Information flow security detection method, device, equipment and medium
By obtaining event identification results and associated event data in information flow security detection, and using target security detection strategies for information flow security detection, the problem of rule engines being unable to detect unknown attacks and false alarms is solved, achieving more accurate security detection and isolation processing.
Patent Information
- Application Number
- CN202511496533.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-20
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-10-20
AI Technical Summary
In existing technologies, rule engines cannot detect new types of unknown attacks that are not configured and there are false positives.
By acquiring the event recognition results of the information flow data to be detected, related event data is obtained from the local knowledge base, and information flow security detection is performed using the target security detection strategy. If security risks exist, data isolation processing is carried out.
It improves the accuracy of detecting unknown attacks, reduces the false alarm rate, and achieves more accurate security detection results.
Smart Images

Figure CN120979841B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and in particular to an information flow security detection method, device, equipment and medium. BACKGROUND
[0002] At present, the network security protection software deployed on a computer device by a user generally adopts a rule engine to detect various requests accessing the computer device or various information flows or data flows sent to the computer device, so as to determine whether various requests, information and data of the computer device exist attack behaviors. However, if the rules configured in the rule engine are limited, the following defects exist:
[0003] 1) New type unknown attacks not configured in the rule engine cannot be detected;
[0004] 2) There is a false alarm situation. SUMMARY
[0005] Embodiments of the present application provide an information flow security detection method, device, equipment and medium, aiming at solving the problems in the prior art that the rule engine is adopted to detect various requests accessing the computer device or various information flows or data flows sent to the computer device, new type unknown attacks not configured in the rule engine cannot be detected, and there is a false alarm situation.
[0006] In a first aspect, an embodiment of the present application provides an information flow security detection method, comprising:
[0007] In response to an information flow detection instruction, obtaining to-be-detected information flow data corresponding to the information flow detection instruction;
[0008] Obtaining an event recognition result corresponding to the to-be-detected information flow data;
[0009] Based on the to-be-detected information flow data and the event recognition result, obtaining associated event data corresponding to the to-be-detected information flow data in a local knowledge base;
[0010] Obtaining a target security detection strategy of the associated event data, and performing information flow security detection on the to-be-detected information flow data based on the target security detection strategy, to obtain a current detection result;
[0011] If it is determined that the current detection result corresponds to a security risk result, performing data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result.
[0012] In a second aspect, an embodiment of the present application further provides an information flow security detection device, comprising:
[0013] An information flow data acquisition unit is configured to acquire, in response to an information flow detection instruction, to-be-detected information flow data corresponding to the information flow detection instruction.
[0014] An event identification unit is configured to acquire an event identification result corresponding to the to-be-detected information flow data.
[0015] An associated event data acquisition unit is configured to acquire, based on the to-be-detected information flow data and the event identification result, associated event data corresponding to the to-be-detected information flow data in a local knowledge base.
[0016] A security detection unit is configured to acquire a target security detection strategy of the associated event data, and perform information flow security detection on the to-be-detected information flow data based on the target security detection strategy, to obtain a current detection result.
[0017] A data isolation processing unit is configured to perform data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result, if it is determined that the current detection result corresponds to a security risk result.
[0018] In a third aspect, an embodiment of the present application further provides a computer device, which comprises a memory and a processor, the memory has a computer program stored thereon, and the processor implements the method in the first aspect when executing the computer program.
[0019] In a fourth aspect, an embodiment of the present application further provides a computer readable storage medium, which has a computer program stored thereon, the computer program comprises program instructions, and the program instructions can implement the method in the first aspect when executed by a processor.
[0020] The embodiments of the present application provide an information flow security detection method, device, equipment and medium, the method comprising: acquiring, in response to an information flow detection instruction, to-be-detected information flow data corresponding to the information flow detection instruction; acquiring an event identification result corresponding to the to-be-detected information flow data; acquiring, based on the to-be-detected information flow data and the event identification result, associated event data corresponding to the to-be-detected information flow data in a local knowledge base; acquiring a target security detection strategy of the associated event data, and performing information flow security detection on the to-be-detected information flow data based on the target security detection strategy, to obtain a current detection result; and performing data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result, if it is determined that the current detection result corresponds to a security risk result. The embodiments of the present application can perform event identification on to-be-detected information flow data, and identify associated event data from a local knowledge base, and then perform security checking on the to-be-detected information flow data based on a target security detection strategy of the associated event data, so that the detection result is more accurate. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments description will be briefly introduced as follows. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort on the basis of these drawings.
