Alarm feature extraction method for business risk control and related device

By combining threat detection models and artificial intelligence models, the system achieves refined and comprehensive automated extraction of alarm features in security protection systems, solving the problem of feature extraction rules failing in existing technologies and improving the system's defense and response capabilities.

CN120979900BActive Publication Date: 2026-08-04BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING VOLCANO ENGINE TECH CO LTD
Filing Date
2025-08-28
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

When faced with new types of attacks or changes in alarm characteristics, the pre-configured feature extraction rules of existing security protection systems become ineffective, resulting in defense delays and missed alarm characteristics, which affects security protection capabilities.

Method used

A threat detection model is used in conjunction with multiple progressive alarm feature extraction steps. The system also incorporates an artificial intelligence model to automatically extract alarm features and performs refined feature extraction by determining the attack stage of the alarm event.

Benefits of technology

It improves the alarm analysis and handling capabilities of the security protection system, achieves more comprehensive and accurate alarm feature extraction, and enhances the system's defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979900B_ABST
    Figure CN120979900B_ABST
Patent Text Reader

Abstract

This disclosure provides a method and related apparatus for alarm feature extraction in business risk control. The alarm feature extraction method includes: acquiring first alarm information associated with a first alarm event; determining a first alarm feature of the first alarm information based on the first alarm information; determining the first attack stage of the first alarm event in a first attack type based on the first alarm feature and a first threat detection model; and determining a second alarm feature of the first alarm information based on attack information of the first attack stage of the first attack type in the first threat detection model. In this alarm feature extraction method, the alarm features extracted for alarm events are more comprehensive and accurate, enabling security protection systems such as cloud security protection products and security agents to have complete and highly generalizable alarm feature extraction capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to an alarm feature extraction method, an alarm feature extraction device, an electronic device, and a computer-readable storage medium for business risk control. Background Technology

[0002] With the continuous development of cloud computing technology, security protection systems for cloud security testing have emerged. These systems can include products such as cloud security centers and cloud workload protection platforms (CWPP) that protect workloads in cloud environments.

[0003] With the development of large-scale model technology, security protection systems can also provide security detection services in the form of security intelligent agents. Security intelligent agents are comprehensive intelligent security applications built on large-scale security models and various security tools / plugins. Depending on the capabilities of the tools / plugins and the security model, they can perform various security tasks.

[0004] In the actual operation of a security protection system, alarm features are usually extracted for generated alarm events, and the extracted alarm features are used for alarm analysis and alarm handling. Summary of the Invention

[0005] This summary section is provided to briefly introduce the concepts, which will be described in detail in the subsequent detailed description section. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0006] At least one embodiment of this disclosure provides an alarm feature extraction method for business risk control, comprising: acquiring first alarm information associated with a first alarm event; determining a first alarm feature of the first alarm information based on the first alarm information; determining a first attack stage of the first alarm event in a first attack type based on the first alarm feature and a first threat detection model, wherein the first threat detection model provides attack information for each attack stage in multiple attack types; and determining a second alarm feature of the first alarm information based on the attack information of the first attack stage of the first attack type in the first threat detection model.

[0007] At least another embodiment of this disclosure provides an alarm feature extraction device for business risk control, comprising: an acquisition module configured to: acquire first alarm information associated with a first alarm event; a first extraction module configured to: determine a first alarm feature of the first alarm information based on the first alarm information; a determination module configured to: determine a first attack stage of the first alarm event in a first attack type based on the first alarm feature and a first threat detection model, wherein the first threat detection model provides attack information for each attack stage in multiple attack types; and a second extraction module configured to: determine a second alarm feature of the first alarm information based on the attack information of the first attack stage of the first attack type in the first threat detection model.

[0008] At least one further embodiment of this disclosure provides an electronic device, including: a processing device; and a storage device including one or more computer program instructions; wherein the one or more computer program instructions are executed by the processing device to perform the alarm feature extraction method for business risk control provided in at least one embodiment of this disclosure.

[0009] At least one further embodiment of this disclosure provides a computer-readable storage medium that non-temporarily stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the alarm feature extraction method for business risk control provided in at least one embodiment of this disclosure.

[0010] At least one embodiment of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the alarm feature extraction method for business risk control provided in at least one embodiment of this disclosure. Attached Figure Description

[0011] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0012] Figure 1 This illustration schematically depicts an application scenario of a security protection system provided by at least one embodiment of the present disclosure;

[0013] Figure 2 The illustration shows a flowchart of an alarm feature extraction method for business risk control provided in at least one embodiment of the present disclosure;

[0014] Figure 3 The illustration shows a flowchart of another alarm feature extraction method for business risk control provided by at least one embodiment of the present disclosure;

[0015] Figure 4 This schematic diagram illustrates the structure of an alarm feature extraction device for business risk control provided in at least one embodiment of the present disclosure; and

[0016] Figure 5 A schematic diagram of the structure of an electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation

[0017] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0018] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0019] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0020] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0021] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0022] The names of the messages or information exchanged between the various devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0023] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0024] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization should be obtained from the relevant users. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.

[0025] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly indicate that the operation requested by the user will require obtaining and using the user's information. This allows the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of any embodiment of the present disclosure based on the prompt message.

[0026] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.

[0027] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0028] With the continuous development of cloud computing technology, security protection systems for cloud security testing have emerged. These systems can perform multi-faceted security testing across various operational scenarios. For example, a security protection system can be a cloud workload protection platform (CWPP), which can test host security and network security. Another example is a host-based intrusion detection system (HIDS), which can perform security testing on the behavior and state of computer systems. Yet another example is an endpoint detection and response (EDR) system, which can perform security testing on the system-level behavior of endpoints. Finally, a security protection system can be a container security platform (CSP), which provides multi-faceted security testing for containers.

[0029] With the development of large-scale model technology, artificial intelligence-driven agents have been widely used. These agents are typically able to perceive information in their environment, make decisions, and take actions to achieve specific goals or tasks. For example, in the field of security detection, security protection systems can also provide security detection services in the form of security agents. These security agents are comprehensive intelligent security applications built upon large-scale security models and various security tools / plugins. Depending on the capabilities of the tools / plugins and the security model, they can perform various security tasks.

