Host malicious external connection event detection method and device

By collecting destination address information from host server logs and using a threat intelligence system to identify malicious destination addresses, the high cost and low coverage issues caused by traditional hardware dependence are resolved, achieving efficient detection of malicious external connection events.

CN121037066APending Publication Date: 2025-11-28SINA TECH (CHINA) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511217113.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

Traditional methods for detecting malicious external connections to hosts rely on hardware optical splitters, which result in high costs and limited coverage, making it ineffective for monitoring malicious external connection events on a large scale of servers.

Method used

By collecting destination address information from the host's server logs, a threat intelligence system is used to identify malicious destination addresses and generate alerts, avoiding direct monitoring of hardware devices and achieving large-scale detection solely through software agents.

Benefits of technology

It has increased detection coverage, reduced detection costs, and improved the efficiency of threat intelligence detection by filtering non-enterprise public IPs and domains to reduce invalid queries.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037066A_ABST
    Figure CN121037066A_ABST
Patent Text Reader

Abstract

The invention provides a malicious external connection event detection method and device of a host. The method comprises the steps that multiple pieces of destination address information are collected in a server log of the host; the destination address information comprises a destination IP and / or a destination domain name; the destination IP is used for indicating IP addresses requested to be accessed by a plurality of servers of the host; the destination domain name is used for indicating websites requested to be accessed by a plurality of servers of the host; the server log is generated through a log generation system deployed in the host; determining malicious destination address information in the multiple pieces of destination address information; the malicious destination address information refers to destination address information successfully matched with a malicious address in the threat intelligence system; determining an alarm object according to the malicious destination address information; and outputting the malicious external connection event alarm information to the alarm object. According to the invention, the detection coverage can be improved, and the detection cost can be saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method and apparatus for detecting malicious external connection events of a host. Background Technology

[0002] Traditional methods for detecting malicious outbound connections on traditional servers primarily rely on traffic splitting technology. This involves performing deep packet inspection or metadata analysis on mirrored traffic to detect malicious connections. This approach requires the deployment of hardware splitting devices, and the number of devices increases linearly with the number of servers, leading to a linear increase in hardware costs. Furthermore, the coverage of these hardware splitting devices is low. Therefore, improving the detection coverage while reducing the cost of malicious outbound connection detection is one of the most pressing technical challenges. Summary of the Invention

[0003] This application provides a method and apparatus for detecting malicious external connection events on a host, so as to improve the detection coverage and save detection costs.

[0004] The technical solution of this application is implemented as follows:

[0005] This application provides a method for detecting malicious external connection events on a host, comprising: collecting multiple destination address information from the host's server logs; the destination address information includes a destination IP and / or a destination domain name; the destination IP is used to indicate the IP address requested by multiple servers on the host; the destination domain name is used to indicate the URL requested by multiple servers on the host; the server logs are generated by a log generation system deployed on the host; identifying malicious destination address information from the multiple destination address information; the malicious destination address information refers to the destination address information that successfully matches a malicious address in a threat intelligence system; determining an alarm object based on the malicious destination address information; and outputting malicious external connection event alarm information to the alarm object.

[0006] In some possible implementations, the server logs include host intrusion detection logs and / or domain name resolution logs; the host intrusion detection logs are used to record the behavior of multiple servers on the host requesting access to the network via IP addresses; the domain name resolution logs are used to record the behavior of multiple servers on the host accessing the network via domain names; multiple destination address information is collected from the host's server logs, including: collecting the destination IP in the host intrusion detection logs; the host intrusion detection logs include at least the destination IP and the source IP corresponding to the destination IP; the source IP is the IP address corresponding to the server on the host that requests access to the destination IP; and / or collecting the destination domain name in the domain name resolution logs; the domain name resolution logs include at least the destination domain name and the client IP corresponding to the destination domain name; the client IP is the IP address of the client used by the user when initiating a domain name resolution request through the host.

[0007] In some possible implementations, when the destination address information is a destination IP, the malicious destination address information is a malicious destination IP, and the alarm target is the administrator ID corresponding to the server on the host that requested access to the malicious destination IP; when the destination address information is a destination domain name, the malicious destination address information is a malicious destination domain name, and the alarm target is the user ID that requested access to the malicious destination domain name through any server on the host.

[0008] In some possible implementations, when the alarm object is the administrator ID corresponding to the server requesting access to the malicious destination IP in the host, the alarm object is determined based on the malicious destination address information, including: determining the victim IP corresponding to the malicious destination IP in the host intrusion detection log based on the malicious destination IP; determining the alarm object corresponding to the victim IP in the domain name management table based on the victim IP; the domain name management table is used to associate and store domain names, the IP addresses pointed to by the domain names, and the administrator IDs of the managed domain names.

[0009] In some possible implementations, the server logs include access authentication logs; the access authentication logs include at least the authentication IP and the user ID associated with the authentication IP; the authentication IP is the IP address assigned to the client used by the user by the server in the host when the user requests access to the network; when the alarm object is a user ID that requests access to a malicious destination domain name through any server of the host, the alarm object is determined based on the malicious destination address information, including: determining the victim client IP corresponding to the malicious destination domain name in the domain name resolution log based on the malicious destination domain name; determining the victim authentication IP that is the same as the victim client IP in the access authentication log based on the victim client IP; and determining the alarm object associated with the victim authentication IP in the access authentication log based on the victim authentication IP.

[0010] In some possible implementations, the malicious address in the threat intelligence system includes at least one malicious IP; determining the malicious destination address information from multiple destination address information includes: filtering multiple destination IPs and retaining non-enterprise public network IPs among the multiple destination IPs; comparing the filtered destination IPs with each malicious IP in the threat intelligence system, and determining the destination IP as a malicious destination IP if the destination IP is the same as any malicious IP and the reputation score of any malicious IP associated with it is greater than a first threshold.

[0011] In some possible implementations, the malicious address in the threat intelligence system includes at least one malicious domain name; determining the malicious destination address information from multiple destination address information includes: filtering multiple destination domain names and retaining non-enterprise public domain names among the multiple destination domain names; comparing the filtered destination domain names with each malicious domain name in the threat intelligence system, and determining the destination domain name as a malicious destination domain name if the destination domain name is the same as any malicious domain name and the reputation score of the domain name associated with the malicious domain name is greater than a second threshold.

[0012] In some possible implementations, the method further includes: aggregating threat intelligence data generated by the protection systems of multiple servers on the host; formatting the threat intelligence data to generate a threat intelligence table; the threat intelligence table includes IP-related information in a first format and domain-related information in a second format; the IP-related information includes at least a malicious IP, the IP reputation score corresponding to the malicious IP, and a first threat type label; the domain-related information includes at least a malicious domain, the domain reputation score corresponding to the malicious domain, and a second threat type label; and caching the threat intelligence table to the threat intelligence system.

