Network intrusion event detection method, related equipment and storage medium

By acquiring and analyzing log data from different channels, automatic detection of network intrusion events was achieved, solving the problem of low detection efficiency in existing technologies, improving the accuracy and timeliness of detection, and reducing the risk of data leakage.

CN121125337APending Publication Date: 2025-12-12CHINA TOWER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511579564.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-31
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In existing technologies, cloud platforms have low efficiency in detecting network intrusion events and are prone to data leakage. Manual detection by administrators is also inefficient and cannot detect network intrusions in a timely manner, resulting in economic losses.

Method used

The system acquires first and second log data from the target platform through different channels, performs normalization processing and analysis, generates alert messages to indicate network intrusion events, and achieves automatic detection.

Benefits of technology

It improves the accuracy and efficiency of network intrusion detection, reduces the risk of data leakage, and enables administrators to respond to network intrusion incidents in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125337A_ABST
    Figure CN121125337A_ABST
Patent Text Reader

Abstract

The invention provides a network intrusion event detection method, related equipment and a storage medium, and the method comprises the steps: obtaining first log data of a target platform through a first channel, and obtaining second log data of the target platform through a second channel; performing normalization processing on the first log data and the second log data to obtain normalized log data; analyzing the normalized log data to obtain an analysis result of the normalized log data; if the analysis result indicates that the target platform has the network intrusion event, generating prompt information based on the network intrusion event; and sending prompt information to the management equipment. By adopting the method provided by the invention, the network intrusion event existing in the target platform can be automatically detected by utilizing the log data of the target platform, and the accuracy and efficiency of network intrusion detection are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technology, and in particular to a method, related equipment and storage medium for detecting network intrusion incidents. Background Technology

[0002] With the development of internet technology, network information technology has advanced rapidly, and the threat to data security has become increasingly severe. Currently, most systems store data by uploading information to cloud platforms for centralized storage. While this method is convenient, cloud platforms may have vulnerabilities or security flaws. In the event of a network intrusion, it could lead to system crashes and large-scale data leaks. Currently, administrators only manually inspect the platform's data after system crashes or large-scale data leaks have occurred. By the time a network intrusion is discovered, significant data breaches or economic losses have often already occurred. Furthermore, manual inspection by administrators is inefficient when dealing with large amounts of log data. Summary of the Invention

[0003] This application provides a method, related equipment, and storage medium for detecting network intrusion events. It can automatically detect network intrusion events existing on the target platform using log data of the target platform, effectively improving the accuracy and efficiency of network intrusion detection.

[0004] On one hand, embodiments of this application provide a method for detecting network intrusion events, wherein the method includes: First log data of the target platform is obtained through a first channel, and second log data of the target platform is obtained through a second channel; the first channel and the second channel are different. The first log data and the second log data are normalized to obtain normalized log data; The normalized log data is analyzed to obtain the analysis results of the normalized log data; If the analysis results indicate that a network intrusion event has occurred on the target platform, then a prompt message is generated based on the network intrusion event; the prompt message is used to indicate the network intrusion event. Send the aforementioned prompt message to the management device.

[0005] On the other hand, embodiments of this application provide a detection device, wherein the device includes: The acquisition unit is configured to acquire first log data of the target platform through a first channel, and to acquire second log data of the target platform through a second channel; the first channel and the second channel are different. The processing unit is used to normalize the first log data and the second log data to obtain normalized log data. The processing unit is also used to analyze the normalized log data to obtain the analysis results of the normalized log data; The generation unit is configured to generate a prompt message based on the network intrusion event if the analysis result indicates that the target platform has a network intrusion event; the prompt message is used to indicate the network intrusion event. The sending unit is used to send the prompt information to the management device.

[0006] In one possible implementation, when the acquisition unit acquires the first log data of the target platform through the first channel, it is specifically used to: acquire the first log data within a first time period from the log database of the target platform; when the acquisition unit acquires the second log data of the target platform through the second channel, it is specifically used to: acquire network traffic data within the first time period in the target platform; perform mirroring processing on the network traffic data to obtain mirrored network traffic data; and perform log auditing based on the mirrored network traffic data to obtain the second log data.

[0007] In one possible implementation, the normalization process includes parsing and integration. When the processing unit performs normalization processing on the first log data and the second log data to obtain normalized log data, it specifically performs the following: parsing processing on the first log data and the second log data to obtain first parsed data and second parsed data; the parsing processing includes formatting, data mapping, and data enhancement; and integrating processing on the first parsed data and the second parsed data to obtain normalized log data.

[0008] In one possible implementation, when the processing unit analyzes the normalized log data to obtain the analysis result, it specifically performs the following steps: extracting features from the normalized log data to obtain data features of the normalized log data; performing correlation analysis between network intrusion features and the data features of the normalized log data to obtain the correlation degree between the network intrusion features and the data features of the normalized log data; the network intrusion features are obtained by extracting features from normalized log data including network intrusion events; and determining the analysis result of the normalized log data based on the correlation degree between the network intrusion features and the data features of the normalized log data.

[0009] In one possible implementation, when the processing unit determines the analysis result of the normalized log data based on the correlation between the network intrusion features and the data features of the normalized log data, it specifically performs the following: if the correlation between the network intrusion features and the data features of the normalized log data is greater than or equal to a set threshold, then the analysis result of the normalized log data is determined as a first analysis result; the first analysis result is used to indicate that a network intrusion event exists on the target platform; if the correlation between the network intrusion features and the data features of the normalized log data is less than the set threshold, then the analysis result of the normalized log data is determined as a second analysis result; the second analysis result is used to indicate that no network intrusion event exists on the target platform.

