Information flow security detection method and device, equipment and medium

By acquiring event recognition results and associated event data from information flow data, and combining them with target security detection strategies from a local knowledge base, the problem of rule engines being unable to detect unknown attacks and false alarms has been solved, achieving more accurate information flow security detection.

CN120979841AActive Publication Date: 2025-11-18ZHEJIANG ELECTRONIC INFORMATION PROD INSPECTION & RES INST (ZHEJIANG INFORMATIZATION & INDUSTRIALIZATION INTEGRATION PROMOTION CENT)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511496533.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2025-11-18
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

In existing technologies, rule engines cannot detect new types of unknown attacks that are not configured, and there are false positives.

Method used

By acquiring the event recognition results of the information flow data to be detected, using the local knowledge base to obtain related event data, and applying the target security detection strategy to perform information flow security detection, if security risks exist, data isolation processing is performed.

Benefits of technology

It improves the accuracy of detecting unknown attacks, reduces the false alarm rate, and achieves more accurate security detection results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979841A_ABST
    Figure CN120979841A_ABST
Patent Text Reader

Abstract

The invention discloses an information flow security detection method and device, equipment and a medium. The method comprises the steps that to-be-detected information flow data corresponding to an information flow detection instruction and an event recognition result of the to-be-detected information flow data are acquired; based on the to-be-detected information flow data and the event identification result, obtaining corresponding associated event data in a local knowledge base; obtaining a target security detection strategy of the associated event data, and performing information flow security detection on the to-be-detected information flow data based on the target security detection strategy to obtain a current detection result; and if it is determined that the current detection result corresponds to the security risk result, performing data isolation processing on the to-be-detected information stream data based on a corresponding target security isolation strategy. According to the embodiment of the invention, after event identification is carried out on the to-be-detected information flow data and associated event data identification is carried out from the local knowledge base, security check is carried out on the to-be-detected information flow data according to the target security detection strategy of the associated event data, and the obtained detection result is more accurate.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and in particular to an information flow security detection method, device, equipment and medium. BACKGROUND

[0002] At present, the network security protection software deployed on a computer device by a user generally adopts a rule engine to detect various requests accessing the computer device or various information flows or data flows sent to the computer device, so as to determine whether various requests, information and data of the computer device exist attack behaviors. However, if the rules configured in the rule engine are limited, the following defects exist: 1) New type unknown attacks not configured in the rule engine cannot be detected; 2) False positives exist. SUMMARY

[0003] Embodiments of the present application provide an information flow security detection method, device, equipment and medium, aiming at solving the problems in the prior art that the rule engine is adopted to detect various requests accessing the computer device or various information flows or data flows sent to the computer device, new type unknown attacks not configured in the rule engine cannot be detected, and false positives exist.

[0004] In a first aspect, an embodiment of the present application provides an information flow security detection method, which comprises: In response to an information flow detection instruction, obtaining to-be-detected information flow data corresponding to the information flow detection instruction; Obtaining event recognition results corresponding to the to-be-detected information flow data; Based on the to-be-detected information flow data and the event recognition results, obtaining associated event data corresponding to the to-be-detected information flow data in a local knowledge base; Obtaining a target security detection strategy of the associated event data, and performing information flow security detection on the to-be-detected information flow data based on the target security detection strategy to obtain a current detection result; If it is determined that the current detection result corresponds to a security risk result, performing data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result.

[0005] In a second aspect, an embodiment of the present application further provides an information flow security detection device, which comprises: An information flow data obtaining unit, configured to, in response to an information flow detection instruction, obtain to-be-detected information flow data corresponding to the information flow detection instruction; An event recognition unit, configured to obtain event recognition results corresponding to the to-be-detected information flow data; An associated event data obtaining unit is configured to obtain, based on the to-be-detected information flow data and the event identification result, associated event data corresponding to the to-be-detected information flow data in a local knowledge base; A security detection unit is configured to obtain a target security detection strategy of the associated event data, and perform information flow security detection on the to-be-detected information flow data based on the target security detection strategy, to obtain a current detection result; A data isolation processing unit is configured to perform data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result, if it is determined that the current detection result corresponds to a security risk result.

[0006] In a third aspect, an embodiment of the present application further provides a computer device, which comprises a memory and a processor, the memory has stored thereon a computer program, and the processor implements the method in the first aspect when executing the computer program.

