Heterogeneous network security data fusion management method and system supporting streaming monitoring
By constructing a standardized security event flow and performing dynamic correlation analysis, setting fusion threat indicators, and triggering real-time response commands, the problem of unifying the processing of multi-source heterogeneous security data has been solved. This has enabled real-time fusion processing and dynamic response of security data in heterogeneous networks, thereby improving security management efficiency.
Patent Information
- Application Number
- CN202511152152.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-18
- Publication Date
- 2025-11-11
AI Technical Summary
Existing technologies suffer from difficulties in processing multi-source heterogeneous security data in a unified manner, insufficient real-time correlation analysis capabilities, and lagging response management, resulting in low efficiency in network security management.
By generating a set of raw data streams for distributed stream processing, a standardized security event stream is constructed, dynamic correlation analysis is performed, cross-data source fusion threat indicators are set, and real-time response commands are triggered to achieve data fusion management.
It enables real-time fusion processing and dynamic response of security data in heterogeneous networks, improving the real-time correlation analysis capability and response efficiency of security data.
Smart Images

Figure CN120934845A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data management technology, and more specifically to a heterogeneous network security data fusion management method and system that supports streaming monitoring. Background Technology
[0002] Network security management involves various security devices and monitoring systems, generating data from complex sources in diverse formats, including logs, traffic data, and alarm records. The lack of a unified structure and processing interface across these data sources makes data access and integration difficult. Analysis mechanisms fail to dynamically correlate data during its generation, resulting in a lack of real-time insight into security events. Security response strategies do not integrate with a global data view and threat levels, leading to response delays and policy mismatches. Overall security protection efficiency is limited. Summary of the Invention
[0003] This application provides a heterogeneous network security data fusion management method and system that supports streaming monitoring, which addresses the technical problems in the prior art such as difficulty in unified processing of multi-source heterogeneous security data, insufficient real-time correlation analysis capabilities, and lagging response management.
[0004] In view of the above problems, this application provides a method and system for heterogeneous network security data fusion management that supports streaming monitoring.
[0005] The first aspect of this application provides a method for managing heterogeneous network security data fusion that supports streaming monitoring, the method comprising: Based on multiple data sources, a set of original data streams is generated by accessing heterogeneous security data streams from multiple sources. Distributed stream processing is then performed on the original data streams to construct standardized security event streams. Dynamic correlation is performed on the standardized security event streams, and multi-dimensional real-time correlation analysis is conducted based on the correlation results. Cross-data source fusion threat indicators are set. Real-time response commands are triggered based on the fusion threat indicators, and data fusion management of heterogeneous networks is performed through the real-time response commands to output a global security situation view.
[0006] A second aspect of this application provides a heterogeneous network security data fusion management system supporting streaming monitoring, the system comprising: The event stream construction module is used to generate a raw data stream set based on multiple data sources and implement access to heterogeneous security data streams from multiple sources. Based on the raw data stream set, distributed stream processing is performed to construct a standardized security event stream. The correlation analysis module is used to dynamically correlate the standardized security event streams, perform multi-dimensional real-time correlation analysis based on the event stream correlation results, and set cross-data source fusion threat indicators. The fusion management module is used to trigger real-time response commands based on the fusion threat indicators, perform data fusion management of heterogeneous networks through the real-time response commands, and output a global security situation view.
[0007] One or more technical solutions provided in this application have at least the following technical effects or advantages: This application implements access to multi-source heterogeneous security data streams from multiple data sources to generate a raw data stream set. Based on this raw data stream set, distributed stream processing is performed to construct a standardized security event stream. Dynamic correlation is performed based on the standardized security event streams, and multi-dimensional real-time correlation analysis is conducted based on the event stream correlation results to set cross-data source fusion threat indicators. Real-time response commands are triggered based on the fusion threat indicators, and data fusion management of the heterogeneous network is performed through these real-time response commands, outputting a global security situation view. This invention solves the technical problems of difficulty in unified processing of multi-source heterogeneous security data, insufficient real-time correlation analysis capabilities, and lagging response management in existing technologies. Through standardized processing of multi-source heterogeneous data streams, real-time correlation analysis across data sources, and a response mechanism driven by fusion threat indicators, it achieves the technical effect of real-time fusion processing and dynamic response of security data in heterogeneous networks. Attached Figure Description
[0008] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0009] Figure 1 This is a flowchart illustrating a heterogeneous network security data fusion management method supporting streaming monitoring, provided in an embodiment of this application. Figure 2 This is a schematic diagram of the heterogeneous network security data fusion management system supporting streaming monitoring, provided in an embodiment of this application.
[0010] Figure labeling: Event flow construction module 11, correlation analysis module 12, fusion management module 13. Detailed Implementation
[0011] This application addresses the technical problems of difficulty in unified processing of multi-source heterogeneous security data, insufficient real-time correlation analysis capabilities, and lagging response management in existing technologies by providing a heterogeneous network security data fusion management method and system that supports streaming monitoring. Through standardized processing of multi-source heterogeneous data streams, real-time correlation analysis across data sources, and a response mechanism driven by fusion threat indicators, it achieves the technical effect of real-time fusion processing and dynamic response of security data in heterogeneous networks.