[0022] Figure 1 The application scenario diagram of the information flow security detection method provided by the embodiments of the present application is shown.
[0023] Figure 2 The flow diagram of the information flow security detection method provided by the embodiments of the present application is shown.
[0024] Figure 3 The sub-flow diagram of the information flow security detection method provided by the embodiments of the present application is shown.
[0025] Figure 4 Another flow diagram of the information flow security detection method provided by the embodiments of the present application is shown.
[0026] Figure 5 Still another sub-flow diagram of the information flow security detection method provided by the embodiments of the present application is shown.
[0027] Figure 6 Still another flow diagram of the information flow security detection method provided by the embodiments of the present application is shown.
[0028] Figure 7 The schematic block diagram of the information flow security detection device provided by the embodiments of the present application is shown.
[0029] Figure 8 The schematic block diagram of the computer device provided by the embodiments of the present application is shown. DETAILED DESCRIPTION
[0030] The technical solutions in the embodiments of the present application will be described clearly and completely with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort belong to the protection scope of the present application.
[0031] It should be understood that, when used in the specification and the appended claims, the terms "comprise" and "include" indicate the existence of the described features, integers, steps, operations, elements, and / or components, but do not exclude one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0032] It should also be understood that the terms used herein are for the purpose of describing particular embodiments and are not intended to limit the application. As used in the specification and the appended claims, the singular forms "a," "an" and "the" are intended to include plural forms as well, unless the context clearly indicates otherwise.
[0033] It should be further understood that the term "and / or" used in the specification and the appended claims means one or more of the associated listed items as well as all possible combinations of the items and includes these combinations.
[0034] Please refer to Figure 1 and Figure 2 , wherein Figure 1 is a schematic diagram of the scenario of the information flow security detection method of the embodiments of the application, Figure 2 is a flowchart of the information flow security detection method provided by the embodiments of the application. As Figure 1 indicated, the information flow security detection method provided by the embodiments of the application is applied to a user terminal 10, which is specifically implemented as a firewall device, a gateway, a switch, a desktop computer, a notebook computer, a tablet computer or other computer device, and is in communication connection with a server 20. As Figure 2 indicated, the method includes the following steps S110-S150.
[0035] S110, in response to an information flow detection instruction, obtaining to-be-detected information flow data corresponding to the information flow detection instruction.
[0036] In this embodiment, the technical solution is described with the user terminal as the execution subject. An information flow security detection platform (which can also be regarded as a kind of network security protection software platform) is deployed on the user terminal. When the user starts the information flow security detection platform on the user terminal, the to-be-detected information flow data (which can also be understood as traffic data, which can be a request sent by other terminals to the user terminal or a data stream or information flow sent by other terminals to the user terminal) sent to the user terminal can be detected in real time to determine whether it has an attack behavior on the user terminal.
[0037] S120, obtaining an event recognition result corresponding to the to-be-detected information flow data.
[0038] In this embodiment, after the information flow security detection platform in the user terminal obtains the to-be-detected information flow data, the event recognition model pre-deployed therein can be used to perform event recognition on the to-be-detected information flow data, so as to obtain an event recognition result.
[0039] In an embodiment, as Figure 3 indicated, step S120 includes:
[0040] S121. Obtain the current log stream corresponding to the information stream data to be detected, and the log event sequence corresponding to the current log stream;
[0041] S122. Obtain a preset weighted random mask model, and perform weighted masking processing on the log event sequence through the weighted random mask model to obtain a weighted mask processing sequence;
[0042] S123. Input the weighted mask processing sequence into the pre-trained classification model to obtain the event recognition result.
[0043] In this embodiment, after the information flow security detection platform obtains the information flow data to be detected, it can first obtain the corresponding current log flow, which includes multiple event logs. Each event log includes at least a timestamp, source IP / destination IP, protocol type, and opcode. The log events can then be concatenated according to their timestamp order to form the log event sequence. Next, a weighted random masking model from the event recognition model is used to perform weighted masking on the log event sequence, resulting in a weighted masked sequence. For example, the masking probability of each source IP / destination IP in the log event sequence using the weighted random masking model is 50%~80%, while the masking probability of other fields is lower than that of the source IP / destination IP. After completing the above weighted masking process, the resulting weighted masked sequence achieves log volume compression compared to the log event sequence while retaining key information features. Finally, the weighted masking sequence is input into a pre-trained classification model (such as a random forest or decision tree model) in the event recognition model to obtain the event recognition result; for example, the obtained event recognition result is document download, connection to other servers, or abnormal script execution.