[0010] In one possible implementation, if the analysis result indicates that a network intrusion event exists on the target platform, the generation unit generates a prompt message based on the network intrusion event, specifically by: when determining that the analysis result of the normalized log data is the first analysis result, obtaining the network intrusion type of the network intrusion event; and generating a prompt message corresponding to the intrusion type of the network intrusion event based on the network intrusion type.

[0011] In one possible implementation, the processing unit is further configured to perform aggregate statistics on the normalized log data to obtain aggregate features of the normalized log data; identify the aggregate features of the normalized log data based on the benchmark aggregate features to obtain an identification result; the benchmark aggregate features are obtained by aggregating and statistically analyzing benchmark log data within a second time period, and the benchmark log data does not include network intrusion data; and determine the analysis result of the normalized log data based on the identification result.

[0012] In one possible implementation, when the processing unit determines the analysis result of the normalized log data based on the identification result, it is specifically configured to: if the identification result indicates that the aggregation characteristics of the normalized log data are abnormal, then determine the analysis result of the normalized log data as a first analysis result; the first analysis result is used to indicate that the target platform has a network intrusion event; if the identification result indicates that the aggregation characteristics of the normalized log data are normal, then determine the analysis result of the normalized log data as a second analysis result; the second analysis result is used to indicate that the target platform does not have a network intrusion event.

[0013] Accordingly, embodiments of this application provide a computer device, wherein the computer device includes: A processor is a tool for implementing computer programs. A computer-readable storage medium storing a computer program adapted to be loaded by a processor and executed by the aforementioned method for detecting network intrusion events.

[0014] Accordingly, embodiments of this application also provide a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program adapted to be loaded by a processor and to implement the network intrusion event detection method provided in embodiments of this application.

[0015] Accordingly, this application also provides a computer program product, wherein the computer program product includes a computer program or computer instructions, and when the computer program or computer instructions are executed by a processor, the network intrusion event detection method provided in this application is implemented.

[0016] In this embodiment, the detection device can acquire first log data of the target platform through a first channel and second log data of the target platform through a second channel; normalize the first and second log data to obtain normalized log data; analyze the normalized log data to obtain analysis results; if the analysis results indicate that a network intrusion event exists on the target platform, generate a prompt message based on the network intrusion event and send the alarm message to the management device; the management device can output the alarm message, and relevant management personnel can obtain the alarm message through the management device. The first and second channels are different channels; the prompt message is used to indicate a network intrusion event. The first and second log data of the target platform can be normalized to obtain normalized log data, and the normalized log data can be analyzed to obtain analysis results; based on the analysis results, it is determined whether a network intrusion event exists on the target platform. When it is determined through the analysis results that a network intrusion event exists on the target platform, a prompt message is generated based on the network intrusion event and sent to the management device. The management device can output the prompt message, and relevant management personnel can manage the network intrusion event based on the prompt message. The method provided in this application embodiment enables automatic detection of network intrusion events on the target platform using log data, effectively improving the accuracy and efficiency of network intrusion detection. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without any creative effort.

[0018] Figure 1This is a schematic diagram of the structure of a network intrusion event alerting system provided in an embodiment of this application; Figure 2 This is a flowchart illustrating a method for detecting network intrusion events provided in an embodiment of this application; Figure 3 This is a flowchart illustrating another method for detecting network intrusion events provided in an embodiment of this application; Figure 4 This is a flowchart illustrating another method for detecting network intrusion events provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of a detection device provided in an embodiment of this application; Figure 6 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0019] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0020] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, components, features, and elements with the same names in different embodiments of this application may have the same meaning or different meanings, the specific meaning of which must be determined by its interpretation in that specific embodiment or further in conjunction with the context of that specific embodiment.

[0021] It should be understood that although the terms first, second, third, etc., may be used herein to describe various information, such information should not be limited to these terms. These terms are used only to distinguish information of the same type from one another. For example, without departing from the scope of this document, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if," as used herein, may be interpreted as "when," "when," or "in response to determination." Furthermore, as used herein, the singular forms "a," "an," and "the" are intended to also include the plural forms unless the context indicates otherwise. It should be further understood that the terms "comprising," "including," indicate the presence of the stated feature, step, operation, element, component, item, kind, and / or group, but do not exclude the presence, occurrence, or addition of one or more other features, steps, operations, elements, components, items, kinds, and / or groups. The terms "or," "and / or," "including at least one of the following," etc., as used in this application, may be interpreted as inclusive, or mean any one or any combination thereof. For example, "including at least one of the following: A, B, C" means "any one of the following: A; B; C; A and B; A and C; B and C; A and B and C." Similarly, "A, B, or C" or "A, B, and / or C" means "any one of the following: A; B; C; A and B; A and C; B and C; A and B and C." Exceptions to this definition only occur when the combination of elements, functions, steps, or operations is inherently mutually exclusive in some way.

[0022] It should be understood that although the steps in the flowcharts of this application's embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least a portion of the sub-steps or stages of other steps.

[0023] Depending on the context, the words “if” or “suppose” as used here can be interpreted as “when” or “in response to determination” or “in response to detection.” Similarly, depending on the context, the phrases “if determination” or “if detection (of the stated condition or event)” can be interpreted as “when determination” or “in response to determination” or “when detection (of the stated condition or event)” or “in response to detection (of the stated condition or event).”

[0024] The following describes a system provided by an embodiment of this application.