[0007] In a fourth aspect, an embodiment of the present application further provides a computer readable storage medium, which stores a computer program, the computer program comprises program instructions, and the program instructions can implement the method in the first aspect when executed by a processor.

[0008] The embodiments of the present application provide an information flow security detection method, device, equipment and medium, the method comprising: in response to an information flow detection instruction, obtaining to-be-detected information flow data corresponding to the information flow detection instruction; obtaining an event identification result corresponding to the to-be-detected information flow data; based on the to-be-detected information flow data and the event identification result, obtaining, in a local knowledge base, associated event data corresponding to the to-be-detected information flow data; obtaining a target security detection strategy of the associated event data, and performing information flow security detection on the to-be-detected information flow data based on the target security detection strategy, to obtain a current detection result; and if it is determined that the current detection result corresponds to a security risk result, performing data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result. The embodiments of the present application can perform security check on the to-be-detected information flow data by event identification on the to-be-detected information flow data and identification of associated event data from the local knowledge base, and the detection result obtained is more accurate. BRIEF DESCRIPTION OF DRAWINGS

[0009] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0010] Figure 1 An application scenario of the information flow security detection method provided by the embodiment of the present application is shown in the figure; Figure 2 A flowchart of the information flow security detection method provided by the embodiment of the present application is shown in the figure; Figure 3 A subflowchart of the information flow security detection method provided by the embodiment of the present application is shown in the figure; Figure 4 Another flowchart of the information flow security detection method provided by the embodiment of the present application is shown in the figure; Figure 5 Still another subflowchart of the information flow security detection method provided by the embodiment of the present application is shown in the figure; Figure 6 Still another flowchart of the information flow security detection method provided by the embodiment of the present application is shown in the figure; Figure 7 A schematic block diagram of the information flow security detection device provided by the embodiment of the present application is shown in the figure; Figure 8 A schematic block diagram of the computer device provided by the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0011] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0012] It should be understood that when used in the specification and the appended claims, the terms “comprise” and “include” indicate the presence of described features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0013] It should also be understood that the terms used in the present application specification are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the present application specification and the appended claims, unless otherwise clearly indicated by the context, the singular forms “a”, “an” and “the” are intended to include the plural forms.

[0014] It should be further understood that the term “and / or” used in the present application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes these combinations.

[0015] Please refer to Figure 1 andFigure 2 wherein Figure 1 is a schematic diagram of a scenario of an information flow security detection method according to an embodiment of the present application, Figure 2 is a schematic diagram of a flow of an information flow security detection method according to an embodiment of the present application. As shown in Figure 1 , the information flow security detection method according to an embodiment of the present application is applied in a user terminal 10, and the user terminal 10 is implemented as a firewall device, a gateway, a switch, a desktop computer, a notebook computer, a tablet computer, or the like, and the user terminal 10 is in communication connection with a server 20. As shown in Figure 2 , the method comprises the following steps S110-S150.

[0016] S110, in response to an information flow detection instruction, obtaining to-be-detected information flow data corresponding to the information flow detection instruction.

[0017] In this embodiment, the technical solution is described with the user terminal as the execution subject. An information flow security detection platform (which can also be regarded as a kind of network security protection software platform) is deployed on the user terminal. When the user starts the information flow security detection platform on the user terminal, the to-be-detected information flow data (which can also be understood as traffic data, which can be a request sent by another terminal to the user terminal, or a data stream or information flow sent by another terminal to the user terminal) sent to the user terminal can be detected in real time to determine whether it has an attack behavior on the user terminal.

[0018] S120, obtaining an event recognition result corresponding to the to-be-detected information flow data.

[0019] In this embodiment, after the information flow security detection platform in the user terminal obtains the to-be-detected information flow data, the event recognition model pre-deployed therein can be used to perform event recognition on the to-be-detected information flow data, so as to obtain the event recognition result.

[0020] In an embodiment, as shown in Figure 3 , step S120 comprises: S121, obtaining a current log stream corresponding to the to-be-detected information flow data, and a log event sequence corresponding to the current log stream; S122, obtaining a preset weighted random mask model, performing weighted mask processing on the log event sequence through the weighted random mask model to obtain a weighted mask processing sequence; S123, inputting the weighted mask processing sequence into a pre-trained classification model to obtain the event recognition result.