[0044] S130. Based on the information stream data to be detected and the event recognition result, obtain the associated event data corresponding to the information stream data to be detected from the local knowledge base.
[0045] In this embodiment, if event identification alone is insufficient to accurately determine whether there is a security risk in the information stream data to be detected, the information stream data to be detected and the event identification results can be combined to obtain related event data corresponding to the information stream data to be detected from the local knowledge base. That is, related event data that is very similar to the information stream data to be detected can be obtained, thereby combining the related event data to further determine the security detection result of the information stream data to be detected.
[0046] In one embodiment, such as Figure 4 As shown, step S130 includes:
[0047] S131, acquire the event entity node corresponding to the to-be-detected information flow data and the weighted mask processing sequence, take the weighted mask processing sequence as attribute data of the event entity node, and update the event entity node;
[0048] S132, acquire a current knowledge graph of a local knowledge base and entity nodes included in the current knowledge graph;
[0049] S133, acquire an association relationship between the event entity node and the entity nodes included in the current knowledge graph, to construct an edge relationship between the event entity node and the entity nodes in the current knowledge graph;
[0050] S134, acquire a target edge relationship with a maximum association value in the edge relationship of the entity nodes in the current knowledge graph, and acquire a target entity node corresponding to the target edge relationship;
[0051] S135, acquire node data of the target entity node as the associated event data.
[0052] In this embodiment, after the information flow security detection platform acquires the to-be-detected information flow data, the corresponding event entity node (such as including source IP / destination IP, user ID, and the like) can also be acquired, and the corresponding weighted mask processing sequence can also be acquired as attribute data of the event entity node, to update the event entity node. After the construction of the entity node for the to-be-detected information flow data is completed, the current knowledge graph stored in the form of a knowledge graph in the local can also be acquired, and all the entity nodes included therein can also be acquired.
[0053] Afterwards, the association relationship (i.e. edge relationship) between the event entity node and all entity nodes included in the current knowledge graph can be acquired. Specifically, the edge generation method based on time and space association can be used to construct the association relationship between the event entity node and all entity nodes included in the current knowledge graph. In the edge generation method based on time and space association, when calculating the association relationship between the event entity node and an entity node, the time density and the space correlation need to be calculated respectively. When calculating the time density of two nodes, the exponential calculation result of the difference between the time stamps of the two nodes is calculated (for example, when calculating the time density of two nodes, the calculation formula is TE = exp (|t1-t2| / 60), where t1 is the time stamp of the event entity node, t2 is the time stamp of the entity node, and TE is the time density of the two nodes). When calculating the space correlation of two nodes, it is determined according to whether the same source IP / destination IP corresponds between the two nodes (when the same source IP / destination IP corresponds between the two nodes, the value of the space correlation is 1, otherwise the value is 0). Finally, the time density and the space correlation of the two nodes are weighted and summed based on a preset weighting summation parameter set to obtain the association relationship between the event entity node and all entity nodes included in the current knowledge graph.
[0054] After the construction of the association relationship between the event entity node and all entity nodes included in the current knowledge graph is completed, the target edge relationship with the maximum association value with the edge relationship of the entity node in the current knowledge graph can be further acquired, and the target entity node corresponding to the target edge relationship can be acquired, so that the target entity node is filtered from the current knowledge graph. Finally, the node data of the target entity node is used as the associated event data, and the source IP / destination IP, user ID and other information included in the target entity node are known at this time, which can be used for further analysis in the future.
[0055] In an embodiment, after step S130, the following steps are further included:
[0056] The preset enhanced injection feature data is acquired, and the enhanced injection feature data is added to the associated event data to update the associated event data.
[0057] In this embodiment, in order to further increase the data features of the associated event data, the preset enhanced injection feature data can also be injected into the associated event data, such as attack threat intelligence, so that the associated event data realizes evidence enhancement.
[0058] S140, acquiring a target security detection strategy of the associated event data, and performing information flow security detection on the to-be-detected information flow data based on the target security detection strategy to obtain a current detection result.
[0059] In this embodiment, after the associated event data is obtained, a target security detection strategy for security detection before acquisition can be continued to be called, and information flow security detection is performed on the to-be-detected information flow data by using the target security detection strategy, so as to obtain a current detection result. By using the security detection strategy of the associated event data, the target security detection strategy required can be quickly determined from a plurality of security detection strategies.