[0025] Please see Figure 1 , Figure 1 This is a schematic diagram of the structure of a network intrusion event alerting system provided in an embodiment of this application. For example... Figure 1 As shown, the network intrusion event alert system includes a detection device 101, a target platform 102, and a management device 103. Among them, the detection device 101 can be a terminal device or a server. The terminal device can include desktop computers, tablets, handheld computers, laptops, mobile internet devices (MIDs), etc. The server can include a single physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. The target platform 102 can be a terminal device or a server. The terminal device can include desktop computers, tablets, handheld computers, laptops, mobile internet devices, etc. The server can include a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence platforms. The management device 103 can include smartphones (such as Android phones, iOS phones, Windows Phones, etc.), desktop computers, tablets, handheld computers, laptops, mobile internet devices, or wearable devices, etc.

[0026] In this embodiment, the detection device 101 can acquire first log data of the target platform 102 through a first channel and second log data of the target platform 102 through a second channel; normalize the first and second log data to obtain normalized log data; analyze the normalized log data to obtain the analysis result; if the analysis result indicates that a network intrusion event has occurred on the target platform, generate a prompt message based on the network intrusion event and send the alarm message to the management device 103; the management device 103 can output the alarm message, and relevant management personnel can obtain the alarm message through the management device 103. The first and second channels are different channels; the prompt message is used to indicate a network intrusion event. The first and second log data of the target platform can be normalized to obtain normalized log data. This normalized log data can then be analyzed to obtain analysis results. Based on the analysis results, it can be determined whether a network intrusion event exists on the target platform. When a network intrusion event is confirmed, a prompt message is generated and sent to the management device. The management device can output this prompt message, allowing relevant administrators to manage the network intrusion event accordingly. Using the method provided in this application embodiment, automatic detection of network intrusion events on the target platform is achieved using the platform's log data, effectively improving the accuracy and efficiency of network intrusion detection.

[0027] It is understood that the structural diagrams of the network intrusion event notification system described in the embodiments of this application are for the purpose of more clearly illustrating the network intrusion event detection method of the embodiments of this application, and do not constitute a limitation on the network intrusion event detection method provided in the embodiments of this application. For example, the network intrusion event detection method provided in the embodiments of this application can be executed not only by the detection device, but also by other devices different from the detection device. Those skilled in the art will understand that... Figure 1 The number of detection devices 101, target platforms 102, and management devices 103 shown in the embodiments is merely illustrative. Any number of detection devices, target platforms, and management devices can be configured according to business implementation needs. Furthermore, as system architecture evolves and new business scenarios emerge, the network intrusion event detection method provided in this application embodiment is also applicable to similar technical problems.

[0028] The following describes a method for detecting network intrusion events provided by an embodiment of this application.

[0029] Please see Figure 2 , Figure 2This is a flowchart illustrating a method for detecting network intrusion events provided in an embodiment of this application. The method for detecting network intrusion events provided in this application can be applied to the above-mentioned... Figure 1 The network intrusion event alerting system shown below will be illustrated using an example of applying the network intrusion event detection method to the detection equipment within this system. For example... Figure 2 As shown, the detection method for this network intrusion event includes: S201. Obtain the first log data of the target platform through the first channel, and obtain the second log data of the target platform through the second channel.

[0030] In one embodiment, the first channel and the second channel are different channels, and log data of the target platform can be obtained using different acquisition methods based on different data sources. The different data sources may be due to differences in system architecture, storage devices, and the principles of the storage technologies used. The acquisition method of log data may be determined based on the data source. The target platform may be a platform with confidentiality requirements for data. Log data may include device abnormal data, network access data, 4A log data, terminal log data, etc. Device abnormal data may be abnormal behavior of user devices when obtaining data from the target platform (e.g., network fluctuations, device failures, etc.). Network access data may be access records generated by each user when accessing data. 4A may include Account, Authentication, Authorization, and Audit. Terminal log data may include application logs (recording events that occur during application runtime), security logs (recording security-related events, such as user login, permission changes, etc.), system logs (recording events that occur during system runtime, such as device driver installation, system startup, etc.), and performance logs (recording system performance data, such as CPU usage, memory usage, etc.). When the target platform needs to detect network intrusion events, the detection device can obtain the first log data of the target platform through the first channel and the second log data of the target platform through the second channel.

[0031] The target platform needs to be detected for network intrusion events. This can be achieved by the target platform sending a detection command to the detection device, which instructs the device to perform network intrusion detection on the target platform; or by the detection device periodically detecting the target platform at set time intervals. The set time interval can be a fixed value (e.g., 1 minute) or a custom time interval based on actual conditions. For example, when the target platform's activity is high, the time interval can be set shorter (e.g., 10 seconds); when the target platform's activity is low, the time interval can be set longer (e.g., 2 minutes). The target platform's activity level can be determined based on information such as the platform's data access volume and the number of users accessing it. This ensures the detection is reasonable, effectively reducing the probability of network intrusion events on the target platform, thereby improving data security.

[0032] In another embodiment, the first channel may include obtaining first log data from a log database. Obtaining first log data of the target platform through the first channel may include: obtaining first log data within a first time period from the target platform's log database. The second channel may include obtaining data from the target platform's network traffic data. Network traffic data can be data obtained from network traffic. Network traffic refers to the amount of data transmitted in a computer network, typically the number or size of data packets passing through the network within a certain period. It can be an indicator used to measure network usage and load. Obtaining second log data of the target platform through the second channel may include: obtaining network traffic data within the first time period on the target platform; mirroring the network traffic data to obtain mirrored network traffic data; and performing log auditing based on the mirrored network traffic data to obtain second log data.