[0030] In the actual operation of a security protection system, alarm features are typically extracted for generated alarm events. These extracted features are then used for alarm analysis and handling. For example, feature extraction rules can be pre-configured to extract features from alarm information (such as network traffic and network logs). If information matching the feature extraction rules is found in the alarm information, then an alarm feature is identified.

[0031] However, the inventors of this disclosure have discovered that the above-mentioned method of feature extraction through feature extraction rules has at least the following problems: First, for new types of attacks or attacks with changing alarm features, the pre-configured feature extraction rules may fail, resulting in limited timeliness of alarm feature extraction, which in turn leads to defense lag and affects the protection capability of the security protection system; In addition, with the increasing complexity of network attack methods, attacks are characterized by fragmentation and concealment, and the pre-configured feature extraction rules are difficult to fully cover alarm features, which can easily lead to omissions of alarm features, resulting in vulnerabilities in the defense and affecting the alarm handling capability of the security protection system.

[0032] To at least partially solve the above-mentioned technical problem, at least one embodiment of this disclosure provides an alarm feature extraction method, the method comprising: acquiring first alarm information associated with a first alarm event; determining a first alarm feature of the first alarm information based on the first alarm information; determining a first attack stage of the first alarm event in a first attack type based on the first alarm feature and a first threat detection model, the first threat detection model providing attack information for each attack stage in multiple attack types; and determining a second alarm feature of the first alarm information based on the attack information of the first attack stage of the first attack type in the first threat detection model.

[0033] Based on the alarm feature extraction method for business risk control provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides an alarm feature extraction device, electronic device, computer-readable storage medium, and computer program product for business risk control.

[0034] This disclosure provides at least one embodiment of an alarm feature extraction method for business risk control. During the alarm feature extraction process, on the one hand, there are multiple progressive alarm feature extraction steps. Based on the first alarm feature and combined with the first attack stage, a second alarm feature is further extracted, making the extracted alarm features more comprehensive. On the other hand, alarm feature extraction is combined with a threat detection model. Since the threat detection model provides attack information for different attack types, the extracted alarm features are more accurate. For example, when the above method is applied to security protection systems such as cloud security protection products or security agents, it enables the security protection system to have complete and highly generalizable alarm feature extraction capabilities, thereby improving the alarm analysis and alarm handling capabilities of the security protection system.

[0035] The embodiments and some examples of this disclosure will now be described in detail with reference to the accompanying drawings.

[0036] Figure 1 The illustration shows an application scenario of a security protection system provided by at least one embodiment of the present disclosure.

[0037] like Figure 1 As shown, the application scenario of this embodiment includes a security protection system 100. The embodiments of this disclosure do not limit the form of the security protection system 100. For example, the security protection system 100 can provide cloud security protection-related services in the form of a security AI agent. The security protection system 100 can be a cloud security platform, a cloud security plugin, a cloud security cloud service, etc.

[0038] In embodiments of this disclosure, the security protection system 100 can combine the threat detection model 200 to extract alarm features. For example, in response to the generation of alarm event 101, the security protection system 100 can obtain alarm information 102 associated with alarm event 101, determine a first alarm feature 103 of alarm information 102 based on alarm information 102, and the security protection system 100 can also determine the first attack stage of alarm event 101 in a first attack type based on the first alarm feature 103 and threat detection model 200, and determine a second alarm feature 104 of alarm information 102 based on attack information of the first attack stage of the first attack type in threat detection model 200.

[0039] Thus, in the process of alarm feature extraction of security protection system 100, by referring to the attack information of each attack stage in multiple attack types provided by threat detection model 200, the first attack type to which the current alarm event 101 belongs and the specific first attack stage in the first attack type are determined, and then the alarm feature is extracted in a targeted and refined manner in combination with the first attack stage.

[0040] Furthermore, in at least one embodiment of this disclosure, the security protection system 100 may further include a knowledge base 105, in which the extracted first alarm feature 103 and second alarm feature 104 may be stored. For example, they may be stored in the knowledge base 105 in the form of feature maps. In this way, the extracted alarm features can be stored as knowledge information and used in subsequent protection by the security protection system 100.

[0041] In at least one embodiment of this disclosure, the security protection system 100 can be connected to the artificial intelligence model 300 to extract alarm features using the artificial intelligence model 300. For example, the security protection system 100 can extract a first alarm feature 103 using the artificial intelligence model 300. As another example, the security protection system 100 can also use the artificial intelligence model 300 to determine the first attack stage of the alarm event 101 in a first attack type. Yet another example, the security protection system 100 can also use the artificial intelligence model 300 to extract a second alarm feature 104.

[0042] In this way, by utilizing the artificial intelligence capabilities of the artificial intelligence model 300, an automated alarm feature extraction process can be implemented in the security protection system 100, eliminating the need for users (such as security operations personnel) to manually configure feature extraction rules, thereby improving the alarm feature extraction efficiency of the security protection system 100.

[0043] This disclosure does not limit the form of the artificial intelligence model 300. For example, the artificial intelligence model 300 may include any one or a combination of multiple of the following: a large language model, a large visual model, a large audio model, and a multimodal large model. For example, the artificial intelligence model 300 may be a model built based on a transformer architecture, a model built based on a recurrent neural network, a model built based on an attention mechanism, etc. Alternatively, the artificial intelligence model 300 may also be a model obtained by improving upon the transformer architecture, such as a mixture of experts (MoE) model.

[0044] The embodiments disclosed herein do not limit the deployment method of the artificial intelligence model 300. For example, as Figure 1 As shown, the artificial intelligence model 300 can be deployed outside the security protection system 100, meaning the security protection system 100 can extract alarm features by calling the external artificial intelligence model 300. Alternatively, the artificial intelligence model 300 can also be deployed inside the security protection system 100 as a functional module, assisting in alarm feature extraction during the operation of the security protection system 100.