[0060] In an embodiment, as shown in FIG. 1, step S140 includes: Figure 5
[0061] S141, obtaining a target large language model corresponding to the associated event data;
[0062] S142, inputting the associated event data or the to-be-detected information flow data as a prompt word into the target large language model for information flow security detection, to obtain the current detection result.
[0063] In this embodiment, if a plurality of large language models are deployed in the information flow security detection platform, and each large language model can be regarded as a separate intelligent agent (different intelligent agents can be understood as different security protection experts, and each intelligent agent has a security protection field in which it is good at, such as being good at processing malicious scripts, process injection, container escape, registry backdoor, etc.). After the target large language model corresponding to the associated event data is obtained, the associated event data or the to-be-detected information flow data can be input as a prompt word into the target large language model for information flow security detection, to obtain the current detection result. Of course, if the to-be-detected information flow data is not structured data, it can also be replaced by a current log stream corresponding to the to-be-detected information flow data, and the current log stream is input into the target large language model for information flow security detection, to obtain the current detection result. For example, the current detection result obtained is that the text is implanted by using a phishing document, data is exfiltrated through a tunnel, etc.
[0064] S150, if it is determined that the current detection result corresponds to an existing security risk result, performing data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result.
[0065] In this embodiment, if a plurality of security risk types are preset in the information flow security detection platform, and the current detection result belongs to one of the plurality of security risk types, it can be determined that the current detection result corresponds to an existing security risk result, and at this time, a target security isolation strategy corresponding to the current detection result can be used to perform data isolation processing, so as to avoid data attacks on the user terminal.
[0066] In an embodiment, as shown in FIG. 1, step S140 includes:Figure 6 As shown, step S150 comprises:
[0067] S151, based on the current security risk type of the current detection result, acquiring the target security isolation strategy corresponding to the current security risk type from a plurality of preset security isolation strategies;
[0068] S152, constructing an isolation area based on the target security isolation strategy, and performing data isolation processing on the to-be-detected information flow data.
[0069] In the embodiment, when the current security risk type of the current detection result is acquired, and the security risk types to which the plurality of preset security isolation strategies are respectively directed are known, the target security isolation strategy corresponding to the same security risk type as the current security risk type can be acquired from the plurality of preset security isolation strategies. Then, the isolation area such as a sandbox area is constructed based on the target security isolation strategy, and the to-be-detected information flow data is subjected to data isolation processing in the isolation area, so as to realize the security protection of data.
[0070] In an embodiment, after step S140, the method further comprises:
[0071] If it is determined that the current detection result corresponds to a non-security risk result, a target access area corresponding to the to-be-detected information flow data is acquired, and the to-be-detected information flow data is released to the target access area.
[0072] In the embodiment, if a plurality of security risk types are preset in the information flow security detection platform, and the current detection result does not belong to any one of the plurality of security risk types, it can be determined that the current detection result corresponds to a non-security risk result. At this time, the target access area corresponding to the to-be-detected information flow data can be acquired first, and then the to-be-detected information flow data is released to the target access area for normal data processing.
[0073] It can be seen that the embodiment implementing the method can perform security check on the to-be-detected information flow data by event recognition on the to-be-detected information flow data and associated event data recognition from the local knowledge base, and the detection result obtained is more accurate.
[0074] Figure 7 is a schematic block diagram of an information flow security detection device provided by an embodiment of the present application. As shown in Figure 7 Corresponding to the above information flow security detection method, the present application further provides an information flow security detection device 100. The information flow security detection device 100 comprises units for executing the above information flow security detection method. Please refer to Figure 7The information flow security detection apparatus 100 comprises an information flow data acquisition unit 110, an event identification unit 120, an associated event data acquisition unit 130, a security detection unit 140, and a data isolation processing unit 150.
[0075] The information flow data acquisition unit 110 is configured to acquire, in response to an information flow detection instruction, to-be-detected information flow data corresponding to the information flow detection instruction.
[0076] In this embodiment, the technical solution is described with the user terminal as the execution subject. An information flow security detection platform (which can also be regarded as a kind of network security protection software platform) is deployed on the user terminal. When the user starts the information flow security detection platform on the user terminal, the to-be-detected information flow data (which can also be understood as traffic data, which can be a request sent by another terminal to the user terminal, or a data stream or information flow sent by another terminal to the user terminal) sent to the user terminal can be detected in real time to determine whether it has an attack behavior on the user terminal.
[0077] The event identification unit 120 is configured to acquire an event identification result corresponding to the to-be-detected information flow data.