[0033] Methods for mirroring network traffic data to obtain mirrored network traffic data may include: copying the network traffic of the target platform to a cloud server, and extracting the network traffic data from the network traffic in the cloud server to obtain mirrored network traffic data. This method can obtain mirrored network traffic data without affecting the performance of the target platform, effectively improving the efficiency of obtaining mirrored network traffic data, thereby improving the detection efficiency of the detection equipment.

[0034] S202. Normalize the first log data and the second log data to obtain normalized log data.

[0035] The data formats and / or content of the first log data and the second log data may be different. The first log data and the second log data can be normalized to obtain normalized log data.

[0036] In one embodiment, normalization processing may include format conversion (converting the data formats of the first and second log data to the same format), deduplication, and noise removal on the first and second log data, followed by combining the first and second log data to obtain normalized log data. The detection device can utilize normalization processing to process the first and second log data to obtain normalized log data; this enables the determination of normalized log data from the first and second log data, effectively improving the accuracy of the normalized log data.

[0037] In another embodiment, the normalization process may include parsing; normalizing the first log data and the second log data to obtain normalized log data includes: the detection device may parse the first log data to obtain first parsed data; and parse the second log data to obtain second parsed data.

[0038] The aforementioned parsing process can include formatting, data mapping, and data augmentation. Parsing the first log data can include: formatting the first log data, and then processing the formatted first log data through data mapping and data augmentation to obtain first parsed data. Parsing the second log data can also include: formatting the second log data, and then processing the formatted second log data through data mapping and data augmentation to obtain second parsed data. Normalization processing can include integration processing; the detection device can integrate the first and second parsed data to obtain normalized log data, effectively improving the efficiency of obtaining normalized log data.

[0039] S203. Analyze the normalized log data to obtain the analysis results of the normalized log data.

[0040] The analysis results are used to indicate whether a network intrusion incident has occurred on the target platform. Network intrusion incidents can include intrusion detection systems, software intrusions (e.g., using social media, hacking websites, etc. to obtain users' personal information), phishing intrusions (posing as legitimate organizations to obtain users' personal information), and zero-day exploits (using software and vulnerabilities to intrude into systems).

[0041] In one embodiment, the analysis can be achieved using various techniques such as aggregate statistical analysis, correlation analysis, anomaly detection, and machine learning; the detection device can analyze the normalized log data of the target platform to obtain the analysis results of the normalized log data.

[0042] In another embodiment, when the analysis method is correlation analysis, the analysis of normalized log data to obtain the analysis results can include: the detection device can extract features from the normalized log data to obtain data features of the normalized log data; correlation analysis is performed between network intrusion features and the data features of the normalized log data to obtain the correlation degree between the network intrusion features and the data features of the normalized log data; the network intrusion features are obtained by extracting features from normalized log data including network intrusion events; and the analysis results of the normalized log data are determined based on the correlation degree between the network intrusion features and the data features of the normalized log data. Correlation analysis can include field value matching, threshold comparison, time-series pattern matching, and correlation analysis between multiple log sources (such as network log terminal correlation, traffic log and device prompt log correlation), etc. In this embodiment, feature extraction can be performed on the log data, and correlation analysis can be performed between the feature data and the network intrusion features to accurately determine whether there are network intrusion events in the log data, effectively improving the efficiency and accuracy of the analysis, thereby improving data security.

[0043] In another embodiment, when the correlation analysis is a threshold comparison, the analysis result of the normalized log data is determined based on the correlation between the network intrusion features and the data features of the normalized log data. This can include: if the correlation between the network intrusion features and the data features of the normalized log data is greater than or equal to a set threshold, then the analysis result of the normalized log data is determined as a first analysis result; the first analysis result is used to indicate that a network intrusion event exists on the target platform; if the correlation between the network intrusion features and the data features of the normalized log data is less than the set threshold, then the analysis result of the normalized log data is determined as a second analysis result; the second analysis result is used to indicate that no network intrusion event exists on the target platform.

[0044] In another embodiment, when the correlation analysis is a field value matching, the detection device can first determine the field value of the network intrusion event, and then use the field value of the network intrusion event to perform field value matching on the normalized log data to obtain a matching result. If the field value of the network intrusion event exists in the normalized log data, the matching result can be determined as the first analysis result; if the field value of the network intrusion event does not exist in the normalized log data, the matching result can be determined as the second analysis result, which effectively improves the accuracy of the analysis results.

[0045] In another embodiment, when the analysis method is aggregate statistical analysis, the detection device can perform aggregate statistics on normalized log data to obtain aggregate features of the normalized log data; identify the aggregate features of the normalized log data based on the benchmark aggregate features to obtain identification results; and determine the analysis results of the normalized log data based on the identification results. The benchmark aggregate features are obtained by aggregating statistics on benchmark log data, which does not include network intrusion data; the benchmark log data can be clustered and grouped to obtain data in different dimensions (such as source and destination IPs, usernames, etc., fields representing users or entities). Statistical methods such as frequency statistics, normal 3-Sigma, quartiles, and unsupervised clustering in machine learning are used to calculate the features of each user or entity in a certain object dimension, and these features are used as benchmark aggregate features; then the aggregate features of the normalized log data are compared with the benchmark aggregate features. If abnormal data is found in the normalized log data, it can be determined that there is a network intrusion event on the target platform, effectively improving the efficiency and accuracy of detection.