[0021] In this embodiment, when the information flow security detection platform obtains the to-be-detected information flow data, the current log stream corresponding to the to-be-detected information flow data can be obtained first, and the current log stream includes a plurality of event logs, each event log at least includes a timestamp, a source IP / destination IP, a protocol type, an operation code and the like. At this time, the log event sequence can be formed by concatenating the log events in the chronological order of the timestamps. Then, the weighted mask processing sequence is obtained by performing weighted mask processing on the log event sequence by using the weighted random mask model in the event recognition model; for example, the mask probability of each source IP / destination IP in the log event sequence is 50% to 80% by using the weighted random mask model, and the mask probability of other fields is less than the mask probability of the source IP / destination IP. After the above weighted mask processing is completed, the weighted mask processing sequence realizes compression of the log volume compared with the log event sequence, and the key information features are retained. Finally, the weighted mask processing sequence is input into the classification model (such as a random forest, a decision tree model and the like) pre-trained in the event recognition model to obtain the event recognition result; for example, the obtained event recognition result is document download, external connection to other servers, or abnormal script execution and the like.

[0022] In this embodiment, if only the event recognition is performed on the to-be-detected information flow data, it is not enough to accurately determine whether there is a security risk result. At this time, the associated event data corresponding to the to-be-detected information flow data can be further obtained in the local knowledge base by combining the to-be-detected information flow data and the event recognition result, that is, the associated event data similar to the to-be-detected information flow data is obtained, so that the security detection result of the to-be-detected information flow data can be further determined by combining the associated event data.

[0023] In this embodiment, if only the event recognition is performed on the to-be-detected information flow data, it is not enough to accurately determine whether there is a security risk result. At this time, the associated event data corresponding to the to-be-detected information flow data can be further obtained in the local knowledge base by combining the to-be-detected information flow data and the event recognition result, that is, the associated event data similar to the to-be-detected information flow data is obtained, so that the security detection result of the to-be-detected information flow data can be further determined by combining the associated event data.

[0024] In an embodiment, as shown in Figure 4 The step S130 includes: S131, obtaining the event entity node corresponding to the to-be-detected information flow data and the weighted mask processing sequence, taking the weighted mask processing sequence as the attribute data of the event entity node, and updating the event entity node; S132, obtaining the current knowledge graph of the local knowledge base and the entity nodes included in the current knowledge graph; S133, obtaining the association relationship between the event entity node and the entity nodes included in the current knowledge graph, to construct the edge relationship between the event entity node and the entity nodes in the current knowledge graph; S134, acquire a target edge relationship with the largest correlation value of the edge relationship of the entity node in the current knowledge graph, and acquire a target entity node corresponding to the target edge relationship; S135, acquire the node data of the target entity node as the correlation event data.

[0025] In the embodiment, after the information flow security detection platform acquires the to-be-detected information flow data, it can also acquire the corresponding event entity node (such as including source IP / destination IP, user ID, and the like), and can also acquire the corresponding weighted mask processing sequence as the attribute data of the event entity node to update the event entity node. When the entity node construction for the to-be-detected information flow data is completed, the current knowledge graph stored in the form of a knowledge graph locally can also be acquired, and all entity nodes included therein can also be acquired.

[0026] Then, the correlation relationship (that is, the edge relationship) of the event entity node and all entity nodes included in the current knowledge graph can be acquired. Specifically, the edge generation method based on space-time correlation can be used to construct the correlation relationship of the event entity node and all entity nodes included in the current knowledge graph. In the space-time correlation edge generation method, when calculating the correlation relationship of the event entity node and an entity node, the time tightness and the spatial correlation need to be calculated respectively. When calculating the time tightness of two nodes, the exponential calculation result of the difference between the time stamps of the two nodes is calculated (for example, when calculating the time tightness of two nodes, the calculation formula is TE=exp(|t1-t2| / 60), where t1 is the time stamp of the event entity node, t2 is the time stamp of the entity node, and TE is the time tightness of the two nodes). When calculating the spatial correlation of two nodes, it is determined according to whether the same source IP / destination IP corresponds between the two nodes (when the same source IP / destination IP corresponds between the two nodes, the value of the spatial correlation is 1, otherwise the value is 0). Finally, the time tightness and the spatial correlation of the two nodes are weighted and summed based on a preset weighted summation parameter set to obtain the correlation relationship of the event entity node and all entity nodes included in the current knowledge graph.