[0078] In this embodiment, after the information flow security detection platform in the user terminal acquires the to-be-detected information flow data, the event identification model pre-deployed therein can be used to identify the event of the to-be-detected information flow data, so as to obtain the event identification result.
[0079] In an embodiment, the event identification unit 120 is specifically configured to:
[0080] acquire a current log stream corresponding to the to-be-detected information flow data, and a log event sequence corresponding to the current log stream;
[0081] acquire a preset weighted random mask model, and perform weighted mask processing on the log event sequence through the weighted random mask model to obtain a weighted mask processing sequence;
[0082] input the weighted mask processing sequence into a pre-trained classification model to obtain the event identification result.
[0083] In this embodiment, when the information flow security detection platform obtains the to-be-detected information flow data, the current log stream corresponding to the to-be-detected information flow data can be obtained first, and the current log stream includes a plurality of event logs, each event log at least includes a timestamp, a source IP / destination IP, a protocol type, an operation code and the like. At this time, the log event sequence can be formed by concatenating the log events in the chronological order of the timestamps. Then, the weighted random mask model in the event recognition model is used to perform weighted mask processing on the log event sequence to obtain a weighted mask processing sequence. For example, the mask probability of each source IP / destination IP in the log event sequence is 50% to 80% through the weighted random mask model, and the mask probability of other fields is less than the mask probability of the source IP / destination IP. After the above weighted mask processing is completed, the weighted mask processing sequence obtained realizes compression of the log volume compared with the log event sequence, and the key information features are retained. Finally, the weighted mask processing sequence is input into the classification model (such as a random forest, a decision tree model and the like) pre-trained in the event recognition model to obtain the event recognition result. For example, the obtained event recognition result is document download, external connection to other servers, or abnormal script execution and the like.
[0084] The associated event data obtaining unit 130 is configured to obtain, based on the to-be-detected information flow data and the event recognition result, associated event data corresponding to the to-be-detected information flow data in a local knowledge base.
[0085] In this embodiment, if the event recognition on the to-be-detected information flow data is not enough to accurately determine whether there is a security risk result, the associated event data corresponding to the to-be-detected information flow data in the local knowledge base can be further obtained in combination with the to-be-detected information flow data and the event recognition result, that is, the associated event data similar to the to-be-detected information flow data is obtained, so that the security detection result of the to-be-detected information flow data can be further determined in combination with the associated event data.
[0086] In an embodiment, the associated event data obtaining unit 130 is specifically configured to:
[0087] obtain the event entity node corresponding to the to-be-detected information flow data and the weighted mask processing sequence, take the weighted mask processing sequence as attribute data of the event entity node, and update the event entity node;
[0088] obtain a current knowledge graph of the local knowledge base and an entity node included in the current knowledge graph;
[0089] obtain an association relationship between the event entity node and the entity node included in the current knowledge graph to construct an edge relationship between the event entity node and the entity node in the current knowledge graph.
[0090] obtaining a target edge relationship with a maximum correlation value of an edge relationship of an entity node in the current knowledge graph, and obtaining a target entity node corresponding to the target edge relationship;
[0091] obtaining node data of the target entity node as the correlation event data.
[0092] In the embodiment, after the information flow security detection platform obtains the to-be-detected information flow data, it can also obtain the corresponding event entity node (such as information including source IP / destination IP, user ID, etc.), and can also obtain the corresponding weighted mask processing sequence as attribute data of the event entity node to update the event entity node. After the construction of the entity node for the to-be-detected information flow data is completed, the current knowledge graph stored in the form of a knowledge graph locally can also be obtained, and all entity nodes included therein can also be obtained.
[0093] Then, the correlation relationship (that is, the edge relationship) of the event entity node and all entity nodes included in the current knowledge graph can be obtained, and the correlation relationship of the event entity node and all entity nodes included in the current knowledge graph can be constructed by using an edge generation method based on space-time correlation. In the edge generation method based on space-time correlation, when calculating the correlation relationship of the event entity node and an entity node, the time density and the spatial correlation of the two nodes need to be calculated respectively, and when calculating the time density of the two nodes, the exponential calculation result of the difference between the time stamps of the two nodes is calculated (for example, when calculating the time density of the two nodes, the calculation formula is TE=exp(|t1-t2| / 60), where t1 is the time stamp of the event entity node, t2 is the time stamp of the entity node, and TE is the time density of the two nodes), and when calculating the spatial correlation of the two nodes, it is determined according to whether the two nodes correspond to the same source IP / destination IP (when the two nodes correspond to the same source IP / destination IP, the value of the spatial correlation is 1, otherwise the value is 0), and finally the time density and the spatial correlation of the two nodes are weighted and summed based on a preset weighted summation parameter set to obtain the correlation relationship of the event entity node and all entity nodes included in the current knowledge graph.