[0045] It should be noted that, in this disclosure, the artificial intelligence model 300 (including the first artificial intelligence model, the second artificial intelligence model, and / or the third artificial intelligence model) can be obtained in various ways. For example, the artificial intelligence model 300 can be an existing, open-source general artificial intelligence model. Alternatively, the artificial intelligence model 300 can be an artificial intelligence model obtained by fine-tuning (e.g., full parameter fine-tuning or partial parameter fine-tuning) based on a pre-trained model using historical security data (e.g., historical alarm information, alarm characteristics of historical alarm information, etc.) from the security protection system 100.

[0046] The following will combine Figure 2 and Figure 3 This disclosure provides a detailed description of an alarm feature extraction method for business risk control, based on at least one embodiment.

[0047] Figure 2 The illustration shows a flowchart of an alarm feature extraction method for business risk control provided in at least one embodiment of the present disclosure.

[0048] like Figure 2 As shown, the alarm feature extraction method for business risk control in this embodiment includes steps S201 to S204. For example, the executing entity of this alarm feature extraction method for business risk control can be an electronic device with a client deployed, an electronic device with a server deployed, or any electronic device that communicates between the client and the server; the embodiments of this disclosure do not limit this.

[0049] Step S201: Obtain the first alarm information associated with the first alarm event.

[0050] The first alarm event can be understood as an alarm event detected by the security protection system. For example, when the security protection system is providing security protection for a virtual machine, it detects that the virtual machine has triggered a first alarm event.

[0051] The first alarm event can be associated with the first alarm information. In other words, when the security system detects the first alarm event, the first alarm information can be the alarm information associated with that alarm event. The first alarm information can be alarm information in different forms and with different content. For example, in terms of form, the first alarm information can be network traffic, network logs, etc.; in terms of content, the first alarm information can include alarm identifier, the time of occurrence of the alarm event, alarm level, alarm source, alarm code, etc.

[0052] Figure 3 The illustration shows a flowchart of another alarm feature extraction method for business risk control provided by at least one embodiment of the present disclosure.

[0053] In some embodiments of this disclosure, considering the comprehensiveness of subsequent alarm feature extraction, the first alarm information may include multi-dimensional alarm information. For example, such as Figure 3 As shown, the original alarm information carried by the first alarm event is obtained, as well as the alarm context information associated with the first alarm event is obtained.

[0054] The original alarm information can be understood as the alarm information directly related to the first alarm event. For example, the original alarm information may include one or more of the following: alarm name, alarm risk level, and alarm judgment result. The alarm context information can be understood as richer alarm information obtained by data aggregation based on the original alarm information. For example, the alarm context information may include one or more of the following: the trigger timestamp of the alarm event, the source Internet Protocol (IP) address and the destination IP address of the alarm event, the network attribute information of the source IP address and the destination IP address, the asset information involved in the alarm event, the importance of the asset, the business domain to which the asset belongs, other alarm events related to the asset, and one or more of the following from host logs.

[0055] By aggregating data based on the original alarm information, richer and more multi-dimensional alarm information is obtained, making the first alarm information an alarm background information that includes "original alarm and context content". In subsequent alarm feature extraction, more comprehensive alarm extraction is performed by combining information such as the spatiotemporal correlation of alarm events and asset attributes, avoiding misjudgment of alarm features due to incomplete alarm information.

[0056] The embodiments disclosed herein do not limit the method of obtaining the first alarm information. For example, the security protection system can obtain the first alarm information by invoking security tools.

[0057] Step S202: Determine the first alarm feature of the first alarm information based on the first alarm information.

[0058] In the embodiments of this disclosure, alarm features (including initial alarm features, first alarm features, and / or second alarm features) can also be referred to as threat features, which can be understood as the risky part of the alarm information (e.g., partial features). By extracting alarm features, the cause of the alarm event can be identified, so as to perform alarm analysis and alarm handling.

[0059] The first alarm feature can be understood as the alarm feature obtained after preliminary feature extraction of the first alarm information. In some possible implementations, the first alarm feature is directly extracted from the first alarm information. For example, by using feature extraction rules, alarm features that conform to the feature extraction rules are determined from the first alarm information, and these alarm features are identified as the first alarm feature.

[0060] In some other possible implementations, the process of determining the first alarm characteristic may include multiple steps. Continuing as... Figure 3 As shown, feature extraction is performed on the first alarm information to obtain initial alarm features. Based on the initial alarm features, the first attack type corresponding to the first alarm event is determined. Based on the attack information of the first attack type in the first threat detection model, the first alarm feature of the first alarm information is determined.

[0061] In this embodiment, the initial alarm feature can be understood as the alarm feature directly extracted from the first alarm information. Based on the initial alarm feature, the first attack type corresponding to the first alarm event is determined, and the judgment of the attack type is completed.

[0062] Next, feature extraction is performed again using the first threat detection model to obtain the first alarm information. In the embodiments of this disclosure, the first threat detection model can provide attack information for each stage of multiple attack types. In other words, the first threat detection model can be understood as a database storing attack information for different stages corresponding to different attack types.

[0063] In some embodiments, the attack information for each attack stage in the multiple attack types may include at least one of the following: attack role information for each attack stage in the multiple attack types, and attack behavior information for each attack stage in the multiple attack types.

[0064] In other words, the attack information provided by the first threat detection model can include information related to the attacking role and information related to the attack behavior. For example, information related to the attacking role can be the target role that performs the attack, and information related to the attack behavior can be information related to the attack method.

[0065] Since the first threat detection model provides multifaceted attack information, it can provide multifaceted assistance in various stages of different attack types during the alarm feature extraction process.

[0066] The embodiments disclosed herein do not limit the type of the first threat detection model. For example, the first threat detection model can be an adversarial tactics, techniques and common knowledge (ATT&CK) threat detection model. The ATT&CK threat detection model is a dynamic database based on real attack behavior. It organizes the tactics and techniques used in the attack lifecycle of different attack types from the attacker's perspective and provides fine-grained attack information.

[0067] In other words, by extracting the initial alarm information, the first attack type is determined. Combined with the attack information related to the first attack type provided by the first threat detection model, alarm features are further extracted under the first attack type to obtain the first alarm features, ensuring the accuracy of the first alarm features and their correlation with the first alarm event.