[0013] In some possible implementations, the method further includes: obtaining domain name information bound to multiple servers of the host in the log collection system; the domain names in the domain name information point to the IP addresses of multiple servers; resolving the domain name information to determine the IP addresses pointed to by the domain names in the domain name information; associating and saving the domain name, the IP address pointed to by the domain name, and the administrator ID of the managed domain name to generate a domain name management table.

[0014] This application provides a malicious external connection event detection device for a host, comprising: a data acquisition module for collecting multiple destination address information from the host's server logs; the destination address information includes a destination IP and / or a destination domain name; the destination IP is used to indicate the IP address requested by multiple servers of the host; the destination domain name is used to indicate the URL requested by multiple servers of the host; the server logs are generated by a log generation system deployed on the host; a malicious external connection location module for determining malicious destination address information from the multiple destination address information; the malicious destination address information refers to the destination address information that successfully matches a malicious address in a threat intelligence system; a malicious external connection source tracing module for determining the alarm object based on the malicious destination address information; and an alarm module for outputting malicious external connection event alarm information to the alarm object.

[0015] In some possible implementations, the server logs include host intrusion detection logs and / or domain name resolution logs; the host intrusion detection logs are used to record the behavior of multiple servers on the host requesting access to the network via IP addresses; the domain name resolution logs are used to record the behavior of multiple servers on the host accessing the network via domain names; a data collection module is used to collect the destination IP from the host intrusion detection logs; the host intrusion detection logs include at least the destination IP and the source IP corresponding to the destination IP; the source IP is the IP address corresponding to the server on the host that requests access to the destination IP; and / or collect the destination domain name from the domain name resolution logs; the domain name resolution logs include at least the destination domain name and the client IP corresponding to the destination domain name; the client IP is the IP address of the client used by the user when initiating a domain name resolution request through the host.

[0016] In some possible implementations, when the destination address information is a destination IP, the malicious destination address information is a malicious destination IP, and the alarm target is the administrator identifier ID corresponding to the server on the host that requested access to the malicious destination IP; when the destination address information is a destination domain name, the malicious destination address information is a malicious destination domain name, and the alarm target is the user ID that requested access to the malicious destination domain name through any server on the host.

[0017] In some possible implementations, when the alarm object is the administrator ID corresponding to the server requesting access to the malicious target IP in the host, the malicious external connection tracing module is used to determine the victim IP corresponding to the malicious target IP in the host intrusion detection log based on the malicious target IP; and to determine the alarm object corresponding to the victim IP in the domain name management table based on the victim IP; the domain name management table is used to associate and store the domain name, the IP address pointed to by the domain name, and the administrator ID of the domain name.

[0018] In some possible implementations, the server logs include access authentication logs; the access authentication logs include at least the authentication IP and the user ID associated with the authentication IP; the authentication IP is the IP address assigned to the client used by the user by the server in the host when the user requests access to the network; when the alarm object is a user ID that requests access to a malicious target domain name through any server of the host, the malicious external connection tracing module is used to determine the victim client IP corresponding to the malicious target domain name in the domain name resolution log based on the malicious target domain name; determine the victim authentication IP that is the same as the victim client IP in the access authentication log based on the victim authentication IP; and determine the alarm object associated with the victim authentication IP in the access authentication log based on the victim authentication IP.

[0019] In some possible implementations, the malicious address in the threat intelligence system includes at least one malicious IP; the malicious external connection location module is used to filter multiple destination IPs and retain non-enterprise public network IPs among the multiple destination IPs; the filtered destination IPs are compared with each malicious IP in the threat intelligence system, and if the destination IP is the same as any malicious IP and the reputation score of any malicious IP is greater than a first threshold, the destination IP is determined to be a malicious destination IP.

[0020] In some possible implementations, the malicious address in the threat intelligence system includes at least one malicious domain name; the malicious external link location module is used to filter multiple destination domain names and retain non-enterprise public network domain names among the multiple destination domain names; the filtered destination domain name is compared with each malicious domain name in the threat intelligence system, and if the destination domain name is the same as any malicious domain name and the reputation score of the domain name associated with the malicious domain name is greater than a second threshold, the destination domain name is determined to be a malicious destination domain name.

[0021] In some possible implementations, the device further includes: a threat intelligence generation module for aggregating threat intelligence data generated by the protection systems of multiple servers on the host; formatting the threat intelligence data to generate a threat intelligence table; the threat intelligence table includes IP-related information in a first format and domain-related information in a second format; the IP-related information includes at least a malicious IP, the IP reputation score corresponding to the malicious IP, and a first threat type label; the domain-related information includes at least a malicious domain, the domain reputation score corresponding to the malicious domain, and a second threat type label; and caching the threat intelligence table to the threat intelligence system.

[0022] In some possible implementations, the device further includes: a domain name management table generation module, used to obtain domain name information bound to multiple servers of the host in the log collection system, wherein the domain name in the domain name information points to the IP addresses of multiple servers; parse the domain name information to determine the IP address pointed to by the domain name in the domain name information; associate and save the domain name, the IP address pointed to by the domain name, and the administrator ID of the managed domain name to generate a domain name management table.

[0023] This application provides an electronic device, including: a memory for storing executable instructions; and a processor for executing the executable instructions stored in the memory to implement the method provided in this application.

[0024] This application provides a computer storage medium storing executable instructions, which are executed by a processor to implement the method provided in this application.

[0025] This application provides a computer program product, including a computer program or instructions, which, when executed by a processor, implement the method provided in this application.

[0026] This application has the following beneficial effects:

[0027] In this application, server logs are generated by a log generation system deployed on the host machine. This log generation system is distributed across multiple servers on the host machine as agent software; that is, each server on the host machine has a log generation system deployed on it. Based on the log generation system, the destination IP and / or destination domain name are collected from the server logs of each server, and malicious outbound events are located based on the destination IP and destination domain name (i.e., the malicious destination IP and malicious destination domain name are determined). This avoids monitoring and detecting malicious outbound events on the host machine through hardware devices. As the scale of servers in the data center increases, only the number of host data collection agent software programs needs to be increased to complete the detection of outbound threat events on a large scale of servers, effectively improving the detection coverage and saving detection costs.

[0028] Furthermore, before comparing the destination IP with malicious IPs in the threat intelligence system, and before comparing the destination domain with malicious domains in the threat intelligence system, the destination IP and destination domain are filtered, retaining only non-enterprise public IPs and non-enterprise public domains. This reduces the number of collisions between invalid IPs and invalid domains and the threat intelligence system during subsequent comparisons, thereby saving on the query costs of the threat intelligence system and improving the collision detection efficiency. Attached Figure Description

[0029] Figure 1 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application;

[0030] Figure 2 This is an optional flowchart illustrating the method for detecting malicious external connection events of a host provided in the embodiments of this application;

[0031] Figure 3 This is an optional flowchart illustrating the method for detecting malicious external connection events of a host provided in the embodiments of this application;

[0032] Figure 4 This is a physical architecture diagram of the host provided in the embodiments of this application. Detailed Implementation

[0033] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0034] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0035] If the application documents contain similar descriptions such as "first / second", the following explanation shall be added: In the following description, the terms "first / second / third" are used only to distinguish similar objects and do not represent a specific order of objects. It is understood that "first / second / third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0036] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0037] Traditional methods for detecting malicious outbound connections primarily rely on traffic splitting technology, using mirrored network traffic for deep packet inspection or metadata analysis. This hardware solution is costly, has limited detection coverage, and its cost increases with the number of servers.