[0012] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0013] It should be noted that any variation of the terms "comprising" and "having" is intended to cover non-exclusive inclusion, for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such processes, methods, products, or devices.
[0014] Example 1, as Figure 1 As shown, this application provides a heterogeneous network security data fusion management method that supports streaming monitoring, the method comprising: Step S100: Based on multiple data sources, implement access to multi-source heterogeneous security data streams to generate an original data stream set, perform distributed stream processing based on the original data stream set, and construct a standardized security event stream.
[0015] In this embodiment, firstly, multi-source heterogeneous security data streams are accessed based on multiple data sources. A protocol adapter cluster is used to connect to an asynchronous message queue, enabling concurrent reception of multi-source data fragments from firewalls, intrusion detection systems, terminal log platforms, etc., generating multi-source heterogeneous data streams. Next, an invalid filtering mechanism is used to clean the data streams, removing erroneous formats, missing fields, or invalid information, retaining structurally complete multi-source heterogeneous security data streams. Then, based on the device type, access protocol, or application scenario of each data source, the data source type is marked, and the cleaned data is uniformly encapsulated into a set of original data streams.
[0016] Based on the original data stream set, distributed stream processing is performed. This process relies on a field mapping rule base to standardize the mapping of data fields from different sources and construct a unified namespace to achieve semantic consistency of fields. Subsequently, combined with dynamic data standards, dynamic normalization processing unifies the data units, formats, and structures, generating a standardized normalized dataset. This dataset is then traversed line by line, and a security attribute matching mechanism is used to extract key security attribute parameters such as IP address, MAC address, port number, timestamp, and alarm type. Finally, based on these key attribute parameters, the original data stream set is filtered and encapsulated to construct a standardized security event stream with consistent structure, clear semantics, and support for real-time analysis.
[0017] Furthermore, the method provided in the application embodiments, which generates an original data stream set based on multiple data sources and accessing multi-source heterogeneous secure data streams, further includes: The protocol adapter cluster concurrently accesses the asynchronous message queue to receive multi-source data fragments, thereby obtaining multi-source heterogeneous data streams; invalid filtering is performed on the multi-source heterogeneous data streams to determine multi-source heterogeneous secure data streams; the multi-source heterogeneous secure data streams are marked according to data source type to generate the original data stream set.
[0018] In this embodiment, a protocol adapter cluster is first used to connect to various data sources, supporting multiple communication protocols such as Syslog, NetFlow, SNMP, and Kafka. A concurrent access mechanism is employed to connect to an asynchronous message queue, receiving asynchronously generated multi-source data fragments from multiple devices. These data fragments contain network security event information in different formats and semantics. After being converted into a uniformly processed format by the protocol adapter cluster, they are aggregated into a multi-source heterogeneous data stream.
[0019] Subsequently, preprocessing is performed on the multi-source heterogeneous data streams. An invalid filtering mechanism is applied to determine the validity of the data content and remove redundancy, eliminating invalid data such as null fields, erroneous timestamps, and missing key attribute fields. Only security-related information that meets the requirements of structural integrity and field accuracy is retained, resulting in a multi-source heterogeneous security data stream with a clear structure and explicit semantics. To support subsequent processing and traceability management, the multi-source heterogeneous security data streams are uniformly encoded and classified according to dimensions such as device identifiers, network area numbers, and protocol types of their source systems. Data source type tagging is performed, adding identifiable tags to data streams from different sources. Finally, the tagging and encapsulation of the above multi-source heterogeneous security data streams are completed, outputting a set of raw data streams with a unified structure that can be invoked by distributed processing.
[0020] Furthermore, the method provided in the application embodiments, which performs distributed stream processing based on the original data stream set to construct a standardized security event stream, further includes: Distributed stream processing is performed on the original data stream set according to the field mapping rule library, and a unified namespace is constructed based on the processing results; the processing results are dynamically normalized to obtain a normalized dataset; security attribute matching is performed on the normalized dataset based on the unified namespace to extract key security attribute parameters; the original data stream set is filtered and encapsulated according to the key security attribute parameters to construct the standardized security event stream.
[0021] In this embodiment, distributed stream processing is first performed on the raw data stream set using a field mapping rule base. The field mapping rule base predefines the mapping relationships between various security device data fields and unified data model fields, covering common fields such as source IP, destination IP, protocol type, timestamp, and event level. Within the distributed stream processing framework, each raw data stream undergoes structural transformation and field renaming according to the field mapping rules, unifying the field formats and semantic definitions of different data sources, thereby constructing a unified namespace with a consistent data structure and naming system.
[0022] The results of the distributed processing are then dynamically normalized. This process is based on a preset normalization strategy, which standardizes and adjusts the differences in units (such as bytes and kilobytes) and formats (such as timestamp format and IP representation) between different data sources, eliminates differences in structure and numerical hierarchy, outputs data items with standard structure, and generates a normalized dataset with a unified format.