[0094] When the construction of the correlation relationship of the event entity node and all entity nodes included in the current knowledge graph is completed, a target edge relationship with a maximum correlation value of an edge relationship of an entity node in the current knowledge graph can also be obtained, and a target entity node corresponding to the target edge relationship can also be obtained, so that the target entity node is filtered from the current knowledge graph. Finally, the node data of the target entity node is used as the correlation event data, and the source IP / destination IP, user ID, etc. included in the target entity node are also known at this time, which can be used for further analysis.
[0095] In an embodiment, the association event data obtaining unit 130 is further configured to:
[0096] obtain preset enhanced injection feature data, and add the enhanced injection feature data to the association event data to update the association event data.
[0097] In this embodiment, in order to further increase the data features of the association event data, preset enhanced injection feature data, such as attack threat intelligence, can also be injected into the association event data, so that the association event data achieves evidence strengthening.
[0098] The security detection unit 140 is configured to obtain a target security detection policy of the association event data, and perform information flow security detection on the to-be-detected information flow data based on the target security detection policy to obtain a current detection result.
[0099] In this embodiment, after obtaining the association event data, the target security detection policy used for security detection before obtaining can be further called, and the information flow security detection is performed on the to-be-detected information flow data through the target security detection policy, so as to obtain the current detection result. Through this way of referring to the security detection policy of the association event data, the target security detection policy required can be quickly determined from a plurality of security detection policies.
[0100] In an embodiment, the security detection unit 140 is specifically configured to:
[0101] obtain a target large language model corresponding to the association event data;
[0102] input the association event data or the to-be-detected information flow data as a prompt word into the target large language model to perform information flow security detection, and obtain the current detection result.
[0103] In this embodiment, if multiple large language models are deployed in the information flow security detection platform, and each large language model can be regarded as a separate agent (different agents can be understood as different security protection experts, and each agent has its own security protection field, such as being good at handling malicious scripts, process injection, container escape, registry backdoor, etc.). When the target large language model corresponding to the associated event data is obtained, the associated event data or the to-be-detected information flow data can be input as a prompt word to the target large language model for information flow security detection to obtain the current detection result. Of course, if the to-be-detected information flow data is not a structured data, it can also be replaced by the current log stream corresponding to the to-be-detected information flow data, and the structured data of the current log stream is input to the target large language model for information flow security detection to obtain the current detection result. For example, the obtained current detection result is a phishing document implantation text, data exfiltration through a tunnel, etc.
[0104] The data isolation processing unit 150 is configured to, if it is determined that the current detection result corresponds to a security risk result, perform data isolation processing on the to-be-detected information flow data based on a target security isolation strategy corresponding to the current detection result.
[0105] In this embodiment, if multiple security risk types are preset in the information flow security detection platform, and the current detection result belongs to one of the multiple security risk types, it can be determined that the current detection result corresponds to a security risk result, and at this time, the target security isolation strategy corresponding to the current detection result can be used to perform data isolation processing, thereby avoiding data attacks on the user terminal.
[0106] In an embodiment, the data isolation processing unit 150 is specifically configured to:
[0107] obtain, based on a current security risk type of the current detection result, a target security isolation strategy corresponding to the current security risk type from multiple preset security isolation strategies;
[0108] construct an isolation area based on the target security isolation strategy, and perform data isolation processing on the to-be-detected information flow data.
[0109] In the embodiment, when the current security risk type of the current detection result is acquired and the security risk types to which the plurality of preset security isolation strategies correspond are known, the target security isolation strategy corresponding to the same security risk type as the current security risk type is acquired from the plurality of preset security isolation strategies. Then, the isolation region such as a sandbox region is constructed based on the target security isolation strategy, and the data isolation processing is performed on the information flow data to be detected in the isolation region, so that the security protection of the data is realized.
[0110] In an embodiment, the information flow security detection apparatus 100 further includes:
[0111] The data release processing unit is configured to acquire a target access region corresponding to the information flow data to be detected and release the information flow data to be detected to the target access region if it is determined that the current detection result corresponds to the non-security risk result.