[0038] In some embodiments, commercial threat intelligence localization can support unlimited concurrent threat intelligence interface queries, but it is expensive. Cloud threat intelligence query interfaces are inexpensive. However, interface queries are limited. Traditional threat intelligence interface queries exhaust the query limit too quickly, failing to meet the needs of IP reputation collision analysis used by many security detection systems.

[0039] In some embodiments, the current real-time analysis and detection strategy based on the threat intelligence message queue of the host detection system is limited by the linear queue data consumption, making it impossible to quickly index message data, creating inflexible and limited security detection strategies, and making it impossible to create multi-log data linkage detection strategies for the host intrusion detection system.

[0040] In some embodiments, traditional IDC server external malicious communication relies on optical mirroring equipment for statistical analysis. However, IDC data centers have huge traffic, high hardware costs, low coverage, and excessive costs, making it impossible to effectively monitor large-scale public network malicious communication.

[0041] To address the aforementioned issues, this application provides a method for detecting malicious external connection events on a host, which can improve the detection coverage and save detection costs.

[0042] See Figure 1 , Figure 1 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Figure 1 The illustrated electronic device 100 can be a terminal and / or a server. Electronic device 100 includes at least one processor 110, memory 150, at least one network interface 120, and a user interface 130. The various components in electronic device 100 are coupled together via a bus system 140. It is understood that the bus system 140 is used to implement communication between these components. In addition to a data bus, the bus system 140 also includes a power bus, a control bus, and a status signal bus. However, for clarity, ... Figure 1 The general labeled all buses as Bus System 140.

[0043] The processor 110 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0044] User interface 130 includes one or more output devices 131 that enable the presentation of media content, including one or more speakers and / or one or more visual displays. User interface 130 also includes one or more input devices 132, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.

[0045] The memory 150 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state storage, hard disk drives, optical disk drives, etc. The memory 150 may optionally include one or more storage devices physically located away from the processor 110.

[0046] The memory 150 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), and the volatile memory may be random access memory (RAM). The memory 150 described in this application embodiment is intended to include any suitable type of memory.

[0047] In some embodiments, memory 150 is capable of storing data to support various operations, examples of which include programs, modules, and data structures or subsets or supersets thereof, as illustrated below.

[0048] Operating system 151 includes system programs for handling various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, driver layer, etc., for implementing various basic business functions and handling hardware-based tasks;

[0049] The network communication module 152 is used to reach other computing devices via one or more (wired or wireless) network interfaces 120, exemplary network interfaces 120 including: Bluetooth, WiFi, and Universal Serial Bus (USB), etc.

[0050] Presentation module 153 is configured to enable the presentation of information (e.g., a user interface for operating peripheral devices and displaying content and information) via one or more output devices 131 (e.g., a display screen, a speaker, etc.) associated with user interface 130;

[0051] The input processing module 154 is used to detect and translate one or more user inputs or interactions from one or more input devices 132.

[0052] In some embodiments, the malicious external connection event detection device for the host provided in this application can be implemented in software. Figure 1 A malicious external connection event detection device 155 for a host, stored in memory 150, is shown. It can be software in the form of programs and plug-ins. The malicious external connection event detection device 155 for the host includes the following software modules: data acquisition module 1551, malicious external connection location module 1552, malicious external connection source tracing module 1553, and alarm module 1554.

[0053] These modules are logically structured, and therefore can be combined or further broken down arbitrarily according to their implemented functions. The functions of each module will be explained below.

[0054] In other embodiments, the malicious external connection event detection device for the host provided in this application can be implemented in hardware. As an example, the device provided in this application can be a processor in the form of a hardware decoding processor, which is programmed to execute the malicious external connection event detection method for the host provided in this application. For example, the processor in the form of a hardware decoding processor can be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.

[0055] The following will describe the method for detecting malicious external connection events of a host provided in the embodiments of this application, in conjunction with exemplary applications and implementations of the electronic devices provided in the embodiments of this application.

[0056] It should be noted that, for ease of description, the malicious external connection event detection device will be referred to as the detection device below. The malicious external connection event detection device is used to detect malicious external connection events on the host.

[0057] See Figure 2 , Figure 2 This is an optional flowchart illustrating the malicious external connection event detection method for a host provided in this application embodiment. The following will be combined with... Figure 2 The steps shown illustrate the method for detecting malicious external connection events on a host.

[0058] Step S201: Collect multiple destination address information from the host's server logs.

[0059] In some embodiments, the destination address information includes the destination Internet Protocol (IP) and / or the destination domain name; the destination IP is used to indicate the IP address requested by multiple servers of the host; the destination domain name is used to indicate the URL requested by multiple servers of the host. The host includes multiple servers, each of which deploys at least one log generation system.

[0060] In some embodiments, a host may include multiple servers and multiple client devices, wherein the servers provide services such as log storage, application services, and databases, and the client devices are devices directly operated by users to access network resources and services.

[0061] In some embodiments, a log generation system distributed across multiple servers collects multiple destination IPs and multiple destination domains.

[0062] Understandably, the log generation system is used to collect host logs, and it is deployed as agent software on multiple servers. When a new host (e.g., a server) is added to the network, the log generation agent software only needs to be deployed on the new server to complete the collection of logs for that host, thereby realizing the malicious external connection event detection method for hosts described in this application embodiment.

[0063] In some embodiments, the log generation system can generate various different types of log data.

[0064] In one example, where the log generation system is a host-based intrusion detection system (HIDS), the HIDS is deployed on a host (such as a server) to monitor host activity and network sessions (e.g., logging connection requests the server attempts to access external networks). The HIDS generates host intrusion detection logs. The log content recorded by the HIDS includes the IP addresses (i.e., destination IPs) accessed by the server within a preset time period.

[0065] In one example, when the log generation system is the Domain Name System (DNS), the DNS generates DNS resolution logs. These logs record detailed information about domain name resolution requests and responses (such as the requesting domain name, the requesting source IP address, the responding IP address, and timestamps). DNS resolution logs can be used to analyze domain name query behavior initiated by users or devices. The DNS records include the URLs (i.e., destination domain names) that users requested to access within a preset time period.

[0066] In one example, when the log generation system is an intelligent management center (IMC), the access authentication system generates access authentication logs. These logs record authentication process information (such as username, device MAC / IP address, authentication time, authentication result, etc.) when a client device (such as a user's computer or mobile phone) attempts to access the office intranet.

[0067] Step S202: Determine the malicious destination address information from multiple destination address information. Here, malicious destination address information refers to destination address information that successfully matches a malicious address in the threat intelligence system.