[0027] When the construction of the correlation relationship of the event entity node and all entity nodes included in the current knowledge graph is completed, a target edge relationship with the largest correlation value of the edge relationship of the entity node in the current knowledge graph can also be acquired, and a target entity node corresponding to the target edge relationship can also be acquired, so that the target entity node is filtered from the current knowledge graph. Finally, the node data of the target entity node is used as the correlation event data, and the source IP / destination IP, user ID, and the like included in the target entity node are also known at this time, which can be used for subsequent further analysis.

[0028] In an embodiment, step S130 is followed by: acquiring preset enhanced injection feature data, and adding the enhanced injection feature data to the correlation event data to update the correlation event data.

[0029] In this embodiment, in order to further increase the data features of the correlation event data, preset enhanced injection feature data, such as attack threat intelligence, can also be injected into the correlation event data, so that the correlation event data achieves evidence strengthening.

[0030] S140, acquiring a target security detection strategy of the correlation event data, and performing information flow security detection on the to-be-detected information flow data based on the target security detection strategy to obtain a current detection result.

[0031] In this embodiment, after the correlation event data is acquired, the target security detection strategy used for security detection before acquisition can be continued to be called, and information flow security detection is performed on the to-be-detected information flow data through the target security detection strategy, so as to obtain a current detection result. Through this way of referring to the security detection strategy of the correlation event data, the target security detection strategy required can be quickly determined from multiple security detection strategies.

[0032] In an embodiment, as shown in Figure 5 step S140 includes: S141, acquiring a target large language model corresponding to the correlation event data; S142, inputting the correlation event data or the to-be-detected information flow data as a prompt word into the target large language model to perform information flow security detection, to obtain the current detection result.

[0033] In this embodiment, if multiple large language models are deployed in the information flow security detection platform, and each large language model can be regarded as a separate intelligent agent (different intelligent agents can be understood as different security protection experts, and each intelligent agent has its own security protection field, such as being good at processing malicious scripts, process injection, container escape, and registry backdoor, etc.). When the target large language model corresponding to the correlation event data is acquired, the correlation event data or the to-be-detected information flow data can be input as a prompt word into the target large language model to perform information flow security detection, to obtain the current detection result. Of course, if the to-be-detected information flow data is not a structured data, it can also be replaced by a current log stream corresponding to the to-be-detected information flow data, and the current log stream is input as a structured data into the target large language model to perform information flow security detection, to obtain the current detection result. For example, the obtained current detection result is a phishing document implantation text, data exfiltration through a tunnel, etc.

[0034] In the embodiment, if the current detection result belongs to one of the plurality of security risk types, it is determined that the current detection result corresponds to the security risk result, and the target security isolation strategy corresponding to the current detection result is used to perform data isolation processing on the to-be-detected information flow data, so as to avoid data attacks on the user terminal.

[0035] In the embodiment, if the current detection result belongs to one of the plurality of security risk types, it is determined that the current detection result corresponds to the security risk result, and the target security isolation strategy corresponding to the current detection result is used to perform data isolation processing on the to-be-detected information flow data, so as to avoid data attacks on the user terminal.

[0036] In an embodiment, as shown in FIG. 1, step S150 includes: Figure 6 S151, based on the current security risk type of the current detection result, obtaining the target security isolation strategy corresponding to the current security risk type from a plurality of preset security isolation strategies; S152, constructing an isolation area based on the target security isolation strategy, and performing data isolation processing on the to-be-detected information flow data.

[0037] In the embodiment, when the current security risk type of the current detection result is obtained, and the security risk types to which the plurality of preset security isolation strategies correspond are known, the target security isolation strategy corresponding to the same security risk type as the current security risk type is obtained from the plurality of preset security isolation strategies. Then, an isolation area such as a sandbox area is constructed based on the target security isolation strategy, and the to-be-detected information flow data is processed in the isolation area, so as to realize data security protection.

[0038] In an embodiment, after step S140, the method further includes: If it is determined that the current detection result corresponds to the security risk result, the target access area corresponding to the to-be-detected information flow data is obtained, and the to-be-detected information flow data is released to the target access area.

[0039] In the embodiment, if the current detection result does not belong to any of the plurality of security risk types, it is determined that the current detection result corresponds to the security risk result, and the target access area corresponding to the to-be-detected information flow data is obtained, and then the to-be-detected information flow data is released to the target access area for normal data processing.