[0023] Then, based on the constructed unified namespace, the normalized dataset is traversed and processed. The security attribute matching mechanism is invoked to filter fields and perform semantic discrimination on data entries, extracting attribute information that is of key significance to security analysis, including but not limited to source address, destination address, port number, protocol type, event behavior code, etc., and uniformly extracting key security attribute parameters.
[0024] Finally, based on the extracted key security attribute parameters, a structured repackaging operation is performed on the original data stream set. This process includes steps such as field reorganization, redundant field removal, and standard field completion to ensure that each output data has a unified field structure, semantic integrity, and contextual relevance. The result after encapsulation is a standardized security event stream.
[0025] Step S200: Dynamically correlate the standardized security event flow, perform multi-dimensional real-time correlation analysis based on the event flow correlation results, and set cross-data source fusion threat indicators.
[0026] In this embodiment, when performing dynamic correlation processing based on standardized security event streams, feature analysis is first performed to extract multiple feature benchmark dimensions with security discrimination significance. Then, a real-time rule engine is used to analyze the event stream, matching it with a predefined threat rule set to generate a primary alert event set with preliminary security anomaly characteristics. This primary alert event set is then dynamically correlated with the extracted feature benchmark dimensions to obtain event stream correlation results with associated behavioral paths and multi-source causal chains. Based on these event stream correlation results, user or system behavioral baseline information is established, while real-time deviation information that significantly deviates from this baseline is identified. By aggregating and analyzing the behavioral baseline information and real-time deviation information, persistent attack identification is achieved, and typical persistent attack patterns are constructed. Finally, multi-dimensional threat detection is performed around this persistent attack pattern, and the analysis results are fused to output a unified threat index that expresses the cross-data source attack posture.
[0027] Furthermore, the method provided in the application embodiment, which involves dynamically associating events based on the standardized security event stream, performing multi-dimensional real-time association analysis based on the event stream association results, and setting cross-data source fusion threat indicators, also includes: Feature analysis is performed on the standardized security event flow to determine multiple feature benchmark dimensions. A predefined threat rule set is matched using a real-time rule engine to generate a primary alert event set. The primary alert event set is dynamically correlated with the multiple feature benchmark dimensions to obtain event flow correlation results. Behavioral baseline information is modeled based on the event flow correlation results, and real-time deviation information is detected based on the event flow correlation results. The behavioral baseline information and the real-time deviation information are aggregated and analyzed, and persistent attack identification is performed based on the aggregation results to determine persistent attack patterns. Multi-dimensional threat detection is performed based on the persistent attack patterns to generate the fused threat index.
[0028] In this embodiment, based on a standardized security event flow, the event flow is first segmented in batches according to a fixed time window. Field aggregation and frequency statistics methods are used to analyze each segment of data, extracting multiple feature benchmark dimensions for behavior judgment, including connection behavior patterns, abnormal session characteristics, threat intelligence matching degree, and user entity behavior. Specifically, connection behavior patterns are obtained by analyzing the number of communications between the source IP and destination IP within a unit of time, the distribution of ports used, and the protocol type. Abnormal session characteristics are identified by calculating session duration, average data length, and connection frequency to identify communication behaviors significantly different from normal business characteristics. Threat intelligence matching degree is determined by comparing each item with a local malicious IP list or a blacklist field in an external intelligence database to determine if a known attack source exists. User entity behavior is established based on the resource access path, usage time period, and operating system call changes of each user or terminal.
[0029] Subsequently, a real-time rule engine matches each standardized security event stream, invoking an internally maintained predefined threat rule set. This rule set contains numerous matching rules with attack pattern characteristics, such as "the number of failed login attempts from the same IP within a unit of time exceeds a threshold," "a terminal continuously accesses multiple different subnet ports," and "the target domain name exists in the threat intelligence database." The rules can be based on Boolean logic, regular expressions, and field combinations, offering scalability and real-time performance. Standardized events are matched against these rules item by item, and events that meet the conditions are labeled as abnormal, outputting a preliminary alert event set. Each preliminary alert event includes its original fields, matching rule ID, trigger time, and other metadata, indicating that the event has initially exhibited security risk characteristics.
[0030] Building upon this foundation, the initial alarm event set is jointly analyzed with the aforementioned extracted feature benchmark dimensions, and dynamic correlation is performed. In this process, using source address, time window, and behavior type as key fields, and based on event aggregation and sliding window mechanisms, events with continuity or commonalities in time, space, and behavioral patterns are clustered or tracked. Multiple scattered alarm events are merged into a group of event paths with related behavioral chains, outputting an event flow correlation result. This event flow correlation result includes event sequences, correlation fields, and contextual logic, used to construct attack chains and behavioral profiles.