[0068] In some embodiments, the threat intelligence system stores known malicious network entity identifiers, primarily including: malicious destination IPs and malicious destination domains. Malicious destination IPs are Internet Protocol addresses that have been confirmed to be involved in or associated with malicious activities (such as attack sources, command and control servers, scanning sources, phishing hosts, etc.); these addresses pose a threat to hosts and may be used to launch intrusions, data theft, denial-of-service attacks, etc. Malicious destination domains are domains that have been confirmed to be used for malicious purposes (such as hosting malware, phishing websites, botnet command and control, fraud, etc.); host access to or resolution of these domains may lead to security risks, such as downloading malicious payloads, leaking credentials, or being remotely controlled.

[0069] In some possible implementations, when the destination address information is a destination IP, the malicious destination address information is a malicious destination IP, and the alarm object is the administrator identifier (ID) corresponding to the server requesting access to the malicious destination IP on the host; when the destination address information is a destination domain name, the malicious destination address information is a malicious destination domain name, and the alarm object is the user ID of the user who requests access to the malicious destination domain name through any server on the host.

[0070] Understandably, matching each of the multiple destination IPs with a malicious IP is performed. If a match is found, it indicates that the destination IP is malicious (i.e., a malicious destination IP) and may pose a threat to the host. Similarly, matching each of the multiple destination domain names with a malicious domain name is performed. If a match is found, it indicates that the destination domain name is malicious (i.e., a malicious destination domain) and may pose a threat to the host.

[0071] Step S203: Determine the target of the alert based on the malicious destination address information.

[0072] Understandably, there is a correlation between IP addresses and domain names; a domain name points to an IP address. Based on the malicious target IP, the administrator ID (hereinafter referred to as the target administrator ID) managing the domain name pointing to the malicious target IP can be determined; and / or, based on the malicious target domain name, the user ID (hereinafter referred to as the target user ID) that initiates access to the malicious target domain name through any server on the host can be determined.

[0073] In some embodiments, the target administrator ID is the ID of the administrator corresponding to the server accessing the malicious target IP; the target user ID is the ID of the user accessing the malicious target domain.

[0074] Understandably, based on the various types of logs generated by the log generation system, it is possible to determine the target administrator ID of the server requesting access to the malicious target IP in the logs when the malicious target IP is known, and it is also possible to determine the target user ID of the domain name requesting access to the malicious target domain in the logs when the malicious target domain is known.

[0075] Step S204: Output malicious external connection event alarm information to the alarm object.

[0076] In some embodiments, a malicious outbound connection event alert is generated for the host based on the target administrator ID and / or the target user ID.

[0077] Understandably, when a malicious outbound connection event is detected from a server within the management scope associated with the target administrator ID, the detection device generates an alarm message and sends it to the administrator corresponding to the target administrator ID via a preset alarm channel (such as email, SMS, or internal corporate communication tools). When a network access initiated by a user client device (such as a personal computer or laptop) associated with the target user ID triggers a malicious outbound connection rule, the detection device generates an alarm message and sends it to the client user corresponding to the target user ID via a preset client alarm method (such as client security proxy, pop-up notification, email, or corporate communication tools).

[0078] In some possible implementations, the server logs include host intrusion detection logs and / or domain name resolution logs; the host intrusion detection logs are used to record the behavior of multiple servers on the host requesting access to the network via IP addresses; the domain name resolution logs are used to record the behavior of multiple servers on the host accessing the network via domain names. Step S201 may include: collecting the destination IP from the host intrusion detection logs; the host intrusion detection logs include at least the destination IP and the source IP corresponding to the destination IP; the source IP is the IP address corresponding to the server on the host requesting access to the destination IP; and / or, collecting the destination domain name from the domain name resolution logs; the domain name resolution logs include at least the destination domain name and the client IP corresponding to the destination domain name; the client IP is the IP address of the client used by the user when initiating a domain name resolution request through the host.

[0079] In some embodiments, a host intrusion detection system is deployed on each server in the host, which logs server requests to access the network (i.e., host intrusion detection logs). A domain name system is deployed on a specific server (such as a DNS server) in the host, which logs user-initiated domain name resolution requests (i.e., domain name resolution logs).

[0080] In some embodiments, after the host intrusion detection system generates host intrusion detection logs, the log collection system (such as graylog) creates a UDP protocol network listening service to receive host intrusion detection logs sent out by the host intrusion detection system using the Syslog protocol. Upon receiving the host intrusion detection logs, the log collection system filters and adjusts the log format. The log format is as follows: [Source IP][Source Port][Destination IP][Destination Port][Protocol][Process Name][Process ID][Username][Timestamp]. The log collection system saves the processed logs to an Elasticsearch cluster database. The Elasticsearch cluster database creates indexes according to predefined templates, and the format of the saved logs is as follows: [Index Name][Source IP][Source Port][Destination IP][Destination Port][Protocol][Process Name][Process ID][Username][Timestamp]. Here, [Index Name] is the table index name in the Elasticsearch cluster database.

[0081] In some embodiments, the Domain Name System is configured with a syslog log forwarding policy, which is used to forward domain name resolution logs to the DNS log listening service of a log collection system (such as graylog).

[0082] In some embodiments, the log collection system creates a UDP network listening service to receive domain name resolution logs sent from the Domain Name System. Upon receiving the logs, it filters and adjusts the log format, which is as follows: [DNS Server IP][Client IP][Domain Name][Timestamp]. The log collection system saves the processed logs to an Elasticsearch cluster database. The Elasticsearch cluster database creates indexes according to a predefined template, and the format of the saved logs is as follows: [Index Name][DNS Server IP][Client IP][Domain Name][Timestamp]. Here, [Index Name] is the table index name in the Elasticsearch cluster database.

[0083] In some possible implementations, the log generation system may include an access authentication system in addition to the host intrusion detection system and domain name system described above. The method for detecting malicious external connections to the host may also include a log collection method for the access authentication system: collecting access authentication logs for each server deploying the access authentication system; the access authentication logs include at least the authentication IP and the user ID associated with the authentication IP; the authentication IP is the IP address assigned to the client used by the user by the server in the host when the user requests network access.

[0084] Understandably, an access authentication system can be deployed on a specific server (such as a management server) within a host. This system records logs of the server authenticating client devices when they request network access. Specifically, when a user requests network access through a client device, the server (such as a DHCP server) assigns a corresponding IP address to the client device. The access authentication system records the assigned IP address and also associates and stores it with information such as the user ID and timestamp.

[0085] In some embodiments, client devices on an enterprise's intranet need to be authenticated by an access authentication system to access the company network. Upon successful authentication, the access authentication system records the client device's IP address, MAC address, user ID, and other information, generating an access authentication log. The access authentication system can then send the access authentication log to a log collection system (such as graylog) via Syslog logs. The user ID corresponding to the client device can be determined from the access authentication log information, allowing the identification of the client device's owner.