[0068] Considering that the attack information provided by the first threat detection model can be described in natural language, and the first alarm information can typically be unstructured text, in at least one embodiment of this disclosure, the first artificial intelligence model can be used to extract the first alarm features. For example, obtaining the first model prompt information, sending the first model prompt information to the first artificial intelligence model, and receiving the first alarm features of the first alarm information returned by the first artificial intelligence model.

[0069] The first artificial intelligence model can have natural language processing capabilities, be able to understand the meaning of natural language, and handle different types of natural language tasks. The first artificial intelligence model can also have multimodal information processing capabilities, be able to understand the meaning of multimodal information, and handle different types of multimodal tasks.

[0070] The first AI model can extract the first warning feature based on prompt learning technology and the prompt information from the first model. Model prompt information, also known as prompt words, can be used to guide the AI ​​model to make specific outputs in generative tasks (such as text generation, question answering, and dialogue tasks). By configuring model prompt information, the AI ​​model can understand the context and requirements of the task, enabling it to handle different types of processing tasks without retraining, thus increasing the scalability and flexibility of the AI ​​model.

[0071] The first model prompt information may include: first alarm information, attack information of a first attack type in the first threat detection model, and instruction information for indicating feature extraction of the first alarm information. For example, the instruction information for indicating feature extraction of the first alarm information may be: instruction information for indicating feature extraction of the first alarm information based on the attack information of the first attack type in the first threat detection model.

[0072] For example, if the first threat detection model is the ATT&CK threat detection model and the first attack type is a data leakage attack, then the instruction information used to indicate feature extraction of the first alarm information can be: according to the attack information (e.g., typical techniques) under the data leakage attack in the ATT&CK threat detection model, extract the first alarm features in the first alarm information that meet the criteria of "transmitting sensitive data through an encrypted channel" and "sending information externally using cloud storage services".

[0073] Furthermore, the instruction information for indicating feature extraction of the first alarm information may also include: instruction information for indicating multi-dimensional feature extraction of the first alarm information. For example, multi-dimensional feature extraction may include tool dimensions, indicator dimensions (such as IP address, hash value), behavioral pattern dimensions (such as the periodic characteristics of periodically connecting to the server), etc. By setting multi-dimensional feature extraction instruction information in the first model prompt information, it is ensured that the first alarm features cover different dimensions.

[0074] By sending the first model's prompt information to the first artificial intelligence model, and leveraging the prompting capabilities of this information, the first artificial intelligence model can analyze the first alarm information and extract the first alarm features from the first alarm information by combining the attack information of the first attack type in the first threat detection model. Thus, by utilizing the semantic understanding capabilities of the first artificial intelligence model, automatic extraction of alarm features is achieved; furthermore, the first alarm features are related to the attack information provided by the first threat detection model, making the extraction of alarm features based on evidence.

[0075] Step S203: Based on the first alarm characteristics and the first threat detection model, determine the first attack stage of the first alarm event in the first attack type.

[0076] After extracting the first alarm feature, the security protection system can determine the first attack stage of the first alarm event in the first attack type based on the first alarm feature and combined with the first threat detection model. That is, it can reconstruct the scenario of the first alarm event and determine the attack life cycle stage of the first alarm event.

[0077] In at least one embodiment of this disclosure, a second artificial intelligence model is used to determine the first attack stage in the first attack type of the first alarm event. For example, second model prompt information is obtained, the second model prompt information is sent to the second artificial intelligence model, and the first attack stage in the first attack type of the first alarm event is received from the second artificial intelligence model.

[0078] Similar to the first AI model, the second AI model can have natural language processing capabilities, be able to understand the meaning of natural language, and handle different types of natural language tasks. The second AI model can also have multimodal information processing capabilities, be able to understand the meaning of multimodal information, and handle different types of multimodal tasks. The second AI model can also be based on cue learning technology to determine the first attack phase according to the cue information provided by the second model.

[0079] It should be noted that in some embodiments, the second artificial intelligence model may be the same as the first artificial intelligence model, or in other embodiments, it may be a different model from the first artificial intelligence model.

[0080] The second model prompt information may include: a first alarm feature, attack information for each attack stage of the first attack type in the first threat detection model, and indication information for determining the attack stage. For example, the indication information for determining the attack stage may be: indication information for determining the attack stage corresponding to the first alarm feature based on the attack information for each attack stage of the first attack type in the first threat detection model.

[0081] By sending the second model's prompt information to the second artificial intelligence model, and leveraging the prompting capabilities of the second model's prompt information, the second artificial intelligence model combines the attack information of each attack stage of the first attack type in the first threat detection model to reconstruct the scenario of the first alarm event and output the first attack stage in the first attack type of the first alarm event.

[0082] For example, the first attack type can be a data penetration attack. In this case, by combining the attack information of each attack stage of the data penetration attack in the first threat detection model (such as the attack techniques and attack methods of each attack stage of the data penetration attack), the first attack stage of the first alarm event is determined (such as the lateral movement stage after the initial intrusion, the data theft stage, etc.).

[0083] Thus, since the first threat detection model provides attack information for each stage of the first attack type, by configuring the second model prompt information, the second artificial intelligence model is precisely guided to analyze the first alarm features, determine the first attack stage corresponding to the first alarm event, and locate the first alarm event in the attack.

[0084] Step S204: Based on the attack information of the first attack stage of the first attack type in the first threat detection model, determine the second alarm feature of the first alarm information.

[0085] Continue as Figure 3 After determining the first attack phase corresponding to the first alarm event, the attack information of the first attack phase of the first attack type in the first threat detection model is used to further extract alarm features and determine the second alarm features.

[0086] In other words, after determining the first alarm feature, the focus is then placed on extracting alarm features for the first attack stage. Since the first threat detection model provides attack information for the first attack stage, by referring to the attack information provided by the first threat detection model, richer alarm features that match the first attack stage can be extracted from the first alarm information, thus increasing the number of alarm features.