[0046] It should be noted that the above-mentioned field value matching, aggregation statistical analysis and other analysis methods can be used simultaneously on the same normalized log data. The embodiments of this application do not limit the type of analysis method.

[0047] In another embodiment, the detection device determines the analysis result of the normalized log data based on the identification result, which may include: if the aggregation characteristics of the normalized log data are determined to be abnormal based on the identification result, the detection device may determine the analysis result of the normalized log data as a first analysis result; the first analysis result is used to indicate that there is a network intrusion event on the target platform; if the aggregation characteristics of the normalized log data are determined to be normal based on the identification result, the detection device may determine the analysis result of the normalized log data as a second analysis result; the second analysis result is used to indicate that there is no network intrusion event on the target platform.

[0048] S204. If the analysis results indicate that there is a network intrusion event on the target platform, then generate a prompt message based on the network intrusion event.

[0049] This notification message can be used to indicate a network intrusion incident.

[0050] In one embodiment, if it is determined from normalized log data that a network intrusion event exists on the target platform, the detection device can generate a prompt message based on the network intrusion event on the target platform. The prompt message may include the content of the network intrusion event.

[0051] In another embodiment, the prompt information can also be used to indicate the type of network intrusion event. When the detection device determines that the analysis result of the normalized log data is the first analysis result, it obtains the network intrusion type of the network intrusion event; based on the network intrusion type, it generates prompt information corresponding to the intrusion type of the network intrusion event. The network intrusion type may include cross-site scripting (XSS) type, man-in-the-middle intrusion type, etc.; when determining the network intrusion type of the network intrusion event, corresponding prompt information can be generated based on the network intrusion type, and this prompt information may include the content of the network intrusion event. Administrators can promptly perform corresponding management operations based on the network intrusion type, effectively improving management efficiency and thus enhancing data security.

[0052] S205. Send a notification message to the management device.

[0053] In one embodiment, the management device is a device used by the administrators of the target platform; when the detection device determines that there is a network intrusion event on the target platform based on normalized log data, it can generate a prompt message and send the prompt message to the management device.

[0054] In another embodiment, the management device receives a prompt message and can output the prompt message. When the administrator confirms that a network intrusion event has occurred on the target platform based on the prompt message, the administrator can manage the target platform according to the network intrusion event and / or network intrusion type in the prompt message. This allows for timely management of the network intrusion event before it is sent or in its early stages, preventing data leakage and effectively improving data security.

[0055] In another embodiment, please refer to Figure 3 , Figure 3 This is a flowchart illustrating another method for detecting network intrusion events provided in an embodiment of this application. Figure 3 As shown, the method for detecting this network intrusion event may include: Initially, the detection device collects first log data from the target platform; the detection device uses mirroring technology to obtain mirrored network traffic data from the network traffic, and examines and statistically analyzes the second log data in the network traffic to obtain second log data; the detection device normalizes the first log data and the second log data, and analyzes them to obtain analysis results; based on the analysis results, it is determined whether a network intrusion event exists on the target platform; if not, the corresponding steps in this flowchart are executed repeatedly; if yes, a prompt message is generated, and the process ends. It should be noted that the specific implementation of this embodiment can be referred to the relevant descriptions of steps S201-S205 in the aforementioned embodiments, and will not be repeated here.

[0056] In another embodiment, when the target platform has no initial log data, only network traffic data can be detected to determine whether the target platform is engaging in abnormal access behavior beyond its authorized permissions. Please refer to [link to relevant documentation]. Figure 4 , Figure 4 This is a flowchart illustrating another method for detecting network intrusion events provided in an embodiment of this application. Figure 4 As shown, the method for detecting this network intrusion event may include: starting by using mirroring technology to obtain network traffic of the target platform; detecting the network traffic accessing data; determining whether a network intrusion event exists on the target platform; if not, repeatedly executing the corresponding steps in this flowchart; if yes, generating a prompt message and ending the process.

[0057] When detecting network traffic data, artificial intelligence (AI) detection models can be used. These models can be trained using sample data containing network intrusion events. The development language (e.g., Java, Python) for these AI detection models can be determined according to specific circumstances. The AI ​​detection module allows developers to customize data source operators, preprocessing, and detection modes, moving beyond traditional data processing workflows and detection patterns. It integrates necessary machine learning and deep learning models or operators as needed, satisfying various detection scenarios such as real-time network traffic data processing and offline batch processing. This achieves automated detection of network traffic data, effectively improving data security.

[0058] In summary, the beneficial effects of this application's embodiments are as follows: the detection device can acquire first log data of the target platform through a first channel and second log data of the target platform through a second channel; the first and second log data are normalized to obtain normalized log data; the normalized log data is analyzed to obtain analysis results; if the analysis results indicate a network intrusion event on the target platform, a prompt message is generated based on the network intrusion event, and the alarm message is sent to the management device; the management device can output the alarm message, and relevant management personnel can obtain the alarm message through the management device. The first and second channels are different channels; the prompt message is used to indicate a network intrusion event. The first and second log data of the target platform can be normalized to obtain normalized log data. This normalized log data can then be analyzed to obtain analysis results. Based on the analysis results, it can be determined whether a network intrusion event exists on the target platform. When a network intrusion event is confirmed, a prompt message is generated and sent to the management device. The management device can output this prompt message, allowing relevant administrators to manage the network intrusion event accordingly. Using the method provided in this application embodiment, automatic detection of network intrusion events on the target platform is achieved using the platform's log data, effectively improving the accuracy and efficiency of network intrusion detection.