[0031] Based on the aforementioned event flow correlation results, behavioral baseline information is modeled. This behavioral baseline is a stable model constructed by statistically analyzing historical normal behavior. Historical behavior templates are generated using fixed-period behavioral field statistics (such as average access frequency, commonly used ports, and communication peers). Simultaneously, a field difference analysis is performed between the current event flow correlation results and the behavioral baseline to identify significant anomalies in communication patterns, behavioral paths, access times, etc., extracting them as real-time deviation information to characterize the degree of difference between current behavior and historical stable behavior.
[0032] Next, the baseline behavioral information and real-time deviation information are fused and aggregated for analysis. Specifically, by comparing factors such as field coverage, the number of deviation fields, and the span of the behavioral path, it is determined whether the current deviation exhibits attack evolution characteristics. If the analysis results match a typical attack development pattern, such as a "scanning—access—persistent connection—data outflow" path involving multiple users or terminals, it is identified as a persistent attack pattern. This pattern is presented in a structured form representing the attack stages, which can be used to track the attack process and assist in early warning.
[0033] Finally, multi-dimensional threat detection is performed based on persistent attack patterns. In this process, topological threat detection and behavioral threat detection are performed separately based on the identified persistent attack patterns, obtaining topological anomaly information and behavioral anomaly information respectively. Then, weights are assigned to the two types of anomaly information to generate corresponding weight coefficients. Based on these weight coefficients, the topological and behavioral information are then fused together, and finally, a unified fused threat index representing the attack range and intensity is set and output.
[0034] Furthermore, in the method provided in the application embodiments, the process of performing multi-dimensional threat detection based on the persistent attack pattern to generate the fused threat index further includes: Topology threat detection is performed based on the persistent attack mode to obtain topology anomaly information; behavioral threat detection is performed based on the persistent attack mode to obtain behavioral anomaly information; multiple weight coefficients are generated by weighting the topology anomaly information and the behavioral anomaly information according to the multiple weight coefficients; the topology anomaly information and the behavioral anomaly information are linked and fused according to the multiple weight coefficients to set the fused threat index.
[0035] In this embodiment, based on the identified persistent attack patterns, topology threat detection is first performed. This involves reconstructing the communication trajectories in the standardized security event stream, such as sourceIP, destinationIP, and communicationPath, to map them to the existing network topology. A depth-first search (DFS) algorithm is then used to traverse possible attack paths, identifying whether the paths cross multiple subnets, involve unauthorized relay nodes, or involve unauthorized access. For example, if an attack path spans three independent protection domains and includes an unregistered jump server IP as an intermediate node, the path is identified as an abnormal path. Information such as path span, number of communication nodes involved, and whether boundary isolation policies are violated is recorded to generate topology anomaly information containing fields such as abnormal path sequence, node hop count, and unauthorized connection identifiers.
[0036] Subsequently, continuous analysis is performed based on fields such as eventType, userID, and operationSequence to perform behavioral threat detection and reconstruct the time sequence of user behaviors or host operations within the event. By sorting by time and matching fields, the presence of abnormal operation sequences is identified, such as consecutive operations like remote login, file encryption, batch access, or network communication within a short period. These operations are statistically analyzed, extracting data such as the number of consecutively triggered events, the number of rules hit, the operation duration, and the scope of resources involved. The output is structured behavioral anomaly information, with fields including the set of abnormal operations, event duration, number of triggers, and scope of behavior.
[0037] After that, data analysis is performed on the above topological anomaly information and behavior anomaly information respectively, and weight assignment is executed. The structural statistical method is used to quantify the topological path, including calculating the number of network segments spanned by the abnormal path (such as 3 segments), the total number of communication nodes (such as 5), and the number of illegal access jumps (such as 1). For behavior anomalies, the number of rule hits (such as 6), the continuous operation time (such as 20 minutes), and the number of operation types (such as 3 types) are counted. According to the configuration rules, the topological dimension is weighted 0.6, and the behavior dimension is weighted 0.4. Multiple weight coefficients are generated and bound to the corresponding anomaly information fields respectively for weighted calculation in subsequent fusion processing.
[0038] On this basis, field alignment and content merging are performed on the topological anomaly information and behavior anomaly information for联动融合. During the fusion process, according to the field matching conditions such as IP address, time interval, and event number, the event sets related in the two types of information are identified and merged into a unified structure. Subsequently, each anomaly item is weighted and summarized according to the aforementioned weight coefficients, and the influence degree in the two dimensions of the network structure and operation behavior is comprehensively evaluated. Finally, a fusion threat indicator with a unified field format is generated. This indicator includes fields such as abnormal path identifier, related user or host, impact scope description, number of events, path span value, operation density value, and risk level label, which can be used to directly represent the breadth, intensity, and potential impact of the currently identified attack.
[0039] Step S300: Trigger a real-time response instruction according to the fusion threat indicator, and perform data fusion management on the heterogeneous network through the real-time response instruction to output a global security situation view.