[0086] In some embodiments, the log collection system creates a UDP network listening service to receive access authentication logs sent by the access authentication system. Upon receiving the logs, the system filters and adjusts the log format, which is as follows: [IP][Username ID][Timestamp]. The log collection system saves the processed logs to an Elasticsearch cluster database. The Elasticsearch cluster database creates an index according to a predefined template, and the format of the saved logs is as follows: [Index Name][IP][Username ID][Timestamp]. Here, [Index Name] is the table index name in the Elasticsearch cluster database.

[0087] In some possible implementations, when the alarm target is the administrator ID corresponding to the server requesting access to the malicious target IP in the host, step S203 may include: determining the victim source IP corresponding to the malicious target IP in the host intrusion detection log based on the malicious target IP; determining the administrator ID corresponding to the victim source IP in the domain name management table based on the victim source IP; the domain name management system is used to associate and store domain names, the IP addresses pointed to by the domain names, and the administrator IDs of the domain names; the IP addresses stored in the domain name management table include the source IPs.

[0088] In some embodiments, the host intrusion detection log associates and stores the malicious destination IP and the victim source IP, with each victim source IP corresponding to one malicious destination IP. The domain name management table is an information table generated by the domain name management system on the host, aggregating domain name information. The domain name management table associates and stores the domain name, the IP address the domain name points to, and the administrator ID managing the domain. Knowing the malicious destination IP, the administrator ID corresponding to the malicious destination IP can be determined based on the host intrusion detection log and the domain name management table.

[0089] In some possible implementations, the above-mentioned method for detecting malicious external connections to a host may also include a method for generating a domain name management table, including: obtaining domain name information bound to multiple servers of the host in a log collection system, wherein the domain names in the domain name information point to the IP addresses of multiple servers; parsing the domain name information to determine the IP addresses pointed to by the domain names in the domain name information; associating and saving the domain name, the IP address pointed to by the domain name, and the administrator ID of the administrator managing the domain name to generate a domain name management table.

[0090] Understandably, the host machine has a log collection system deployed on it. This system collects domain name query logs from all hosts on the network, recording all domain names in historical records. By resolving these domain names, the corresponding IP addresses are determined. Then, the domain names, IP addresses, and administrator IDs are associated and saved to obtain the domain name management table.

[0091] In some embodiments, the domain administrator configures the DNS resolution settings between domain names and IP addresses in the front-end management interface. The domain management system provides an API query function, supporting the query of relationship records between domain names, IP addresses, and administrator IDs. The domain management table generated by the domain management system is formatted as follows: [Domain Name] [IP Address] [Administrator ID].

[0092] In some embodiments, when the detection device is detecting malicious threat events, it can query and retrieve the required field content from the domain name management system via a RESTful API. For example, it can query the IP address and administrator ID corresponding to the domain name based on the domain name.

[0093] In some possible implementations, the server log includes an access authentication log; the access authentication log includes at least an authentication IP and a user ID associated with the authentication IP; the authentication IP is the IP address assigned to the client used by the user by the server in the host when the user requests network access. Step S203 may include: determining the victim client IP corresponding to the malicious destination domain name in the domain name resolution log based on the malicious destination domain name; determining the victim authentication IP that is the same as the victim client IP in the access authentication log based on the victim client IP; and determining the alarm object associated with the victim authentication IP in the access authentication log based on the victim authentication IP.

[0094] In some embodiments, the domain name management table is an information table generated by the domain name management system in the host, which aggregates domain name information. The domain name management table stores the domain name, the IP address the domain name points to, and the administrator ID of the domain name being managed. The access authentication log stores the IP address and the username ID corresponding to that IP address. Upon learning of a malicious target domain name, the target user ID (i.e., the alert target) corresponding to the malicious target domain name can be determined based on the domain name management table and the access authentication log.

[0095] In some possible implementations, the method for detecting malicious external connections to the host may further include generating a threat intelligence table, including: aggregating threat intelligence data generated by the protection systems of multiple servers on the host; formatting the threat intelligence data to generate a threat intelligence table; the threat intelligence table includes IP-related information in a first format and domain-related information in a second format; the IP-related information includes at least a malicious IP, the IP reputation score corresponding to the malicious IP, and a first threat type label; the domain-related information includes at least a malicious domain, the domain reputation score corresponding to the malicious domain, and a second threat type label; and caching the threat intelligence table to the threat intelligence system.

[0096] Understandably, the data in threat intelligence tables comes from two sources: open-source threat intelligence and commercial threat intelligence. Open-source threat intelligence is generated through threat intelligence systems, while commercial threat intelligence is obtained through commercial purchases.

[0097] In some embodiments, the detection device can aggregate threat intelligence data from multiple protection systems (such as office network firewall systems, traffic intrusion detection systems, WAF systems, and anti-crawler systems) through a threat intelligence system. The threat intelligence data is formatted according to a predetermined format to obtain a threat intelligence table. The threat intelligence table is directly cached in the threat intelligence system, and an API interface is provided for detecting malicious external connection events on hosts.

[0098] In some embodiments, for commercial threat intelligence, the commercial threat intelligence can be formatted and then the processed data can be cached in the threat intelligence system.

[0099] In some embodiments, threat intelligence information includes IP-related threat intelligence information in a first format and domain-related threat intelligence information in a second format. The first format is as follows: [IP][IP Reputation Score][Threat Intelligence Tag][Timestamp]. The second format is as follows: [Domain][Domain Reputation Score][Threat Intelligence Tag][Timestamp]. It should be noted that IP reputation score and domain reputation score can be directly expressed using the formats "low, relatively low, medium, relatively high, high" to represent the threat level of the IP and domain. A high IP reputation score or domain reputation score indicates a high threat level for the corresponding IP or domain. Alternatively, the threat level of the IP and domain can be directly expressed as a numerical value, with a higher value indicating a higher threat level.

[0100] In this embodiment, threat intelligence information is cached in the threat intelligence system, providing cost-free threat intelligence query services for various internal network detection systems. This effectively utilizes threat intelligence information generated locally within the enterprise, expands the scope of asset detection, reduces the cost of querying commercial threat intelligence, and saves economic costs associated with using threat intelligence.

[0101] In some possible implementations, the above-mentioned method for detecting malicious external connections to hosts may also include an information aggregation method for the configuration management database (CMDB) system, including: counting the IP addresses of hosts across the entire network, including internal network IPs (i.e., public network IPs belonging to company assets) and external network IPs (i.e., public network IPs not belonging to company assets); binding the administrator ID of the device to which the IP address belongs; recording the location marker of the device to which the IP address belongs; recording the allocation or change time of the IP address; and generating a configuration management table.

[0102] In one example, the IP address, administrator ID, data center name, and timestamp are associated and stored together to obtain a configuration management table. The format of the configuration management table is as follows: [IP][Administrator][Data Center Name][Timestamp]. Here, [IP] can be divided into [Internal IP] and [External IP].

[0103] In some possible implementations, step S202 may include: filtering multiple destination IPs and retaining non-enterprise public network IPs among the multiple destination IPs; comparing the filtered destination IPs with each malicious IP in the threat intelligence system, and determining the destination IP as a malicious destination IP if the destination IP is the same as any malicious IP and the reputation score of any malicious IP associated with it is greater than a first threshold.