[0112] In the embodiment, if a plurality of security risk types are preset in the information flow security detection platform and the current detection result does not belong to any one of the plurality of security risk types, it is determined that the current detection result corresponds to the non-security risk result. In this case, the target access region corresponding to the information flow data to be detected is acquired first, and then the information flow data to be detected is released to the target access region for normal data processing.
[0113] It can be seen that, by performing the event recognition on the information flow data to be detected and the associated event data recognition from the local knowledge base, the embodiment of the apparatus performs the security check on the information flow data to be detected by using the target security detection strategy of the associated event data, so that the detection result is more accurate.
[0114] The information flow security detection apparatus can be implemented in the form of a computer program, which can run on the computer device as shown in Figure 8 .
[0115] Please refer to Figure 8 , Figure 8 is a schematic block diagram of a computer device provided by an embodiment of the present application. The computer device integrates any one of the information flow security detection apparatuses provided by the embodiments of the present application.
[0116] Please refer to Figure 8 , the computer device 400 includes a processor 402, a memory and a network interface 405 connected through a system bus 401, wherein the memory can include a storage medium 403 and an internal memory 404.
[0117] The storage medium 403 can store an operating system 4031 and a computer program 4032. The computer program 4032 includes program instructions, which, when executed, can cause the processor 402 to perform an information flow security detection method.
[0118] The processor 402 is configured to provide computing and control capabilities to support the operation of the entire computer device.
[0119] The memory 404 provides an environment for the execution of the computer program 4032 in the storage medium 403, which, when executed by the processor 402, can cause the processor 402 to perform the information flow security detection method described above.
[0120] The network interface 405 is configured to perform network communication with other devices. Those skilled in the art can understand that the network interface 405 can be configured to perform wired or wireless communication with the network. Figure 8 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0121] The processor 402 is configured to run the computer program 4032 stored in the memory to implement the information flow security detection method described above.
[0122] It should be understood that, in the embodiments of the present application, the processor 402 can be a central processing unit (CPU), and the processor 402 can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0123] Those of ordinary skill in the art can understand that all or part of the processes in the above-described embodiments of the method can be completed by a computer program instructing related hardware. The computer program includes program instructions, and the computer program can be stored in a storage medium, which is a computer readable storage medium. The program instructions are executed by at least one processor in the computer system to implement the process steps of the above-described embodiments of the method.
[0124] Therefore, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, wherein the computer program comprises program instructions. The program instructions, when executed by a processor, cause the processor to perform the information flow security detection method described above.
[0125] The storage medium can be a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk, and various computer readable storage media that can store program codes.
[0126] Those skilled in the art can appreciate that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in general terms in the above description. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0127] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of each unit is only a logical function division, and actual implementation can have another division manner. For example, a plurality of units or components can be combined or integrated into another system, or some features can be omitted or not executed.
[0128] The steps in the method embodiments of the present application can be adjusted, combined and reduced in sequence according to actual needs. The units in the device embodiments of the present application can be combined, divided and reduced according to actual needs. In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.
[0129] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a storage medium. Based on this understanding, the technical solutions of the present application essentially or say the parts that make contributions to the prior art, or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a terminal or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.
[0130] The above merely illustrates the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any skilled person in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements shall be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A method for information flow security detection, characterized in that, include: In response to an information flow detection command, acquire the information flow data to be detected corresponding to the information flow detection command; Obtain the event identification result corresponding to the information stream data to be detected; Based on the information stream data to be detected and the event recognition result, obtain the associated event data corresponding to the information stream data to be detected from the local knowledge base; The target security detection strategy for the associated event data is obtained, and information flow security detection is performed on the information flow data to be detected based on the target security detection strategy to obtain the current detection result; If it is determined that the current detection result corresponds to a result with security risks, then the data to be detected information stream will be isolated based on the target security isolation strategy corresponding to the current detection result; The step of obtaining the event recognition result corresponding to the information stream data to be detected includes: Obtain the current log stream corresponding to the information stream data to be detected, and the log event sequence corresponding to the current log stream; Obtain a preset weighted random mask model, and perform weighted masking processing on the log event sequence using the weighted random mask model to obtain a weighted masking processing sequence; The weighted masking sequence is input into a pre-trained classification model to obtain the event recognition result; The step of obtaining associated event data corresponding to the information stream data to be detected from the local knowledge base based on the information stream data to be detected and the event recognition result includes: Obtain the event entity node corresponding to the information stream data to be detected and the weighted mask processing sequence, and use the weighted mask processing sequence as the attribute data of the event entity node to update the event entity node; Obtain the current knowledge graph of the local knowledge base and the entity nodes included in the current knowledge graph; The association between the event entity node and the entity nodes included in the current knowledge graph is obtained to construct the edge relationship between the event entity node and the entity nodes in the current knowledge graph; wherein, the temporal density and spatial correlation between entity nodes are calculated by an edge generation method based on spatiotemporal correlation to construct the association between the event entity node and all entity nodes included in the current knowledge graph. Obtain the target edge relationship that has the maximum association value with the edge relationship of the entity node in the current knowledge graph, and obtain the target entity node corresponding to the target edge relationship; Obtain the node data of the target entity node as the associated event data.