[0040] In the embodiment of the present application, after generating the fusion threat indicator, first, taking the fusion threat indicator as a trigger condition, execute the real-time response instruction generation process, that is, trigger the real-time response instruction according to the fusion threat indicator. In this process, confidence evaluation is performed through keyword fields such as path span, abnormal behavior intensity, and affected host range in the fusion threat indicator, and the indicator confidence level is output. Subsequently, impact analysis is performed according to the confidence level, specific threat impact range parameters are extracted, and comprehensive control analysis is carried out accordingly to set multiple threat levels.
[0041] The threat level is then used as an index to query a preset response strategy matrix, matching the corresponding handling plan to the current threat level and automatically generating a real-time response command containing response action parameters. This command can include operations such as disconnection, isolation, rate limiting, and session termination, adapting to different types of heterogeneous network nodes and protocol environments. Subsequently, the heterogeneous network is fused and managed through the real-time response command, that is, response actions are executed simultaneously in terms of network structure, communication paths, and device status, realizing the blocking of potential attack paths, isolation of affected nodes, and dynamic adjustment of data flow rules.
[0042] After the response operation is completed, the generated response and handling results are recorded and fed back into the standardized security event flow for secondary analysis and optimization, constructing an event optimization mapping table. This mapping table is used to retrospectively identify misjudgments, calibrate the identification model, and drive rule correction and context information completion. Finally, threat indicators, response and handling results, and event flow data are comprehensively integrated to dynamically draw a global security posture view.
[0043] Furthermore, in the method provided in the application embodiments, triggering a real-time response command based on the fusion threat indicator, performing data fusion management on the heterogeneous network through the real-time response command, and outputting a global security posture view, further includes: A confidence assessment is performed on the fused threat indicators to generate indicator confidence levels. Impact analysis is then conducted on the fused threat indicators based on these confidence levels to determine threat impact range parameters. Comprehensive control analysis is performed based on these threat impact range parameters, and multiple threat levels are set. A response strategy matrix is constructed, and the multiple threat levels are used as indexes to retrieve and match the response strategy matrix, determining real-time response instructions. These real-time response instructions include response and handling action parameters. The response and handling action parameters are executed to dynamically block malicious attacks on heterogeneous networks, generating response and handling results. These response and handling results are fed back to the standardized security event stream for analysis and optimization, obtaining an event optimization mapping table. False alarm backtracking is performed based on the event optimization mapping table to construct the global security situation view.
[0044] In this embodiment, after generating the converged threat index, a confidence assessment is first performed on the index. A rule-based threshold mapping method is invoked to segment and analyze key fields in the converged threat index. For example, path span values are divided into 0–2, 3–5, and 6 and above; the number of abnormal behaviors is divided into 1–5, 6–10, and 10 and above; and the affected host range is classified into single node, single subnet, and cross-network segment. Based on these field combinations, the corresponding index confidence level is determined and output as a standard for measuring the current threat intensity.
[0045] Subsequently, the sourceIP, destinationIP, assetGroup, and other fields contained in the standardized security event flow are compared and analyzed with the network topology. Impact analysis is then performed to identify whether the threat involves sensitive nodes such as critical business systems, core routing devices, and border gateways. Specific threat impact parameters are output, such as single-terminal impact, cross-subnet propagation, and multi-domain access.
[0046] After completing the dual assessment of confidence level and scope of impact, a comprehensive control analysis is conducted, and the aforementioned two results are combined and mapped into multiple threat levels, such as medium threat, high threat, and very high threat. Each threat level corresponds to a set of preset response strategy priorities.
[0047] Next, the process of constructing the response strategy matrix begins. First, scenario mapping and clustering are performed based on multiple threat levels to extract typical attack paths, resource types, and communication patterns, forming a preliminary threat scenario classification system. Then, based on this classification system, constraints on control boundaries, device types, and protocol characteristics in the current heterogeneous network structure are identified, generating response action constraint instructions, such as which devices support session termination and which only allow port blocking. Subsequently, multi-dimensional matching is performed between the aforementioned response action constraint instructions and the threat scenario classification system to generate a corresponding scenario-action association list. This list undergoes consistency review and conflict detection to identify conflict scenarios, such as simultaneously implementing isolation and allowance on the same target, generating corresponding mutually exclusive data pairs. Finally, based on these mutually exclusive data pairs, the scenario-action associations are updated and integrated to construct a response strategy matrix with a two-dimensional mapping relationship between threat level and action.
[0048] Based on the real-time identified threat level, matching items are retrieved from the response policy matrix to generate real-time response instructions containing explicit response and handling parameters, such as disconnecting connections, blocking IPs, and restricting protocol communication. Subsequently, various security control device interfaces (such as firewalls, intrusion prevention systems, and endpoint control systems) are invoked to execute the response operations, completing the dynamic blocking of malicious activity on the current heterogeneous network and preventing further threat spread.
[0049] After the response operation is executed, the execution result, the target device's feedback status, and the effectiveness of the action are recorded, generating a structured response and handling result. This response and handling result is written back to the standardized security event stream to update event identifiers and status labels, and to generate an event optimization mapping table to clarify the correspondence between events and responses.