[0040] ​It can be seen that the embodiment implementing the method can perform security check on the to-be-detected information flow data by the target security detection policy of the associated event data after event recognition is performed on the to-be-detected information flow data and associated event data is recognized from the local knowledge base, and the detection result obtained is more accurate.

[0041] Figure 7 is a schematic block diagram of an information flow security detection device provided by an embodiment of the present application. As shown in Figure 7 Corresponding to the above information flow security detection method, the present application also provides an information flow security detection device 100. The information flow security detection device 100 comprises units for executing the above information flow security detection method. Please refer to Figure 7 The information flow security detection device 100 comprises an information flow data acquisition unit 110, an event recognition unit 120, an associated event data acquisition unit 130, a security detection unit 140, and a data isolation processing unit 150.

[0042] The information flow data acquisition unit 110 is configured to acquire to-be-detected information flow data corresponding to an information flow detection instruction in response to the information flow detection instruction.

[0043] In this embodiment, the technical solution is described with the user terminal as the execution subject. An information flow security detection platform (which can also be regarded as a network security protection software platform) is deployed on the user terminal. When the user starts the information flow security detection platform on the user terminal, the to-be-detected information flow data (which can also be understood as traffic data, which can be a request sent by another terminal to the user terminal, or a data stream or information flow sent by another terminal to the user terminal) sent to the user terminal can be detected in real time to determine whether it has an attack behavior on the user terminal.

[0044] The event recognition unit 120 is configured to acquire an event recognition result corresponding to the to-be-detected information flow data.

[0045] In this embodiment, after the information flow security detection platform in the user terminal acquires the to-be-detected information flow data, the event recognition model pre-deployed therein can be used to perform event recognition on the to-be-detected information flow data, thereby obtaining an event recognition result.

[0046] In an embodiment, the event recognition unit 120 is specifically configured to: acquire a current log stream corresponding to the to-be-detected information flow data, and a log event sequence corresponding to the current log stream; acquire a preset weighted random mask model, and perform weighted mask processing on the log event sequence by using the weighted random mask model to obtain a weighted mask processing sequence; input the weighted mask processing sequence into a pre-trained classification model to obtain the event identification result.

[0047] In the embodiment, when the information flow security detection platform obtains the to-be-detected information flow data, the current log stream corresponding to the to-be-detected information flow data can be obtained first, and the current log stream includes a plurality of event logs, each of which includes at least a timestamp, a source IP / destination IP, a protocol type, an operation code and the like. At this time, the log event sequence can be formed by concatenating the log events in chronological order of the timestamps. Then, the weighted mask processing sequence of the log event sequence is obtained by using a weighted random mask model in the event identification model. For example, the mask probability of each source IP / destination IP in the log event sequence is 50% to 80% by using the weighted random mask model, and the mask probability of other fields is less than that of the source IP / destination IP. After the above weighted mask processing is completed, the weighted mask processing sequence is compressed in log volume compared with the log event sequence, and the key information features are retained. Finally, the weighted mask processing sequence is input into a classification model (such as a random forest, a decision tree model, etc.) pre-trained in the event identification model to obtain the event identification result. For example, the obtained event identification result is document download, external connection to other servers, or abnormal script execution, etc.

[0048] The associated event data acquisition unit 130 is configured to acquire, based on the to-be-detected information flow data and the event identification result, associated event data corresponding to the to-be-detected information flow data in a local knowledge base.

[0049] In the embodiment, if the event identification of the to-be-detected information flow data is not enough to accurately determine whether there is a security risk result, the associated event data corresponding to the to-be-detected information flow data in the local knowledge base can be further acquired by combining the to-be-detected information flow data and the event identification result, that is, the associated event data similar to the to-be-detected information flow data is acquired, so that the security detection result of the to-be-detected information flow data can be further determined by combining the associated event data.

[0050] In an embodiment, the associated event data acquisition unit 130 is specifically configured to: acquire the event entity node corresponding to the to-be-detected information flow data and the weighted mask processing sequence, and use the weighted mask processing sequence as attribute data of the event entity node to update the event entity node; acquire a current knowledge graph of the local knowledge base and an entity node included in the current knowledge graph; obtaining an association relationship of the event entity node and an entity node included in the current knowledge graph to construct an edge relationship of the event entity node and the entity node in the current knowledge graph; obtaining a target edge relationship with a maximum association value of the edge relationship of the entity node in the current knowledge graph, and obtaining a target entity node corresponding to the target edge relationship; obtaining node data of the target entity node as the associated event data.

