event after receiving an attack event reported by the Agent intelligent protection module on the container host. The rule generation module is used to generate alarm rules for attack events after training a large model based on the historical data of the attack alarm log; The attack handling module is used to obtain the attack alarm logs through the security monitoring system SIEM, and match the attack handling process based on the attack alarm logs and the alarm rules of the attack event. It executes the manual attack handling process or the automatic attack handling process based on the alarm information and host attack command obtained by the linkage defense platform. The alarm information is generated by the security monitoring system SIEM, and the host attack command is generated by the manual attack handling process.
6. The cloud-based container host attack automatic handling device according to claim 5, characterized in that, The breach handling module includes: The attack alarm log is parsed based on the alarm rules to determine whether the attack event meets the alarm conditions. If the alarm conditions are met, the attack handling process is matched. The type of the attack event is determined, and a manual or automatic attack handling process is executed according to the type of the attack event.
7. The cloud-based container host attack automatic handling device according to claim 6, characterized in that, The breach handling module performs the manual breach handling process, including: Based on the aforementioned attack alarm log, an alarm notification message is simultaneously triggered on the smart terminal; The smart terminal identifies the user's operation commands, determines the input blocked container IP, and sends the blocked container IP to the manual secondary review process. After the manual secondary review process is passed, a host attack command is sent to the linked defense system, and an automatic attack handling process is executed.
8. The cloud-based container host attack automatic handling device according to claim 7, characterized in that, The attack handling module executes an automatic attack handling process, including: After the joint defense system receives the alarm information generated by the security monitoring system SIEM or the host attack instruction generated by the manual attack handling process, it obtains the basic information corresponding to the blocked container IP. Based on the basic information corresponding to the blocked container IP, the corresponding cloud API interface is called to perform attack and defense operations on the container host corresponding to the blocked container IP.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that are loaded and executed by a processor to perform the operations described in any one of claims 1-4.
10. An electronic device comprising a processor and a memory, characterized in that, The memory stores computer program instructions that can be executed by the processor, and when the processor executes the computer program instructions, it implements the instructions of the method as described in any one of claims 1-4.