2. The method according to claim 1, characterized in that, After the step of obtaining the associated event data corresponding to the information stream data to be detected from the local knowledge base based on the information stream data to be detected and the event recognition result, the method further includes: Obtain preset enhanced injection feature data and add the enhanced injection feature data to the associated event data to update the associated event data.
3. The method according to claim 1 or 2, characterized in that, The target security detection strategy for acquiring the associated event data, and the information flow security detection performed on the information flow data to be detected based on the target security detection strategy to obtain the current detection result, includes: Obtain the target large language model corresponding to the associated event data; The associated event data or the information flow data to be detected is input as prompt words into the target large language model for information flow security detection, and the current detection result is obtained.
4. The method according to claim 3, characterized in that, The process of isolating the data stream to be detected based on the target security isolation strategy corresponding to the current detection result includes: Based on the current security risk type of the current detection result, the target security isolation strategy corresponding to the current security risk type is obtained from multiple preset security isolation strategies; An isolation zone is constructed based on the target security isolation strategy, and the data stream data to be detected is processed for data isolation.
5. The method according to claim 1, characterized in that, After the steps of acquiring the target security detection strategy for the associated event data, and performing information flow security detection on the information flow data to be detected based on the target security detection strategy to obtain the current detection result, the method further includes: If it is determined that the current detection result corresponds to a result without security risks, then the target access area corresponding to the information flow data to be detected is obtained, and the information flow data to be detected is allowed to the target access area.
6. An information flow security detection device, characterized in that, include: The information flow data acquisition unit is used to acquire the information flow data to be detected corresponding to the information flow detection command in response to the information flow detection command; An event recognition unit is used to acquire event recognition results corresponding to the information stream data to be detected; The associated event data acquisition unit is used to acquire associated event data corresponding to the information stream data to be detected from a local knowledge base based on the information stream data to be detected and the event recognition result. A security detection unit is used to acquire the target security detection strategy of the associated event data, and to perform information flow security detection on the information flow data to be detected based on the target security detection strategy, so as to obtain the current detection result; The data isolation processing unit is used to perform data isolation processing on the information stream data to be detected based on the target security isolation strategy corresponding to the current detection result if it is determined that the current detection result corresponds to a result with security risks. The event recognition unit is specifically used for: Obtain the current log stream corresponding to the information stream data to be detected, and the log event sequence corresponding to the current log stream; Obtain a preset weighted random mask model, and perform weighted masking processing on the log event sequence using the weighted random mask model to obtain a weighted masking processing sequence; The weighted masking sequence is input into a pre-trained classification model to obtain the event recognition result; The associated event data acquisition unit is specifically used for: Obtain the event entity node corresponding to the information stream data to be detected and the weighted mask processing sequence, and use the weighted mask processing sequence as the attribute data of the event entity node to update the event entity node; Obtain the current knowledge graph of the local knowledge base and the entity nodes included in the current knowledge graph; The association between the event entity node and the entity nodes included in the current knowledge graph is obtained to construct the edge relationship between the event entity node and the entity nodes in the current knowledge graph; wherein, the temporal density and spatial correlation between entity nodes are calculated by an edge generation method based on spatiotemporal correlation to construct the association between the event entity node and all entity nodes included in the current knowledge graph. Obtain the target edge relationship that has the maximum association value with the edge relationship of the entity node in the current knowledge graph, and obtain the target entity node corresponding to the target edge relationship; Obtain the node data of the target entity node as the associated event data.
7. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the information flow security detection method as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions, which, when executed by a processor, can implement the information flow security detection method as described in any one of claims 1-5.
Citation Information
Patent Citations
Automatic penetration testing method and system based on knowledge graph
CN114866358A
Network attack path prediction and defense method and device, computer equipment and medium
CN119484135A
Visual early warning method and system for network security event
CN120474836A