[0104] Understandably, the detection device filters multiple destination IPs based on the "Internal IP" field in the configuration management table. The filtered destination IPs are all public IPs that do not belong to company assets. Then, the filtered destination IPs are compared with malicious IPs stored in the threat intelligence system. If the IP addresses are the same and the reputation score of the malicious IP is greater than a preset first threshold, the destination IP is identified as a malicious destination IP.

[0105] In some embodiments, in step S201, the target IP address within a preset first time period is collected. For example, the host intrusion detection log is queried according to a preset time window (e.g., a timestamp range of 1 minute) and preset query conditions to obtain the target IP address. The preset query conditions can be the target port and the protocol. For example, the target IP address is queried from the host intrusion detection log where the target port is 443 or 80 and the protocol is TCP.

[0106] In some embodiments, after querying the destination IP in the host intrusion detection log within a preset first time period, the queried destination IP is filtered, retaining only public IPs that do not belong to company assets. Finally, the aforementioned destination IPs (i.e., public IPs that do not belong to company assets) are deduplicated. The deduplicated destination IPs are then compared with all malicious IPs in the threat intelligence system.

[0107] In one example, host intrusion detection logs are retrieved at specific time intervals (e.g., every minute). The search criteria are: destination port {80} or {443}, and protocol {TCP}. The search results are deduplicated by destination port and protocol, removing duplicate destination IPs for both. The destination IPs in the deduplicated results are compared with the internal IPs in the configuration management table, excluding records where the destination IP is a public IP address. The filtered destination IPs are then correlated with the IPs in the threat intelligence system. If a destination IP in the search results is found to be a malicious IP recorded in the threat intelligence system and has a high reputation score, it is classified as a malicious IP. Based on the malicious destination IP, the source IP corresponding to the malicious destination IP is determined in the host intrusion detection logs. Finally, based on the source IP, the administrator ID corresponding to the source IP is determined in the configuration management table. Finally, threat event alert fields are generated, which are as follows: [Source IP] [Data Center Name] [Source Port] [Destination IP] [Destination Port] [Protocol] [Process Name] [Process ID] [Username] [Administrator ID] [IP Reputation Score] [Threat Intelligence Tag].

[0108] In this embodiment, data filtering and correlation analysis revealed multiple malicious external communication records, indicating that multiple server assets were subject to threat events. Threat event alerts identified which server initiated the malicious external communication event, along with the username, process name, process ID, and server administrator information of the process that initiated the external communication. The threat intelligence system then directly correlated these information with the malicious IP address to determine the specific type of malicious external communication threat, such as phishing emails or remote Trojan attacks. This allows security operations personnel to quickly respond to threat events through threat event alerts.

[0109] In some possible implementations, the malicious address in the threat intelligence system includes at least one malicious domain name; the above step S202 may include: filtering multiple destination domain names and retaining non-enterprise public domain names among the multiple destination domain names; comparing the filtered destination domain names with each malicious domain name in the threat intelligence system, and determining the destination domain name as a malicious destination domain name if the destination domain name is the same as any malicious domain name and the reputation score of the domain name associated with the malicious domain name is greater than a second threshold.

[0110] Understandably, the detection device filters multiple destination domains based on the "Domain" field in the domain management table. The filtered destination domains are all business domains not belonging to the company. Then, the filtered destination domains are compared with malicious domains stored in the threat intelligence system. If the domains are identical, and the reputation score of the malicious domain is greater than a preset second threshold, the destination domain is identified as a malicious destination domain.

[0111] In some embodiments, in step S201, the target domain name within a preset first time period is collected. For example, the domain name resolution log is queried according to a preset time window (e.g., the [timestamp] range is 1 minute) to obtain the target domain name.

[0112] In some embodiments, the domain name resolution logs are statistically analyzed according to a specific time window to obtain the destination domains. The destination domains are compared with the [Domain Names] in the domain name management table, filtering out company domains and retaining only business domains that do not belong to the company. The filtered destination domains are then deduplicated. The deduplicated destination domains are compared with the [Malicious Domain Names] in the threat intelligence system to identify malicious destination domains. Based on the malicious destination domain name, the client IP address accessing the malicious destination domain is determined from the domain name resolution logs. Based on the client IP address, the user ID accessing the malicious destination domain is searched in the access authentication logs, and then a malicious external connection event alert is issued.

[0113] In one example, access authentication logs are statistically analyzed at specific time intervals, with timestamps ranging from 1 minute, yielding multiple destination domains. These destination domains are then deduplicated based on their DNS server IP, client IP, and domain name. After filtering out duplicates, only business domains not belonging to the company are retained. The filtered destination domains are then compared with the domain names in the threat intelligence system. If a destination domain is found in the threat intelligence system and its corresponding domain reputation score is high, it is identified as a malicious domain, and any access to this malicious domain is classified as a malicious external domain threat event. Based on the malicious domain, the corresponding client IP is determined from the domain name resolution logs. Based on this client IP, the corresponding user ID is determined from the access authentication logs, and a malicious external event alert is triggered. The threat event alert fields are as follows: DNS server IP, client IP, domain name, domain reputation score, threat intelligence tag, and user ID.

[0114] This application provides a method for detecting malicious external connection events on a host. Figure 3 This is an optional flowchart illustrating the malicious external connection event detection method for a host provided in this application embodiment. It should be noted that... Figure 3 Only the case where the destination address information includes both the destination IP and the destination domain is shown. In the case where the destination address information only includes the destination IP, the step of determining the target user ID based on the malicious destination domain is simply removed from the embodiment, and this application embodiment will not elaborate on this. Similarly, in the case where the destination address information only includes the destination domain, the step of determining the target administrator ID based on the malicious destination IP is simply removed from the embodiment, and this application embodiment will not elaborate on this.

[0115] Figure 4 This is a physical architecture diagram of the host provided in an embodiment of this application. See also... Figure 3 and Figure 4 As shown, the above method may include:

[0116] It should be noted that, Figure 4 All the systems shown are deployed on the host machine.

[0117] Step S301 includes: Step S3011, the host intrusion detection system 401 generates a host intrusion detection log. Step S3012, the host intrusion detection log is formatted. Step S3013, the formatted host intrusion detection log is stored in the log collection system 404.

[0118] Step S302 includes: Step S3021, the Domain Name System 402 generates a domain name resolution log. Step S3022, the domain name resolution log is formatted. Step S3023, the formatted domain name resolution log is stored in the log collection system 404.

[0119] Step S303 includes: Step S3031, the access authentication system 403 generates an access authentication log. Step S3032, the access authentication log is formatted. Step S3033, the formatted access authentication log is stored in the log collection system 404.

[0120] Step S304: The configuration management system 405 generates the configuration management table.

[0121] Step S305: The domain name management system generates the domain name management table.

[0122] Step S306: The threat intelligence system 407 generates a threat intelligence table.