[0087] In some embodiments of this disclosure, attack information of the first attack stage of the first attack type in the first threat detection model is used as key information and matched with the first alarm information. Based on the matching result, the second alarm feature of the first alarm information is determined.

[0088] In other words, since the first threat detection model provides attack information related to the first attack type in the first attack phase, the first alarm information is filtered to see if any attack information related to the first attack type in the first attack phase exists. If it does (i.e., the matching result indicates a successful match), this information is used as the second alarm feature. Thus, the second alarm feature related to the first attack phase is further obtained from the first alarm information.

[0089] In other embodiments of this disclosure, a third artificial intelligence model is used to determine a second alarm feature of the first alarm information based on attack information from the first attack stage of the first attack type in the first threat detection model. For example, a third model prompt is obtained, the third model prompt is sent to the third artificial intelligence model, and the second alarm feature of the first alarm information returned by the third artificial intelligence model is received.

[0090] Similar to the first AI model, the third AI model can have natural language processing capabilities, understand the meaning of natural language, and handle different types of natural language tasks. The third AI model can also have multimodal information processing capabilities, understand the meaning of multimodal information, and handle different types of multimodal tasks. The third AI model can also extract second alarm features based on prompting learning technology and prompting information from the third model.

[0091] It should be noted that in some embodiments, the third artificial intelligence model may be the same model as the first artificial intelligence model, or in other embodiments, it may be a different model from the first artificial intelligence model.

[0092] The third model prompt information may include: first alarm information, attack information of the first attack stage of the first attack type of the first attack type in the first threat detection model, and instruction information for indicating the extraction of alarm features. For example, the instruction information for indicating the extraction of alarm features may be: instruction information for indicating the extraction of alarm features from the first alarm information based on the attack information of the first attack stage of the first attack type of the first attack type in the first threat detection model.

[0093] By sending the third model's prompt information to the third artificial intelligence model, and leveraging the prompting capabilities of the third model's prompt information, the third artificial intelligence model combines the attack information of the first attack type and the first attack stage in the first threat detection model to extract the alarm features that match the first attack stage from the first alarm information and output the second alarm features.

[0094] Thus, by utilizing the third artificial intelligence model in conjunction with the first threat detection model, hidden alarm features related to the attack stage of the first alarm event can be extracted from the first alarm information, making alarm feature extraction more targeted and in-depth.

[0095] In the alarm feature extraction method disclosed herein, by determining the attack stage of the alarm event, more comprehensive alarm features are extracted in combination with the attack stage, ensuring the accuracy of alarm features and making alarm feature extraction more generalizable, without the need for manual maintenance of feature extraction rules.

[0096] Furthermore, after extracting the first alarm feature and the second alarm feature, an alarm feature map of the first alarm event can be constructed based on the first alarm feature and the second alarm feature.

[0097] Alarm feature graphs can describe alarm features in the form of knowledge graphs. For example, nodes in an alarm feature graph represent alarm features (such as the first alarm feature or the second alarm feature), and the connections between nodes in an alarm feature graph represent the relationships between alarm features.

[0098] In other words, after the security protection system completes the alarm feature extraction, the first and second alarm features of the first alarm event are used to construct an alarm feature map, which represents the alarm features. Thus, one alarm event corresponds to one alarm feature map. Compared to each alarm feature being a separate data point, the alarm feature map can represent richer relationships between alarm features, facilitating the management of alarm features for alarm events.

[0099] In some possible implementations, the correlation between alarm features in the alarm feature map of the first alarm event is determined by at least one of the following methods: constructing the correlation between alarm features related to the same object in the first alarm feature and the second alarm feature; constructing the correlation between alarm features in the first threat detection model that indicate the correlation between the first alarm feature and the second alarm feature.

[0100] An object can be understood as an entity appearing in the first alarm message. For example, an object can be an Internet Protocol (IP) address, a process, a server, etc. For instance, for a specific IP address, there is a correlation between the alarm features corresponding to two operations related to that IP address.

[0101] In the first threat detection model, the indicator correlation can be understood as a correlation among the attack information provided by the first threat detection model. For example, the indicator correlation in the first threat detection model can be attack information of the same attack type and the same attack stage in the first threat detection model. For instance, there is a correlation between the alarm features corresponding to attack methods of the same attack type and the same attack stage.

[0102] Thus, in the embodiments of this disclosure, not only are alarm features extracted, but also the correlation between alarm features is established, so that multiple alarm features of an alarm event are correlated, and alarm events can be better represented by alarm features.

[0103] In at least one embodiment of this disclosure, the security protection system may further include a knowledge base, which may be used to store alarm features, for example, associating a first alarm event with an alarm feature map of the first alarm event and storing it in the knowledge base.

[0104] For example, the first alarm event and its alarm feature map are stored in a knowledge base as key-value pairs; for example, in the knowledge base, the first alarm event is the key and the alarm feature map of the first alarm event is the value.

[0105] Thus, the alarm feature map is stored in the knowledge base as existing knowledge information of the security protection system. During the operation of the security protection system, the alarm feature map can be used to assist other functions related to security protection. For example, the alarm feature map can be used as training data to train a machine learning model for feature extraction.

[0106] In the embodiments of this disclosure, the alarm feature map of the first alarm event can be used in different ways. For example, the alarm analysis result of the first alarm event can be determined based on the alarm feature map of the first alarm event; or, in response to the similarity between the generated second alarm event and the first alarm event meeting a set condition, the alarm features corresponding to the second alarm event can be determined based on the alarm feature map of the first alarm event.

[0107] The set conditions can be understood as conditions used to indicate that the first alarm event and the second alarm event are similar. For example, the set conditions can be that the first alarm event and the second alarm event belong to the same attack type, or that the similarity between the first alarm information of the first alarm event and the second alarm information of the second alarm event is greater than the similarity threshold.

[0108] In other words, on the one hand, the alarm feature map of the first alarm event can be used in the subsequent alarm analysis and alarm handling process of the first alarm event. For example, by using the alarm feature map of the first alarm event, the root cause analysis of the first alarm event can be carried out, and then a handling plan for the first alarm event can be given. By using rich and comprehensive alarm feature maps, accurate and efficient alarm analysis and alarm handling can be achieved.