[0050] Subsequently, a false alarm backtracking was performed based on the mapping table. By analyzing historical records such as handling failures, misses, and duplicate responses, problems in the matching logic were identified, such as rules with too broad coverage or unclear field combination logic, thereby driving the adjustment and optimization of the rule base.
[0051] Finally, by combining threat indicators, response and handling results, and event optimization mapping tables, a visualization layer is generated to construct a global security situation view, which intuitively displays threat distribution, response trajectory, handling efficiency, and remaining risks, realizing a dynamic closed loop of threat identification, policy response, and situation management.
[0052] Furthermore, in the method provided in the application embodiments, the process of constructing the response strategy matrix further includes: Based on the multiple threat levels, scenario mapping and clustering are performed to define a threat scenario classification system; response constraint analysis is conducted on heterogeneous networks according to the threat scenario classification system to generate response action constraint instructions; multi-dimensional matching is performed between the response action constraint instructions and the threat scenario classification system to determine a scenario-action association list; conflict detection is performed based on the scenario-action association list to generate mutually exclusive data pairs; the scenario-action association list is updated according to the mutually exclusive data pairs to construct the response strategy matrix.
[0053] In this embodiment, after setting multiple threat levels, scenario mapping clustering is first performed based on key fields (including path span value, number of abnormal behaviors, affected host range, event trigger frequency, etc.) in historical event samples and fused threat indicators. This step uses rule classification and field combination identification methods to cluster threat events with similar indicator characteristics, extract typical attack behavior paths and operation sequences, and form structured classification labels, such as intranet lateral penetration scenarios, cross-network segment remote control scenarios, and boundary data leakage scenarios. Finally, a unified format threat scenario classification system is constructed, which serves as an intermediate bridge connecting threat levels and response strategies to guide subsequent action configurations.
[0054] After defining the threat scenario classification system, response constraint analysis is conducted on the control boundaries, device types, and protocol support capabilities in the current heterogeneous network based on its content. This analysis uses fields such as assetType, deviceCapability, protocolSupport, and accessControlRange to determine the feasibility of responses for each type of network object. For example, in an internal network lateral movement scenario, if the corresponding deviceCapability field is marked as supporting only logging, then connection blocking actions are not supported. The scenario and object capability matching relationship is traversed item by item, and standardized response action constraint instructions are output. Each instruction includes a scenario label, restricted action identifier, restriction reason field, and suggested alternatives to constrain the boundary conditions of the response strategy.
[0055] After receiving the response action constraint instructions, a multi-dimensional matching operation is performed based on the field scenario label, threat level, device category, and supported action types to generate a preliminary scenario-action association list. This list structure consists of multiple executable response actions corresponding to each scenario label, with each action corresponding to a set of target device objects. For example, in a boundary data breach scenario, three response actions are matched: blocking the destination IP, closing a specified port, and initiating packet mirroring, with their applicable device types and action restrictions indicated.
[0056] Next, a consistency check is performed on the scene-action association list, and conflict detection is executed. This detection uses the action target field, action time window, and control type as input dimensions to analyze whether there are conflicts between control commands. For example, if a sourceIP is marked as allowed to communicate in action A, but is also listed as a blocked object in action B, it is considered a control conflict. The conflict rule set is invoked, and through field comparison and operation intent parsing, structured mutually exclusive data pairs are output, including the conflict action pair ID, conflict field position, and conflict type description.
[0057] Finally, based on the generated mutually exclusive data, the scenario-action association list is updated and pruned. Actions that cannot be executed in parallel are removed, conflicting actions are replaced with higher-priority strategies, and compliant and controllable response paths are retained to form the final structure. This structure is formatted as a two-dimensional mapping table, namely the response strategy matrix, where the row index is a combination of threat level and scenario label, and the column fields are response action name, target device type, action execution interface, and action restriction conditions.
[0058] In summary, the embodiments of this application have at least the following technical effects: This application implements access to multi-source heterogeneous security data streams from multiple data sources to generate a raw data stream set. Based on this raw data stream set, distributed stream processing is performed to construct a standardized security event stream. Dynamic correlation is performed based on the standardized security event streams, and multi-dimensional real-time correlation analysis is conducted based on the event stream correlation results to set cross-data source fusion threat indicators. Real-time response commands are triggered based on the fusion threat indicators, and data fusion management of the heterogeneous network is performed through these real-time response commands, outputting a global security situation view. This invention solves the technical problems of difficulty in unified processing of multi-source heterogeneous security data, insufficient real-time correlation analysis capabilities, and lagging response management in existing technologies. Through standardized processing of multi-source heterogeneous data streams, real-time correlation analysis across data sources, and a response mechanism driven by fusion threat indicators, it achieves the technical effect of real-time fusion processing and dynamic response of security data in heterogeneous networks.