[0123] In step S307, the malicious external connection event analysis system 408, based on the destination IP and destination domain name, as well as the configuration management table, domain name management table, and threat intelligence table, determines the administrator ID of the server where the malicious external connection event occurred and the user ID of the user accessing the malicious destination domain name.

[0124] In some embodiments, after collecting host intrusion detection logs, domain name resolution logs, and access authentication logs, the log collection system 404 stores the host intrusion detection logs, domain name resolution logs, and access authentication logs in the cluster database 411.

[0125] Step S308: The malicious external connection event analysis system 408 obtains analysis data (i.e., destination IP and destination domain name) from the cluster database 411, obtains analysis results (i.e., server IP and user ID), and stores the analysis results in the database 409.

[0126] Step S309: Visualize the analysis results in the visualization system 410.

[0127] In this embodiment, server logs are generated by a log generation system deployed on the host. This log generation system is distributed across multiple servers on the host as agent software; that is, each server on the host has a log generation system deployed on it. Based on the log generation system, the destination IP and / or destination domain name are collected from the server logs of each server, and malicious outbound events are located based on the destination IP and destination domain name (i.e., the malicious destination IP and malicious destination domain name are determined). This avoids monitoring and detecting malicious outbound events on the host through hardware devices. As the scale of servers in the data center increases, only the number of host data collection agent software needs to be increased to complete the detection of outbound threat events on a large scale of servers, effectively improving the detection coverage and thus saving detection costs.

[0128] Furthermore, before comparing the destination IP with malicious IPs in the threat intelligence system, and before comparing the destination domain with malicious domains in the threat intelligence system, the destination IP and destination domain are filtered, retaining only non-enterprise public IPs and non-enterprise public domains. This reduces the number of collisions between invalid IPs and invalid domains and the threat intelligence system during subsequent comparisons, thereby saving on the query costs of the threat intelligence system and improving the collision detection efficiency.

[0129] Furthermore, the threat intelligence system caches threat intelligence information, enabling it to provide unlimited threat intelligence query services for detecting malicious external connections, regardless of cost or frequency. This saves on the economic costs of using threat intelligence.

[0130] Furthermore, this application embodiment utilizes a threat intelligence system to quickly locate malicious external connection events to malicious target IPs and domains. Based on the malicious target IP, malicious target domain, host intrusion detection logs, domain management table, domain name resolution logs, and access authentication logs, it can quickly trace the malicious external connection events back to the administrator IP and user ID. This significantly improves the host's response speed to malicious external connection events.

[0131] The following continues to describe an exemplary structure of the malicious external connection event detection device 155 for a host provided in this application embodiment as a software module. In some embodiments, such as Figure 1As shown, the software modules in the malicious external connection event detection device 155 of the host stored in the memory 150 may include: a data acquisition module 1551, used to collect multiple destination address information from the host's server logs; the destination address information includes a destination IP and / or a destination domain name; the destination IP is used to indicate the IP address requested by multiple servers of the host; the destination domain name is used to indicate the URL requested by multiple servers of the host; the server logs are generated by a log generation system deployed in the host; a malicious external connection location module 1552, used to determine malicious destination address information from multiple destination address information; the malicious destination address information refers to the destination address information that successfully matches the malicious address in the threat intelligence system; a malicious external connection source tracing module 1553, used to determine the alarm object based on the malicious destination address information; and an alarm module 1554, used to output malicious external connection event alarm information to the alarm object.

[0132] In some possible implementations, the server logs include host intrusion detection logs and / or domain name resolution logs; the host intrusion detection logs are used to record the behavior of multiple servers on the host requesting access to the network via IP addresses; the domain name resolution logs are used to record the behavior of multiple servers on the host accessing the network via domain names; the data acquisition module 1551 is used to collect the destination IP in the host intrusion detection logs; the host intrusion detection logs include at least the destination IP and the source IP corresponding to the destination IP; the source IP is the IP address corresponding to the server on the host that requests access to the destination IP; and / or collect the destination domain name in the domain name resolution logs; the domain name resolution logs include at least the destination domain name and the client IP corresponding to the destination domain name; the client IP is the IP address of the client used by the user when initiating a domain name resolution request through the host.

[0133] In some possible implementations, when the destination address information is a destination IP, the malicious destination address information is a malicious destination IP, and the alarm target is the administrator identifier ID corresponding to the server on the host that requested access to the malicious destination IP; when the destination address information is a destination domain name, the malicious destination address information is a malicious destination domain name, and the alarm target is the user ID that requested access to the malicious destination domain name through any server on the host.

[0134] In some possible implementations, when the alarm object is the administrator ID corresponding to the server requesting access to the malicious target IP in the host, the malicious external connection tracing module 1553 is used to determine the victim IP corresponding to the malicious target IP in the host intrusion detection log based on the malicious target IP; and to determine the alarm object corresponding to the victim IP in the domain name management table based on the victim IP; the domain name management table is used to associate and store the domain name, the IP address pointed to by the domain name, and the administrator ID of the domain name.

[0135] In some possible implementations, the server logs include access authentication logs; the access authentication logs include at least an authentication IP and a user ID associated with the authentication IP; the authentication IP is the IP address assigned to the client used by the user by the server in the host when the user requests access to the network; when the alarm object is a user ID that requests access to a malicious target domain name through any server of the host, the malicious external connection tracing module 1553 is used to determine the victim client IP corresponding to the malicious target domain name in the domain name resolution log based on the malicious target domain name; determine the victim authentication IP that is the same as the victim client IP in the access authentication log based on the victim client IP; and determine the alarm object associated with the victim authentication IP in the access authentication log based on the victim authentication IP.

[0136] In some possible implementations, the malicious address in the threat intelligence system includes at least one malicious IP; the malicious external connection location module 1552 is used to filter multiple destination IPs and retain non-enterprise public network IPs among the multiple destination IPs; the filtered destination IPs are compared with each malicious IP in the threat intelligence system, and if the destination IP is the same as any malicious IP and the reputation score of any malicious IP is greater than a first threshold, the destination IP is determined to be a malicious destination IP.

[0137] In some possible implementations, the malicious address in the threat intelligence system includes at least one malicious domain name; the malicious external link location module 1552 is used to filter multiple destination domain names and retain non-enterprise public network domain names among the multiple destination domain names; the filtered destination domain name is compared with each malicious domain name in the threat intelligence system, and if the destination domain name is the same as any malicious domain name and the reputation score of the domain name associated with the malicious domain name is greater than a second threshold, the destination domain name is determined to be a malicious destination domain name.

[0138] In some possible implementations, the device further includes: a threat intelligence generation module for aggregating threat intelligence data generated by the protection systems of multiple servers on the host; formatting the threat intelligence data to generate a threat intelligence table; the threat intelligence table includes IP-related information in a first format and domain-related information in a second format; the IP-related information includes at least a malicious IP, the IP reputation score corresponding to the malicious IP, and a first threat type label; the domain-related information includes at least a malicious domain, the domain reputation score corresponding to the malicious domain, and a second threat type label; and caching the threat intelligence table to the threat intelligence system.