[0051] In the embodiment, after the information flow security detection platform obtains the to-be-detected information flow data, the corresponding event entity node (such as including source IP / destination IP, user ID, and the like) can also be obtained, and the corresponding weighted mask processing sequence can also be obtained as attribute data of the event entity node to update the event entity node. After the construction of the entity node for the to-be-detected information flow data is completed, the current knowledge graph stored in the form of a knowledge graph locally can also be obtained, and all entity nodes included therein can also be obtained.

[0052] Then, the association relationship (that is, the edge relationship) of the event entity node and all entity nodes included in the current knowledge graph can be obtained, and the association relationship of the event entity node and all entity nodes included in the current knowledge graph can be constructed by using an edge generation method based on time-space association. In the edge generation method based on time-space association, when calculating the association relationship of the event entity node and an entity node, the time density and the spatial correlation of the two nodes need to be calculated respectively, and when calculating the time density of the two nodes, the exponential calculation result of the difference between the time stamps of the two nodes is calculated (for example, when calculating the time density of the two nodes, the calculation formula is TE=exp(|t1-t2| / 60), where t1 is the time stamp of the event entity node, t2 is the time stamp of the entity node, and TE is the time density of the two nodes), and when calculating the spatial correlation of the two nodes, whether the two nodes correspond to the same source IP / destination IP is determined (when the two nodes correspond to the same source IP / destination IP, the value of the spatial correlation is 1, otherwise the value is 0), and finally the time density and the spatial correlation of the two nodes are weighted and summed based on a preset weighted summation parameter set to obtain the association relationship of the event entity node and all entity nodes included in the current knowledge graph.

[0053] When the construction of the association relationship between the event entity node and all entity nodes included in the current knowledge graph is completed, the target edge relationship with the largest association value with the edge relationship of the entity node in the current knowledge graph can be further obtained, and the target entity node corresponding to the target edge relationship is obtained, so as to filter out the target entity node from the current knowledge graph. Finally, the node data of the target entity node is used as the associated event data, and the source IP / destination IP, user ID and other information included in the target entity node are known at this time, which can be used for further analysis in the future.

[0054] In an embodiment, the associated event data acquisition unit 130 is further configured to: acquire preset enhanced injection feature data, and add the enhanced injection feature data to the associated event data to update the associated event data.

[0055] In this embodiment, in order to further increase the data features of the associated event data, the preset enhanced injection feature data can also be injected into the associated event data, such as the enhanced injection feature data being attack threat intelligence, so that the associated event data realizes evidence strengthening.

[0056] The security detection unit 140 is configured to acquire a target security detection strategy of the associated event data, and perform information flow security detection on the to-be-detected information flow data based on the target security detection strategy to obtain a current detection result.

[0057] In this embodiment, after the associated event data is acquired, the target security detection strategy for security detection of the associated event data before acquisition can be further called, and the information flow security detection is performed on the to-be-detected information flow data through the target security detection strategy, so as to obtain the current detection result. Through this way of referring to the security detection strategy of the associated event data, the target security detection strategy required can be quickly determined from a plurality of security detection strategies.

[0058] In an embodiment, the security detection unit 140 is specifically configured to: acquire a target large language model corresponding to the associated event data; input the associated event data or the to-be-detected information flow data as a prompt word into the target large language model to perform information flow security detection, and obtain the current detection result.

[0059] In the embodiment, if multiple large language models are deployed in the information flow security detection platform, and each large language model can be regarded as a separate agent (different agents can be understood as different security protection experts, and each agent has its own security protection field, such as being good at processing malicious scripts, process injection, container escape, registry backdoor, etc.). When the target large language model corresponding to the associated event data is obtained, the associated event data or the to-be-detected information flow data can be input as a prompt word to the target large language model for information flow security detection to obtain the current detection result. Of course, if the to-be-detected information flow data is not a structured data, it can also be replaced by the current log stream corresponding to the to-be-detected information flow data, and the structured data of the current log stream is input to the target large language model for information flow security detection to obtain the current detection result. For example, the obtained current detection result is a phishing document implantation text, data exfiltration through a tunnel, etc.

[0060] The data isolation processing unit 150 is configured to, if it is determined that the current detection result corresponds to a security risk existing result, perform data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result.