[0059] The following describes a detection device provided by an embodiment of this application.

[0060] Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of a detection device provided in an embodiment of this application. Figure 5 As shown, the detection device includes: The acquisition unit 501 is used to acquire first log data of the target platform through a first channel, and to acquire second log data of the target platform through a second channel; the first channel and the second channel are different. Processing unit 502 is used to normalize the first log data and the second log data to obtain normalized log data; The processing unit 502 is also used to analyze the normalized log data to obtain the analysis results of the normalized log data; The generation unit 503 is configured to generate a prompt message based on the network intrusion event if the analysis result indicates that the target platform has a network intrusion event; the prompt message is used to indicate the network intrusion event. The sending unit 504 is used to send the prompt information to the management device.

[0061] In one possible implementation, when the acquisition unit 501 acquires the first log data of the target platform through the first channel, it is specifically used to: acquire the first log data within a first time period from the log database of the target platform; when the acquisition unit 501 acquires the second log data of the target platform through the second channel, it is specifically used to: acquire network traffic data within the first time period in the target platform; perform mirroring processing on the network traffic data to obtain mirrored network traffic data; and perform log auditing based on the mirrored network traffic data to obtain the second log data.

[0062] In one possible implementation, the normalization process includes parsing and integration processing; when the processing unit 502 performs normalization processing on the first log data and the second log data to obtain normalized log data, it is specifically used to: perform parsing processing on the first log data and the second log data to obtain first parsed data and second parsed data; the parsing processing includes formatting processing, data mapping, and data enhancement; and perform integration processing on the first parsed data and the second parsed data to obtain normalized log data.

[0063] In one possible implementation, when the processing unit 502 analyzes the normalized log data to obtain the analysis result, it specifically performs the following steps: extracting features from the normalized log data to obtain data features of the normalized log data; performing correlation analysis between network intrusion features and the data features of the normalized log data to obtain the correlation degree between the network intrusion features and the data features of the normalized log data; the network intrusion features are obtained by extracting features from normalized log data including network intrusion events; and determining the analysis result of the normalized log data based on the correlation degree between the network intrusion features and the data features of the normalized log data.

[0064] In one possible implementation, when the processing unit 502 determines the analysis result of the normalized log data based on the correlation between the network intrusion features and the data features of the normalized log data, it specifically performs the following: if the correlation between the network intrusion features and the data features of the normalized log data is greater than or equal to a set threshold, then the analysis result of the normalized log data is determined as a first analysis result; the first analysis result is used to indicate that a network intrusion event exists on the target platform; if the correlation between the network intrusion features and the data features of the normalized log data is less than the set threshold, then the analysis result of the normalized log data is determined as a second analysis result; the second analysis result is used to indicate that no network intrusion event exists on the target platform.

[0065] In one possible implementation, if the analysis result indicates that a network intrusion event exists on the target platform, the generation unit 503, when generating a prompt message based on the network intrusion event, specifically performs the following: when determining that the analysis result of the normalized log data is the first analysis result, it obtains the network intrusion type of the network intrusion event; and generates a prompt message corresponding to the intrusion type of the network intrusion event based on the network intrusion type.

[0066] In one possible implementation, the processing unit 502 is further configured to: perform aggregate statistics on the normalized log data to obtain aggregate features of the normalized log data; identify the aggregate features of the normalized log data based on the benchmark aggregate features to obtain an identification result; the benchmark aggregate features are obtained by aggregating and statistically analyzing benchmark log data within a second time period, and the benchmark log data does not include network intrusion data; and determine the analysis result of the normalized log data based on the identification result.

[0067] In one possible implementation, when the processing unit 502 determines the analysis result of the normalized log data based on the identification result, it is specifically configured to: if the identification result indicates that the aggregation characteristics of the normalized log data are abnormal, then determine the analysis result of the normalized log data as a first analysis result; the first analysis result is used to indicate that the target platform has a network intrusion event; if the identification result indicates that the aggregation characteristics of the normalized log data are normal, then determine the analysis result of the normalized log data as a second analysis result; the second analysis result is used to indicate that the target platform does not have a network intrusion event.

[0068] Based on the above detection device, it is possible to automatically detect network intrusion events on the target platform using the target platform's log data, thereby reducing the occurrence of network intrusion events and effectively improving the data security of the target platform.

[0069] It should be noted that the functions of each unit of the detection device in the embodiments of this application can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can be referred to the relevant descriptions in the various method embodiments of this application, which will not be repeated here.

[0070] According to another embodiment of this application, Figure 5The various units in the detection device shown can be individually or entirely combined into one or more other units, or some of the units can be further divided into multiple functionally smaller units. This achieves the same operation without affecting the technical effects of the embodiments of this application. The above-mentioned units are based on logical function division. In practical applications, the function of one unit can also be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of this application, the detection device may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by multiple units.

[0071] According to another embodiment of this application, the following can be achieved by running on a general-purpose computing device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM), a device capable of performing operations such as... Figure 2 Computer programs for the steps involved in some or all of the methods shown, to construct, for example... Figure 5 The detection device shown herein, and the method for detecting network intrusion events in accordance with the embodiments of this application, are described. The computer program may be recorded on, for example, a computer-readable storage medium, loaded onto the aforementioned computing device via the computer-readable storage medium, and run therein.

[0072] Based on the above methods and apparatus embodiments, this application provides a computer device. Please refer to... Figure 6 This figure is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 6 The computer device shown includes at least a processor 601, an input interface 602, an output interface 603, and a computer-readable storage medium 604. The processor 601, input interface 602, output interface 603, and computer-readable storage medium 604 can be connected via a bus or other means.