[0139] In some possible implementations, the device further includes: a domain name management table generation module, used to obtain domain name information bound to multiple servers of the host in the log collection system, wherein the domain name in the domain name information points to the IP addresses of multiple servers; parse the domain name information to determine the IP address pointed to by the domain name in the domain name information; associate and save the domain name, the IP address pointed to by the domain name, and the administrator ID of the managed domain name to generate a domain name management table.

[0140] This application provides a computer program product or computer program that includes computer instructions stored in a computer storage medium. A processor of a computer device reads the computer instructions from the computer storage medium and executes the computer instructions, causing the computer device to perform the malicious external connection event detection method for a host described in this application.

[0141] This application provides a computer storage medium storing executable instructions. When these executable instructions are executed by a processor, they cause the processor to execute the malicious external connection event detection method for a host provided in this application, for example... Figure 2 The method for detecting malicious external connection events on the host is shown.

[0142] In some embodiments, the computer storage medium may be a memory such as FRAM, ROM, PROM, EEPROM, EEPROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or it may be a variety of devices including one or any combination of the above-mentioned memories.

[0143] In some embodiments, executable instructions may take the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0144] As an example, executable instructions may, but do not necessarily, correspond to files in a file system. They may be stored as part of a file that holds other programs or data, for example, in one or more scripts in a Hypertext Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple collaborating files (e.g., a file that stores one or more modules, subroutines, or code sections).

[0145] As an example, executable instructions can be deployed to execute on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network.

[0146] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.

Claims

1. A method for detecting malicious external connection events on a host, characterized in that, include: Collect multiple destination address information from the host's server logs; The destination address information includes the destination Internet Protocol IP address and / or the destination domain name; The destination IP is used to indicate the IP address requested for access by multiple servers on the host; The destination domain name is used to indicate the URL that multiple servers of the host are requesting to access; The server logs are generated by a log generation system deployed on the host. Determine malicious destination address information from the plurality of destination address information; The malicious destination address information refers to the destination address information that successfully matches a malicious address in the threat intelligence system; Based on the malicious destination address information, determine the target of the alert; Output malicious external connection event alarm information to the alarm target.

2. The method according to claim 1, characterized in that, The server logs include host intrusion detection logs and / or domain name resolution logs; the host intrusion detection logs are used to record the behavior of multiple servers of the host requesting access to the network through IP addresses; The domain name resolution log is used to record the behavior of multiple servers of the host accessing the network through domain names; The process of collecting multiple destination address information from the host's server logs includes: The destination IP is collected from the host intrusion detection log; the host intrusion detection log includes at least the destination IP and the source IP corresponding to the destination IP; the source IP is the IP address of the server on the host that requested access to the destination IP; and / or The destination domain name is collected from the domain name resolution log; the domain name resolution log includes at least the destination domain name and the client IP corresponding to the destination domain name; the client IP is the IP address of the client used by the user when initiating the domain name resolution request through the host.

3. The method according to claim 2, characterized in that, When the destination address information is the destination IP, the malicious destination address information is the malicious destination IP, and the alarm object is the administrator identifier ID corresponding to the server in the host that requested access to the malicious destination IP; When the destination address information is the destination domain name, the malicious destination address information is the malicious destination domain name, and the alarm object is the user ID that requests access to the malicious destination domain name through any server of the host.

4. The method according to claim 3, characterized in that, When the alarm target is the administrator ID corresponding to the server requesting access to the malicious target IP on the host, determining the alarm target based on the malicious target address information includes: Based on the malicious target IP, determine the victim source IP corresponding to the malicious target IP in the host intrusion detection log; Based on the victim's IP address, an alarm object corresponding to the victim's IP address is determined in the domain name management table; the domain name management table is used to associate and store domain names, the IP addresses pointed to by the domain names, and the administrator IDs of the domain names.

5. The method according to claim 3, characterized in that, The server logs include access authentication logs; the access authentication logs include at least an authentication IP and a user ID associated with the authentication IP; the authentication IP is the IP address assigned by the server in the host to the client used by the user when the user requests network access; When the alarm target is a user ID that requests access to the malicious target domain name through any server of the host, determining the alarm target based on the malicious target address information includes: Based on the malicious target domain name, determine the victim client IP corresponding to the malicious target domain name in the domain name resolution log; Based on the victim client IP, identify the same victim authentication IP in the access authentication log; Based on the victim authentication IP, the alarm object associated with the victim authentication IP is determined in the access authentication log.

6. The method according to claim 3, characterized in that, The malicious addresses in the threat intelligence system include at least one malicious IP address; The step of determining malicious destination address information from the plurality of destination address information includes: Filter the multiple destination IPs and retain the non-enterprise public IPs among them; The filtered target IP is compared with each malicious IP in the threat intelligence system. If the target IP is the same as any malicious IP and the reputation score of the IP associated with any malicious IP is greater than a first threshold, the target IP is determined to be a malicious target IP.

7. The method according to claim 3, characterized in that, The malicious addresses in the threat intelligence system include at least one malicious domain name; The step of determining malicious destination address information from the plurality of destination address information includes: Filter the multiple destination domains and retain non-enterprise public domains among them; The filtered destination domain name is compared with each malicious domain name in the threat intelligence system. If the destination domain name is the same as any malicious domain name and the reputation score of the domain name associated with the malicious domain name is greater than the second threshold, the destination domain name is determined to be the malicious destination domain name.

8. The method according to claim 1, characterized in that, The method further includes: The threat intelligence data generated by the protection systems of multiple servers on the host is aggregated. The threat intelligence data is formatted to generate a threat intelligence table; the threat intelligence table includes IP-related information in a first format and domain-related information in a second format; the IP-related information includes at least a malicious IP, the IP reputation score corresponding to the malicious IP, and a first threat type label; the domain-related information includes at least a malicious domain, the domain reputation score corresponding to the malicious domain, and a second threat type label; The threat intelligence table is cached in the threat intelligence system.

9. The method according to claim 4, characterized in that, The method further includes: The log collection system obtains the domain name information bound to multiple servers of the host; the domain names in the domain name information point to the IP addresses of the multiple servers; Parse the domain name information to determine the IP address that the domain name in the domain name information points to; The domain name, the IP address pointed to by the domain name, and the administrator ID managing the domain name are associated and saved to generate the domain name management table.

10. A malicious external connection event detection device for a host, characterized in that, include: The data acquisition module is used to collect multiple destination address information from the host's server logs; The destination address information includes the destination Internet Protocol IP address and / or the destination domain name; The destination IP is used to indicate the IP address of multiple server requests from the host; The destination domain name is used to indicate the URL that multiple servers of the host are requesting to access; The server logs are generated by a log generation system deployed on the host. A malicious external connection location module is used to determine malicious destination address information from the multiple destination address information; The malicious destination address information refers to the destination address information that successfully matches a malicious address in the threat intelligence system; The malicious external connection tracing module is used to determine the alarm target based on the malicious destination address information; The alarm module is used to output alarm information about malicious external connection events to the alarm object.