[0061] In the embodiment, if multiple security risk types are preset in the information flow security detection platform, and the current detection result belongs to one of the multiple security risk types, it can be determined that the current detection result corresponds to a security risk existing result, and at this time, the target security isolation strategy corresponding to the current detection result can be used to perform data isolation processing, thereby avoiding data attacks on the user terminal.

[0062] In an embodiment, the data isolation processing unit 150 is specifically configured to: obtain, based on a current security risk type of the current detection result, the target security isolation strategy corresponding to the current security risk type from multiple preset security isolation strategies; construct an isolation area based on the target security isolation strategy, and perform data isolation processing on the to-be-detected information flow data.

[0063] In the embodiment, when the current security risk type of the current detection result is obtained, and the security risk types to which the multiple preset security isolation strategies are respectively directed are known, the target security isolation strategy corresponding to the same security risk type as the current security risk type can be obtained from the multiple preset security isolation strategies. Then, an isolation area such as a sandbox area is constructed based on the target security isolation strategy, and the to-be-detected information flow data is subjected to data isolation processing in the isolation area, thereby realizing data security protection.

[0064] In an embodiment, the information flow security detection apparatus 100 further comprises: a data release processing unit, configured to acquire a target access region corresponding to the to-be-detected information flow data and release the to-be-detected information flow data to the target access region if it is determined that the current detection result corresponds to the result of no security risk.

[0065] In the embodiment, if multiple security risk types are preset in the information flow security detection platform and the current detection result does not belong to any of the multiple security risk types, it can be determined that the current detection result corresponds to the result of no security risk. At this time, the target access region corresponding to the to-be-detected information flow data can be acquired first, and then the to-be-detected information flow data is released to the target access region for normal data processing.

[0066] It can be seen that the embodiment of the apparatus performs event recognition on the to-be-detected information flow data, and performs associated event data recognition from the local knowledge base. Then, the target security detection strategy of the associated event data is used to perform security check on the to-be-detected information flow data, so that the detection result is more accurate.

[0067] The information flow security detection apparatus described above can be implemented in the form of a computer program, which can run on a computer device as shown in Figure 8 .

[0068] Please refer to Figure 8 , Figure 8 is a schematic block diagram of a computer device provided by an embodiment of the present application. The computer device integrates any of the information flow security detection apparatuses provided by the embodiments of the present application.

[0069] Please refer to Figure 8 , the computer device 400 includes a processor 402, a memory and a network interface 405 connected through a system bus 401, wherein the memory can include a storage medium 403 and an internal memory 404.

[0070] The storage medium 403 can store an operating system 4031 and a computer program 4032. The computer program 4032 includes program instructions, which when executed, can cause the processor 402 to perform an information flow security detection method.

[0071] The processor 402 is configured to provide computing and control capabilities to support the operation of the entire computer device.

[0072] The memory 404 provides an environment for the running of the computer program 4032 in the storage medium 403, and the computer program 4032 is executed by the processor 402 to enable the processor 402 to perform the information flow security detection method described above.

[0073] The network interface 405 is used for network communication with other devices. Those skilled in the art can understand that, Figure 8 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0074] The processor 402 is configured to run the computer program 4032 stored in the memory to implement the information flow security detection method described above.

[0075] It should be understood that, in the embodiments of the present application, the processor 402 can be a central processing unit (CPU), and the processor 402 can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0076] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments of the method can be completed by a computer program instructing related hardware. The computer program includes program instructions, and the computer program can be stored in a storage medium, which is a computer readable storage medium. The program instructions are executed by at least one processor in the computer system to implement the process steps of the above-mentioned embodiments of the method.

[0077] Therefore, the present application also provides a computer readable storage medium. The computer readable storage medium stores a computer program, wherein the computer program includes program instructions. The program instructions are executed by the processor to enable the processor to perform the information flow security detection method described above.

[0078] The storage medium can be a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk, and various computer readable storage media that can store program codes.

[0079] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in the above description in a general manner. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0080] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of each unit is only a logical functional division, and actual implementation can have another division manner. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0081] The steps in the method embodiments of the present application can be adjusted, combined and reduced in sequence according to actual needs. The units in the device embodiments of the present application can be combined, divided and reduced according to actual needs. In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0082] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts that make contributions to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a terminal or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application.