[0073] Computer-readable storage medium 604 can be stored in the memory of a computer device. Computer-readable storage medium 604 is used to store computer programs, which include program instructions. Processor 601 is used to execute the computer program stored in computer-readable storage medium 604. The computer program may include multiple program instructions such as program instruction 1, program instruction 2, and program instruction n. Processor 601 (or CPU (Central Processing Unit)) is the computing and control core of the computer device; it is suitable for implementing computer programs, specifically for loading and executing computer programs to achieve the above-mentioned functions. Figure 2 The method flow is shown.

[0074] This application also provides a computer-readable storage medium (Memory), which is a memory device in a computer device used to store programs and data. It is understood that the computer-readable storage medium here can include both built-in storage media in the computer device and extended storage media supported by the computer device. The computer-readable storage medium provides storage space for storing the operating system of the computer device. Furthermore, the storage space also stores computer programs suitable for loading and execution by a processor. It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device; optionally, it can also be at least one computer-readable storage medium located remotely from the aforementioned processor.

[0075] The computer equipment can be the above. Figure 1 The detection device 101 in the network intrusion event alert system shown. Specifically, the processor 601 can load and execute the computer program stored in the computer-readable storage medium 604 to implement the corresponding steps of the network intrusion event detection method in each method embodiment of this application. Specifically, the computer program in the computer-readable storage medium 604 is loaded by the processor 601 and executed with the following steps: First log data of the target platform is obtained through a first channel, and second log data of the target platform is obtained through a second channel; the first channel and the second channel are different. The first log data and the second log data are normalized to obtain normalized log data; The normalized log data is analyzed to obtain the analysis results of the normalized log data; If the analysis results indicate that a network intrusion event has occurred on the target platform, then a prompt message is generated based on the network intrusion event; the prompt message is used to indicate the network intrusion event. Send the aforementioned prompt message to the management device.

[0076] In one possible implementation, when the processor 601 acquires the first log data of the target platform through the first channel, it is specifically used to: acquire the first log data within a first time period from the log database of the target platform; when the processor 601 acquires the second log data of the target platform through the second channel, it is specifically used to: acquire network traffic data within the first time period in the target platform; perform mirroring processing on the network traffic data to obtain mirrored network traffic data; and perform log auditing based on the mirrored network traffic data to obtain the second log data.

[0077] In one possible implementation, the normalization process includes parsing and integration processing; when the processor 601 performs normalization processing on the first log data and the second log data to obtain normalized log data, it specifically performs the following: parsing processing on the first log data and the second log data to obtain first parsed data and second parsed data; the parsing processing includes formatting processing, data mapping, and data enhancement; and integrating processing on the first parsed data and the second parsed data to obtain normalized log data.

[0078] In one possible implementation, when the processor 601 analyzes the normalized log data to obtain the analysis result, it specifically performs the following steps: extracting features from the normalized log data to obtain data features of the normalized log data; performing correlation analysis between network intrusion features and the data features of the normalized log data to obtain the correlation degree between the network intrusion features and the data features of the normalized log data; the network intrusion features are obtained by extracting features from normalized log data including network intrusion events; and determining the analysis result of the normalized log data based on the correlation degree between the network intrusion features and the data features of the normalized log data.

[0079] In one possible implementation, when the processor 601 determines the analysis result of the normalized log data based on the correlation between the network intrusion features and the data features of the normalized log data, it specifically performs the following: if the correlation between the network intrusion features and the data features of the normalized log data is greater than or equal to a set threshold, then the analysis result of the normalized log data is determined as a first analysis result; the first analysis result is used to indicate that a network intrusion event exists on the target platform; if the correlation between the network intrusion features and the data features of the normalized log data is less than the set threshold, then the analysis result of the normalized log data is determined as a second analysis result; the second analysis result is used to indicate that no network intrusion event exists on the target platform.

[0080] In one possible implementation, if the analysis result indicates that a network intrusion event exists on the target platform, the processor 601, when generating a prompt message based on the network intrusion event, specifically performs the following: when determining that the analysis result of the normalized log data is the first analysis result, it obtains the network intrusion type of the network intrusion event; and generates a prompt message corresponding to the intrusion type of the network intrusion event based on the network intrusion type.

[0081] In one possible implementation, the processor 601 is further configured to: perform aggregate statistics on the normalized log data to obtain aggregate features of the normalized log data; identify the aggregate features of the normalized log data based on benchmark aggregate features to obtain an identification result; the benchmark aggregate features are obtained by aggregating and statistically analyzing benchmark log data within a second time period, and the benchmark log data does not include network intrusion data; and determine the analysis result of the normalized log data based on the identification result.

[0082] In one possible implementation, when the processor 601 determines the analysis result of the normalized log data based on the identification result, it is specifically configured to: if the identification result indicates that the aggregation characteristics of the normalized log data are abnormal, then determine the analysis result of the normalized log data as a first analysis result; the first analysis result is used to indicate that the target platform has a network intrusion event; if the identification result indicates that the aggregation characteristics of the normalized log data are normal, then determine the analysis result of the normalized log data as a second analysis result; the second analysis result is used to indicate that the target platform does not have a network intrusion event.

[0083] Based on the aforementioned detection equipment, it is possible to automatically detect network intrusion events on the target platform using log data, thereby reducing the occurrence of network intrusion events and effectively improving the data security of the target platform.