[0059] Example 2, based on the same inventive concept as the heterogeneous network security data fusion management method supporting streaming monitoring in the foregoing examples, such as... Figure 2 As shown, this application provides a heterogeneous network security data fusion management system that supports streaming monitoring. The system and method embodiments in this application are based on the same inventive concept. The system includes: The event flow construction module 11 is used to generate a raw data flow set based on multiple data sources and implement access to multi-source heterogeneous security data flows, and to perform distributed stream processing based on the raw data flow set to construct a standardized security event flow; the correlation analysis module 12 is used to dynamically correlate the standardized security event flow, perform multi-dimensional real-time correlation analysis based on the event flow correlation results, and set cross-data source fusion threat indicators; the fusion management module 13 is used to trigger real-time response commands based on the fusion threat indicators, perform data fusion management of heterogeneous networks through the real-time response commands, and output a global security situation view.
[0060] Furthermore, the system is also used to implement the following functions: The protocol adapter cluster concurrently accesses the asynchronous message queue to receive multi-source data fragments, thereby obtaining multi-source heterogeneous data streams; invalid filtering is performed on the multi-source heterogeneous data streams to determine multi-source heterogeneous secure data streams; the multi-source heterogeneous secure data streams are marked according to data source type to generate the original data stream set.
[0061] Furthermore, the system is also used to implement the following functions: Distributed stream processing is performed on the original data stream set according to the field mapping rule library, and a unified namespace is constructed based on the processing results; the processing results are dynamically normalized to obtain a normalized dataset; security attribute matching is performed on the normalized dataset based on the unified namespace to extract key security attribute parameters; the original data stream set is filtered and encapsulated according to the key security attribute parameters to construct the standardized security event stream.
[0062] Furthermore, the system is also used to implement the following functions: Feature analysis is performed on the standardized security event flow to determine multiple feature benchmark dimensions. A predefined threat rule set is matched using a real-time rule engine to generate a primary alert event set. The primary alert event set is dynamically correlated with the multiple feature benchmark dimensions to obtain event flow correlation results. Behavioral baseline information is modeled based on the event flow correlation results, and real-time deviation information is detected based on the event flow correlation results. The behavioral baseline information and the real-time deviation information are aggregated and analyzed, and persistent attack identification is performed based on the aggregation results to determine persistent attack patterns. Multi-dimensional threat detection is performed based on the persistent attack patterns to generate the fused threat index.
[0063] Furthermore, the system is also used to implement the following functions: Topology threat detection is performed based on the persistent attack mode to obtain topology anomaly information; behavioral threat detection is performed based on the persistent attack mode to obtain behavioral anomaly information; multiple weight coefficients are generated by weighting the topology anomaly information and the behavioral anomaly information according to the multiple weight coefficients; the topology anomaly information and the behavioral anomaly information are linked and fused according to the multiple weight coefficients to set the fused threat index.
[0064] Furthermore, the system is also used to implement the following functions: A confidence assessment is performed on the fused threat indicators to generate indicator confidence levels. Impact analysis is then conducted on the fused threat indicators based on these confidence levels to determine threat impact range parameters. Comprehensive control analysis is performed based on these threat impact range parameters, and multiple threat levels are set. A response strategy matrix is constructed, and the multiple threat levels are used as indexes to retrieve and match the response strategy matrix, determining real-time response instructions. These real-time response instructions include response and handling action parameters. The response and handling action parameters are executed to dynamically block malicious attacks on heterogeneous networks, generating response and handling results. These response and handling results are fed back to the standardized security event stream for analysis and optimization, obtaining an event optimization mapping table. False alarm backtracking is performed based on the event optimization mapping table to construct the global security situation view.
[0065] Furthermore, the system is also used to implement the following functions: Based on the multiple threat levels, scenario mapping and clustering are performed to define a threat scenario classification system; response constraint analysis is conducted on heterogeneous networks according to the threat scenario classification system to generate response action constraint instructions; multi-dimensional matching is performed between the response action constraint instructions and the threat scenario classification system to determine a scenario-action association list; conflict detection is performed based on the scenario-action association list to generate mutually exclusive data pairs; the scenario-action association list is updated according to the mutually exclusive data pairs to construct the response strategy matrix.
[0066] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.
[0067] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
[0068] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.
Claims
1. A heterogeneous network security data fusion management method supporting streaming monitoring, characterized in that, The method includes: Based on multiple data sources, access to multi-source heterogeneous security data streams is implemented to generate a raw data stream set. Based on the raw data stream set, distributed stream processing is performed to construct a standardized security event stream. Dynamic correlation is performed based on the standardized security event flow, and multi-dimensional real-time correlation analysis is conducted based on the event flow correlation results to set cross-data source fusion threat indicators; Real-time response commands are triggered based on the fusion threat indicators, and data fusion management of heterogeneous networks is performed through the real-time response commands to output a global security situation view.