[0083] The above description is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for information flow security detection, characterized in that, include: In response to an information flow detection command, acquire the information flow data to be detected corresponding to the information flow detection command; Obtain the event identification result corresponding to the information stream data to be detected; Based on the information stream data to be detected and the event recognition result, obtain the associated event data corresponding to the information stream data to be detected from the local knowledge base; The target security detection strategy for the associated event data is obtained, and information flow security detection is performed on the information flow data to be detected based on the target security detection strategy to obtain the current detection result; If it is determined that the current detection result corresponds to a result with security risks, then the data to be detected will be isolated based on the target security isolation strategy corresponding to the current detection result.

2. The method according to claim 1, characterized in that, The step of obtaining the event recognition result corresponding to the information stream data to be detected includes: Obtain the current log stream corresponding to the information stream data to be detected, and the log event sequence corresponding to the current log stream; Obtain a preset weighted random mask model, and perform weighted masking processing on the log event sequence using the weighted random mask model to obtain a weighted masking processing sequence; The weighted masking sequence is input into a pre-trained classification model to obtain the event recognition result.

3. The method according to claim 2, characterized in that, The step of obtaining associated event data corresponding to the information stream data to be detected from the local knowledge base based on the information stream data to be detected and the event recognition result includes: Obtain the event entity node corresponding to the information stream data to be detected and the weighted mask processing sequence, and use the weighted mask processing sequence as the attribute data of the event entity node to update the event entity node; Obtain the current knowledge graph of the local knowledge base and the entity nodes included in the current knowledge graph; Obtain the association relationship between the event entity node and the entity nodes included in the current knowledge graph, so as to construct the edge relationship between the event entity node and the entity nodes in the current knowledge graph; Obtain the target edge relationship that has the maximum association value with the edge relationship of the entity node in the current knowledge graph, and obtain the target entity node corresponding to the target edge relationship; Obtain the node data of the target entity node as the associated event data.

4. The method according to claim 1, characterized in that, After the step of obtaining the associated event data corresponding to the information stream data to be detected from the local knowledge base based on the information stream data to be detected and the event recognition result, the method further includes: Obtain preset enhanced injection feature data and add the enhanced injection feature data to the associated event data to update the associated event data.

5. The method according to claim 1 or 4, characterized in that, The target security detection strategy for acquiring the associated event data, and the information flow security detection performed on the information flow data to be detected based on the target security detection strategy to obtain the current detection result, includes: Obtain the target large language model corresponding to the associated event data; The associated event data or the information flow data to be detected is input as prompt words into the target large language model for information flow security detection, and the current detection result is obtained.

6. The method according to claim 5, characterized in that, The process of isolating the data stream to be detected based on the target security isolation strategy corresponding to the current detection result includes: Based on the current security risk type of the current detection result, the target security isolation strategy corresponding to the current security risk type is obtained from multiple preset security isolation strategies; An isolation zone is constructed based on the target security isolation strategy, and the data stream data to be detected is processed for data isolation.

7. The method according to claim 1, characterized in that, After the steps of acquiring the target security detection strategy for the associated event data, and performing information flow security detection on the information flow data to be detected based on the target security detection strategy to obtain the current detection result, the method further includes: If it is determined that the current detection result corresponds to a result without security risks, then the target access area corresponding to the information flow data to be detected is obtained, and the information flow data to be detected is allowed to the target access area.

8. An information flow security detection device, characterized in that, include: The information flow data acquisition unit is used to acquire the information flow data to be detected corresponding to the information flow detection command in response to the information flow detection command; An event recognition unit is used to acquire event recognition results corresponding to the information stream data to be detected; The associated event data acquisition unit is used to acquire associated event data corresponding to the information stream data to be detected from a local knowledge base based on the information stream data to be detected and the event recognition result. A security detection unit is used to acquire the target security detection strategy of the associated event data, and to perform information flow security detection on the information flow data to be detected based on the target security detection strategy, so as to obtain the current detection result; The data isolation processing unit is used to perform data isolation processing on the information stream data to be detected based on the target security isolation strategy corresponding to the current detection result if it is determined that the current detection result corresponds to a result with security risks.

9. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the information flow security detection method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions, which, when executed by a processor, can implement the information flow security detection method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Automatic penetration testing method and system based on knowledge graph

    CN114866358A

  • Network attack path prediction and defense method and device, computer equipment and medium

    CN119484135A

  • Visual early warning method and system for network security event

    CN120474836A

  • System and Method for Distributed Denial of Service Identification and Prevention

    US20100082513A1