[0109] On the other hand, the alarm feature map of the first alarm event can also be used to assist in the extraction of alarm features for other similar alarm events. Since the first alarm event is similar to the second alarm event, the alarm feature map of the first alarm event can play an auxiliary role in the extraction of alarm features for the second alarm event to a certain extent, simplifying the process of extracting alarm features for the second alarm event and improving the accuracy of extracting alarm features for the second alarm event.

[0110] Based on the alarm feature extraction method for business risk control provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides an alarm feature extraction device for business risk control. The following will be combined with... Figure 4 This alarm feature extraction device used for business risk control is described in detail.

[0111] Figure 4 The illustration shows a schematic diagram of an alarm feature extraction device for business risk control provided in at least one embodiment of the present disclosure.

[0112] like Figure 4 As shown, the alarm feature extraction device 400 of this embodiment includes an acquisition module 401, a first extraction module 402, a determination module 403, and a second extraction module 404. For example, these units or modules can be implemented by hardware (e.g., circuit) modules or software modules, etc. The following embodiments are similar and will not be repeated. For example, these units or modules can be implemented by a central processing unit (CPU), a general-purpose graphics processor (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, as well as corresponding computer instructions.

[0113] The acquisition module 401 is configured to acquire the first alarm information associated with the first alarm event. For example, the acquisition module 401 can be configured to execute step S201 described above. The specific implementation principle can be referred to the relevant description of step S201, which will not be repeated here.

[0114] The first extraction module 402 is configured to: determine the first alarm feature of the first alarm information based on the first alarm information. For example, the first extraction module 402 can be configured to execute step S202 as described above; its specific implementation principle can be found in the relevant description of step S202, and will not be repeated here.

[0115] The determining module 403 is configured to: determine the first attack stage of the first alarm event within the first attack type based on the first alarm characteristics and the first threat detection model, wherein the first threat detection model provides attack information for each attack stage in multiple attack types. For example, the determining module 403 can be configured to execute step S203 described above; its specific implementation principle can be found in the relevant description of step S203, and will not be repeated here.

[0116] The second extraction module 404 is configured to: determine the second alarm feature of the first alarm information based on the attack information of the first attack stage of the first attack type in the first threat detection model. For example, the second extraction module 404 can be configured to execute step S204 as described above; its specific implementation principle can be found in the relevant description of step S204, and will not be repeated here.

[0117] In at least one embodiment of this disclosure, the first extraction module 402 is further configured to: extract features from the first alarm information to obtain initial alarm features; determine the first attack type corresponding to the first alarm event based on the initial alarm features; and determine the first alarm feature of the first alarm information based on the attack information of the first attack type in the first threat detection model.

[0118] In at least one embodiment of this disclosure, the first extraction module 402 is further configured to: acquire first model prompt information, wherein the first model prompt information includes: the first alarm information, attack information of the first attack type in the first threat detection model, and indication information for indicating feature extraction of the first alarm information; send the first model prompt information to the first artificial intelligence model, and receive the first alarm feature of the first alarm information returned by the first artificial intelligence model.

[0119] In at least one embodiment of this disclosure, the determining module 403 is further configured to: obtain second model prompt information, wherein the second model prompt information includes: the first alarm feature, attack information of each attack stage of the first attack type in the first threat detection model, and indication information for indicating the determination of the attack stage; send the second model prompt information to the second artificial intelligence model, and receive the first attack stage in the first attack type returned by the second artificial intelligence model.

[0120] In at least one embodiment of this disclosure, the second extraction module 404 is further configured to: use the attack information of the first attack stage of the first attack type in the first threat detection model as key information, match it with the first alarm information, and determine the second alarm feature of the first alarm information based on the matching result; or use a third artificial intelligence model to determine the second alarm feature of the first alarm information based on the attack information of the first attack stage of the first attack type in the first threat detection model.

[0121] In at least one embodiment of this disclosure, the attack information for each attack stage in the plurality of attack types includes at least one of the following: attack role information for each attack stage in the plurality of attack types; and attack behavior information for each attack stage in the plurality of attack types.

[0122] In at least one embodiment of this disclosure, the acquisition module 401 is further configured to: acquire the original alarm information carried by the first alarm event; and acquire alarm context information associated with the first alarm event.

[0123] In at least one embodiment of this disclosure, the alarm feature extraction device 400 for business risk control further includes a construction module configured to: construct an alarm feature map of the first alarm event based on the first alarm feature and the second alarm feature.

[0124] In at least one embodiment of this disclosure, the construction module is further configured to: construct an association between alarm features related to the same object in the first alarm feature and the second alarm feature; and construct an association between alarm features indicated by the first threat detection model in the first alarm feature and the second alarm feature.

[0125] In at least one embodiment of this disclosure, the alarm feature extraction device 400 for business risk control further includes a storage module configured to associate the first alarm event with the alarm feature map of the first alarm event and store it in a knowledge base.

[0126] In at least one embodiment of this disclosure, the alarm feature extraction device 400 for business risk control further includes a processing module configured to: determine the alarm analysis result of the first alarm event based on the alarm feature map of the first alarm event; or, in response to the similarity between the generated second alarm event and the first alarm event meeting a set condition, determine the alarm feature corresponding to the second alarm event based on the alarm feature map of the first alarm event.

[0127] It should be noted that, for clarity and brevity, this disclosure does not provide all the constituent units of the alarm feature extraction device 400 for business risk control. To achieve the necessary functions of the alarm feature extraction device 400 for business risk control, those skilled in the art can provide or configure other constituent units (not shown) according to specific needs, and this disclosure does not impose any limitations on this.

[0128] At least one embodiment of this disclosure also provides an electronic device, including: a processing device; a storage device including one or more computer program modules; wherein the one or more computer program modules are stored in the storage device and configured to be executed by the processing device, and the one or more computer program modules are used to implement the alarm feature extraction method for business risk control provided in any embodiment of this disclosure.