2. The heterogeneous network security data fusion management method supporting streaming monitoring as described in claim 1, characterized in that, The method for generating a raw data stream set based on multiple data source access heterogeneous secure data streams includes: By concurrently accessing the asynchronous message queue through the protocol adapter cluster, multi-source data fragments are received to obtain multi-source heterogeneous data streams; Based on the aforementioned multi-source heterogeneous data streams, invalid filtering is performed to determine the multi-source heterogeneous secure data streams. The original data stream set is generated by labeling the multi-source heterogeneous secure data streams according to the data source type.
3. The heterogeneous network security data fusion management method supporting streaming monitoring as described in claim 1, characterized in that, Based on the original data stream set, distributed stream processing is performed to construct a standardized security event stream. The method includes: Perform distributed stream processing on the original data stream set according to the field mapping rule library, and construct a unified namespace based on the processing results; The processing results are dynamically normalized to obtain a normalized dataset; Based on the unified namespace, the normalized dataset is traversed to perform security attribute matching and extract key security attribute parameters. The raw data stream set is filtered and encapsulated according to the key security attribute parameters to construct the standardized security event stream.
4. The heterogeneous network security data fusion management method supporting streaming monitoring as described in claim 1, characterized in that, Dynamic correlation is performed based on the standardized security event flow, and multi-dimensional real-time correlation analysis is conducted based on the event flow correlation results. Cross-data source fusion threat indicators are set. The method includes: Based on the standardized security event flow, feature analysis is performed to determine multiple feature benchmark dimensions; A primary alert event set is generated by matching predefined threat rule sets with a real-time rule engine; The event flow association results are obtained by dynamically associating the primary alarm event set with the multiple feature benchmark dimensions. Based on the event flow association results, model behavioral baseline information and detect real-time deviation information based on the event flow association results; The baseline behavioral information and the real-time deviation information are aggregated and analyzed. Based on the aggregation results, persistent attacks are identified, and persistent attack patterns are determined. Multidimensional threat detection is performed based on the persistent attack pattern to generate the fused threat index.
5. The heterogeneous network security data fusion management method supporting streaming monitoring as described in claim 4, characterized in that, The method for performing multi-dimensional threat detection based on the persistent attack pattern and generating the fused threat index includes: Topology threat detection is performed based on the described persistent attack pattern to obtain topology anomaly information; Behavioral threat detection is performed based on the described persistent attack pattern to obtain abnormal behavior information; Based on the topological anomaly information and the behavioral anomaly information, multiple weight coefficients are generated by weighting them. The topological anomaly information and the behavioral anomaly information are linked and fused according to the multiple weighting coefficients, and the fusion threat index is set.
6. The heterogeneous network security data fusion management method supporting streaming monitoring as described in claim 1, characterized in that, The method includes triggering a real-time response command based on the fused threat indicators, performing data fusion management on the heterogeneous network through the real-time response command, and outputting a global security posture view. A confidence assessment is performed on the fusion threat indicators to generate indicator confidence levels. An impact analysis is then conducted on the fusion threat indicators based on the indicator confidence levels to determine the threat impact range parameters. Based on the aforementioned threat impact range parameters, a comprehensive management and control analysis is conducted, and multiple threat levels are set. A response strategy matrix is constructed, and the multiple threat levels are used as indexes to search and match the response strategy matrix to determine real-time response instructions, which include response and handling action parameters. The response and handling action parameters are executed to maliciously and dynamically block the heterogeneous network, and a response and handling result is generated. The response and handling results are fed back to the standardized security event flow for analysis and optimization to obtain an event optimization mapping table. False alarms are backtracked based on the event optimization mapping table to construct the global security situation view.
7. The heterogeneous network security data fusion management method supporting streaming monitoring as described in claim 6, characterized in that, The process of constructing the response strategy matrix includes the following methods: Based on the multiple threat levels, scenario mapping and clustering are performed to define a threat scenario classification system; Based on the threat scenario classification system, perform response constraint analysis on heterogeneous networks and generate response action constraint instructions. Based on the response action constraint command and the threat scenario classification system, a multi-dimensional matching is performed to determine the scenario-action association list; Conflict detection is performed based on the scene-action association list to generate mutually exclusive data pairs; The scene-action association list is updated according to the mutually exclusive data pairs to construct the response strategy matrix.
8. A heterogeneous network security data fusion management system supporting streaming monitoring, characterized in that: The system is used to execute the heterogeneous network security data fusion management method supporting streaming monitoring as described in any one of claims 1-7, and the system includes: The event stream construction module is used to generate a raw data stream set based on multiple data sources and implement access to multi-source heterogeneous security data streams, perform distributed stream processing based on the raw data stream set, and construct a standardized security event stream. The correlation analysis module is used to dynamically correlate events based on the standardized security event flow, perform multi-dimensional real-time correlation analysis based on the event flow correlation results, and set cross-data source fusion threat indicators. The convergence management module is used to trigger real-time response commands based on the convergence threat indicators, perform data convergence management on heterogeneous networks through the real-time response commands, and output a global security situation view.
Citation Information
Cited By
Data processing method and system based on industrial internet-oriented identification analysis middleware
CN121542051A