[0129] For example, the processing device may be a central processing unit (CPU), digital signal processor (DSP), image processor (GPU), general-purpose graphics processor (GPGPU), or other form of processing unit with data processing capabilities and / or instruction execution capabilities. It may be a general-purpose processor or a dedicated processor and may control other components in the electronic device to perform the desired functions.

[0130] For example, the storage device may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and a processing device may execute these program instructions to implement the functions (implemented by the processing device) in the embodiments of this disclosure and / or other desired functions. Various application programs and various data may also be stored in the computer-readable storage medium, which is not limited in the embodiments of this disclosure.

[0131] The following is for reference. Figure 5The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 500 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0132] like Figure 5 As shown, the electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the electronic device 500. The processing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0133] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0134] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a ROM 502. When the computer program is executed by the processing device 501, it performs the functions defined in the methods of embodiments of this disclosure.

[0135] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0136] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0137] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0138] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: acquire first alarm information associated with the first alarm event; determine a first alarm feature of the first alarm information based on the first alarm information; determine a first attack stage of the first alarm event in a first attack type based on the first alarm feature and a first threat detection model; and determine a second alarm feature of the first alarm information based on attack information of the first attack stage of the first attack type in the first threat detection model.

[0139] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0140] Embodiments of this disclosure also provide a computer program product comprising one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the processes or functions described in any embodiment of this disclosure are generated.

[0141] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0142] When the computer program product is executed by a computer, the computer executes any of the aforementioned alarm feature extraction methods for business risk control. The computer program product can be a software installation package; when any of the aforementioned alarm feature extraction methods for business risk control needs to be used, the computer program product can be downloaded and executed on the computer.

[0143] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0144] The units or modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units or modules do not necessarily constitute a limitation on the unit or module itself.

[0145] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0146] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0147] According to one or more embodiments of this disclosure, Example 1 provides a method for extracting alarm features for business risk control, including:

[0148] Obtain the first alarm information associated with the first alarm event;

[0149] Based on the first alarm information, determine the first alarm feature of the first alarm information;

[0150] Based on the first alarm feature and the first threat detection model, the first attack stage of the first alarm event in the first attack type is determined, wherein the first threat detection model provides attack information for each attack stage in multiple attack types.

[0151] Based on the attack information of the first attack stage of the first attack type in the first threat detection model, the second alarm feature of the first alarm information is determined.

[0152] According to one or more embodiments of this disclosure, Example 2 provides the method of determining a first alarm feature of the first alarm information based on the first alarm information, as in Example 1, including:

[0153] Feature extraction is performed on the first alarm information to obtain initial alarm features;

[0154] Based on the initial alarm characteristics, determine the first attack type corresponding to the first alarm event;

[0155] Based on the attack information of the first attack type in the first threat detection model, the first alarm feature of the first alarm information is determined.

[0156] According to one or more embodiments of this disclosure, Example 3 provides the method of determining a first alarm feature of the first alarm information based on attack information of the first attack type in the first threat detection model, as in Example 2, including:

[0157] Obtain first model prompt information, wherein the first model prompt information includes: first alarm information, attack information of the first attack type in the first threat detection model, and indication information for indicating feature extraction of the first alarm information;

[0158] The first model prompt information is sent to the first artificial intelligence model, and the first alarm feature of the first alarm information returned by the first artificial intelligence model is received.

[0159] According to one or more embodiments of this disclosure, Example 4 provides the method in Example 1 for determining the first attack stage of the first alarm event in a first attack type based on the first alarm characteristics and the first threat detection model, including:

[0160] Obtain second model prompt information, wherein the second model prompt information includes: the first alarm feature, attack information of each attack stage of the first attack type in the first threat detection model, and indication information for indicating the determination of the attack stage;

[0161] The second model prompt information is sent to the second artificial intelligence model, and the first alarm event returned by the second artificial intelligence model is received as being in the first attack stage of the first attack type.

[0162] According to one or more embodiments of this disclosure, Example 5 provides the method of determining a second alarm feature of the first alarm information based on attack information of the first attack stage of the first attack type in the first threat detection model, as in Example 1, including:

[0163] The attack information of the first attack stage of the first attack type in the first threat detection model is used as key information and matched with the first alarm information. Based on the matching result, the second alarm feature of the first alarm information is determined; or

[0164] Using a third artificial intelligence model, based on the attack information of the first attack stage of the first attack type in the first threat detection model, the second alarm feature of the first alarm information is determined.

[0165] According to one or more embodiments of this disclosure, Example Six provides attack information for each attack stage in multiple attack types of Example One, including at least one of the following:

[0166] Information on the attacking role at each stage of multiple attack types;

[0167] Information on attack behavior at each stage of multiple attack types.

[0168] According to one or more embodiments of this disclosure, Example 7 provides the method of obtaining first alarm information associated with the first alarm event as in Example 1, including:

[0169] Obtain the original alarm information carried by the first alarm event; and

[0170] Obtain the alarm context information associated with the first alarm event.

[0171] According to one or more embodiments of this disclosure, Example Eight provides a method from any of Examples One through Seven, further comprising:

[0172] Based on the first alarm feature and the second alarm feature, an alarm feature map of the first alarm event is constructed.

[0173] According to one or more embodiments of this disclosure, Example 9 provides that the correlation between alarm features in the alarm feature map of the first alarm event in Example 8 is determined by at least one of the following methods:

[0174] Construct the association relationship between alarm features related to the same object in the first alarm feature and the second alarm feature;

[0175] In constructing the first alarm feature and the second alarm feature, the first threat detection model indicates the correlation between related alarm features.

[0176] According to one or more embodiments of this disclosure, Example 10 provides the method of Example 8, further comprising:

[0177] The first alarm event is associated with the alarm feature map of the first alarm event and stored in the knowledge base.

[0178] According to one or more embodiments of this disclosure, Example 11 provides the method of Example 8, further comprising:

[0179] Based on the alarm feature map of the first alarm event, determine the alarm analysis result of the first alarm event; or

[0180] In response to the fact that the similarity between the generated second alarm event and the first alarm event meets the set conditions, the alarm features corresponding to the second alarm event are determined based on the alarm feature map of the first alarm event.

[0181] According to one or more embodiments of this disclosure, Example Twelve provides an alarm feature extraction apparatus, comprising:

[0182] The acquisition module is configured to: acquire the first alarm information associated with the first alarm event;

[0183] The first extraction module is configured to: determine the first alarm feature of the first alarm information based on the first alarm information;

[0184] The determination module is configured to: determine the first attack stage of the first alarm event in the first attack type based on the first alarm characteristics and the first threat detection model, wherein the first threat detection model provides attack information for each attack stage in multiple attack types;

[0185] The second extraction module is configured to: determine the second alarm feature of the first alarm information based on the attack information of the first attack stage of the first attack type in the first threat detection model.

[0186] According to one or more embodiments of this disclosure, Example Thirteen provides an electronic device, including:

[0187] Processing device; and

[0188] Storage device, including one or more computer program instructions;

[0189] The one or more computer program instructions are executed by the processing device to perform the alarm feature extraction method for business risk control provided in at least one embodiment of the present disclosure.

[0190] According to one or more embodiments of the present disclosure, Example Fourteen provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the alarm feature extraction method for business risk control provided in at least one embodiment of the present disclosure.

[0191] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0192] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0193] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A method for extracting alarm features for business risk control, comprising: Obtain the first alarm information associated with the first alarm event; Based on the first alarm information, determine the first alarm feature of the first alarm information; Based on the first alarm feature and the first threat detection model, the first attack stage of the first alarm event in the first attack type is determined, wherein the first threat detection model is a database storing attack information of each attack stage in multiple attack types. Based on the attack information of the first attack stage of the first attack type in the first threat detection model, determine the second alarm feature in the first alarm information that matches the first attack stage. The step of determining the first attack stage of the first alarm event in the first attack type based on the first alarm feature and the first threat detection model includes: obtaining second model prompt information, wherein the second model prompt information includes: the first alarm feature, attack information of each attack stage of the first attack type in the first threat detection model, and indication information for indicating the determination of the attack stage; sending the second model prompt information to the second artificial intelligence model, and receiving the first attack stage of the first alarm event in the first attack type returned by the second artificial intelligence model.

2. The method of claim 1, wherein, The step of determining the first alarm feature of the first alarm information based on the first alarm information includes: Feature extraction is performed on the first alarm information to obtain initial alarm features; Based on the initial alarm characteristics, determine the first attack type corresponding to the first alarm event; Based on the attack information of the first attack type in the first threat detection model, the first alarm feature of the first alarm information is determined.

3. The method according to claim 2, wherein, The step of determining the first alarm feature of the first alarm information based on the attack information of the first attack type in the first threat detection model includes: Obtain first model prompt information, wherein the first model prompt information includes: first alarm information, attack information of the first attack type in the first threat detection model, and indication information for indicating feature extraction of the first alarm information; The first model prompt information is sent to the first artificial intelligence model, and the first alarm feature of the first alarm information returned by the first artificial intelligence model is received.

4. The method according to claim 1, wherein, The step of determining a second alarm feature in the first alarm information that matches the first attack stage based on the attack information of the first attack type in the first threat detection model includes: The attack information of the first attack stage of the first attack type in the first threat detection model is used as key information and matched with the first alarm information. Based on the matching result, the second alarm feature of the first alarm information is determined; or Using a third artificial intelligence model, based on the attack information of the first attack stage of the first attack type in the first threat detection model, a second alarm feature matching the first attack stage is determined in the first alarm information.

5. The method according to claim 1, wherein, The attack information for each stage of the multiple attack types includes at least one of the following: Information on the attacking role at each stage of multiple attack types; Information on attack behavior at each stage of multiple attack types.

6. The method according to claim 1, wherein, The step of obtaining the first alarm information associated with the first alarm event includes: Obtain the original alarm information carried by the first alarm event; and Obtain the alarm context information associated with the first alarm event.

7. The method according to any one of claims 1 to 6, further comprising: Based on the first alarm feature and the second alarm feature, an alarm feature map of the first alarm event is constructed.

8. The method according to claim 7, wherein, The correlation between alarm features in the alarm feature map of the first alarm event is determined by at least one of the following methods: Construct the association relationship between alarm features related to the same object in the first alarm feature and the second alarm feature; In constructing the first alarm feature and the second alarm feature, the first threat detection model indicates the correlation between related alarm features.

9. The method according to claim 7, further comprising: The first alarm event is associated with the alarm feature map of the first alarm event and stored in the knowledge base.

10. The method of claim 7, further comprising: Based on the alarm feature map of the first alarm event, determine the alarm analysis result of the first alarm event; or In response to the fact that the similarity between the generated second alarm event and the first alarm event meets the set conditions, the alarm features corresponding to the second alarm event are determined based on the alarm feature map of the first alarm event.

11. An alarm feature extraction device for business risk control, comprising: The acquisition module is configured to: acquire the first alarm information associated with the first alarm event; The first extraction module is configured to: determine the first alarm feature of the first alarm information based on the first alarm information; The determination module is configured to: determine the first attack stage of the first alarm event in the first attack type based on the first alarm feature and the first threat detection model, wherein the first threat detection model is a database storing attack information of each attack stage in multiple attack types. The second extraction module is configured to: determine a second alarm feature in the first alarm information that matches the first attack stage based on the attack information of the first attack stage of the first attack type in the first threat detection model. The determining module is further configured to: acquire second model prompt information, wherein the second model prompt information includes: the first alarm feature, attack information of each attack stage of the first attack type in the first threat detection model, and indication information for indicating the determination of the attack stage; send the second model prompt information to the second artificial intelligence model, and receive the first attack stage in the first attack type returned by the second artificial intelligence model.

12. An electronic device, comprising: Processing device; as well as Storage device, including one or more computer program instructions; The one or more computer program instructions are executed by the processing device according to any one of claims 1 to 10.

13. A computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, The method of any one of claims 1 to 10 is implemented when the computer-readable instructions are executed by a processor.