[0084] In specific implementations, the processor 601, input interface 602, output interface 603, and computer-readable storage medium 604 described in the embodiments of this application can execute the embodiments of this application. Figure 2 The implementation methods described in the relevant embodiments of the provided method can also be used to execute the embodiments of this application. Figure 5 The implementation methods described in the relevant embodiments of the provided device will not be repeated here.

[0085] In the several embodiments provided in this application, it should be understood that the disclosed methods, apparatus, systems, and computer devices can be implemented in other ways. The embodiments described above are merely illustrative, and the division of units is only a logical functional division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0086] This application also provides a computer program product, which includes program instructions stored in a computer-readable storage medium. A processor of a computer device reads the program instructions from the computer-readable storage medium and executes the program instructions, causing the computer device to perform the aforementioned data processing method, which will not be described in detail here.

[0087] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0088] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more program instructions. When the program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The program instructions can be stored in or transmitted through a computer-readable storage medium. The program instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0089] This application involves first log data, second log data, normalized log data, network intrusion events, prompt information, etc. When the above embodiments of this application are applied to specific products or technologies, the collection, use and processing of related data should comply with the requirements of relevant laws and regulations. Before collecting related data, the information processing rules should be informed and the individual consent of the subject should be obtained. Related data should be processed in strict accordance with the requirements of laws and regulations and personal information processing rules, and technical measures should be taken to ensure the security of related data.

[0090] It should be noted that, in the embodiments of this application, the terms "module" or "unit" refer to a computer program or part of a computer program with a predetermined function, which works together with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0091] It should be noted that the terms "first," "second," etc., used in the embodiments of this application are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a technical feature specified with "first" or "second" may explicitly or implicitly include at least one of those features.

[0092] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for detecting network intrusion events, characterized in that, The method includes: First log data of the target platform is obtained through a first channel, and second log data of the target platform is obtained through a second channel; the first channel and the second channel are different. The first log data and the second log data are normalized to obtain normalized log data; The normalized log data is analyzed to obtain the analysis results of the normalized log data; If the analysis results indicate that a network intrusion event has occurred on the target platform, then a prompt message is generated based on the network intrusion event; the prompt message is used to indicate the network intrusion event. Send the aforementioned prompt message to the management device.

2. The method according to claim 1, characterized in that, The step of obtaining the first log data of the target platform through the first channel includes: Retrieve the first log data within the first time period from the target platform's log database; The step of obtaining the second log data of the target platform through the second channel includes: Obtain network traffic data within the first time period on the target platform; The network traffic data is mirrored to obtain mirrored network traffic data; Log auditing is performed based on the mirror network traffic data to obtain the second log data.

3. The method according to claim 1 or 2, characterized in that, The normalization process includes parsing and integration; the normalization process of the first log data and the second log data to obtain normalized log data includes: The first log data and the second log data are parsed to obtain first parsed data and second parsed data; the parsing process includes formatting, data mapping and data augmentation. The first and second parsed data are integrated to obtain normalized log data.

4. The method according to claim 3, characterized in that, The analysis of the normalized log data to obtain the analysis results includes: Feature extraction is performed on the normalized log data to obtain the data features of the normalized log data; The correlation analysis between network intrusion features and the data features of the normalized log data is performed to obtain the correlation degree between the network intrusion features and the data features of the normalized log data; the network intrusion features are obtained by feature extraction from normalized log data including network intrusion events. The analysis results of the normalized log data are determined based on the correlation between the network intrusion characteristics and the data characteristics of the normalized log data.

5. The method according to claim 4, characterized in that, The step of determining the analysis result of the normalized log data based on the correlation between the network intrusion characteristics and the data characteristics of the normalized log data includes: If the correlation between the network intrusion characteristics and the data characteristics of the normalized log data is greater than or equal to a set threshold, then the analysis result of the normalized log data is determined as the first analysis result; the first analysis result is used to indicate that a network intrusion event exists on the target platform. If the correlation between the network intrusion characteristics and the data characteristics of the normalized log data is less than a set threshold, then the analysis result of the normalized log data is determined as the second analysis result; the second analysis result is used to indicate that there is no network intrusion event on the target platform.

6. The method according to claim 5, characterized in that, If the analysis result indicates that a network intrusion event has occurred on the target platform, then based on the network intrusion event, a prompt message is generated, including: When the analysis result of the normalized log data is determined to be the first analysis result, the network intrusion type of the network intrusion event is obtained; Based on the network intrusion type, generate a prompt message corresponding to the intrusion type of the network intrusion event.

7. The method according to any one of claims 4-6, characterized in that, The method further includes: The normalized log data is aggregated and statistically analyzed to obtain the aggregated features of the normalized log data; The aggregation features of the normalized log data are identified based on the benchmark aggregation features to obtain the identification results; the benchmark aggregation features are obtained by aggregating and statistically analyzing the benchmark log data within the second time period, and the benchmark log data does not include network intrusion data. The analysis results of the normalized log data are determined based on the identification results.

8. The method according to claim 7, characterized in that, The step of determining the analysis result of the normalized log data based on the identification result includes: If the identification result indicates that the aggregation characteristics of the normalized log data are abnormal, then the analysis result of the normalized log data is determined as the first analysis result; the first analysis result is used to indicate that there is a network intrusion event on the target platform; If the identification result indicates that the aggregation characteristics of the normalized log data are normal, then the analysis result of the normalized log data is determined to be the second analysis result; the second analysis result is used to indicate that there is no network intrusion event on the target platform.

9. A detection device, characterized in that, The device includes: The acquisition unit is configured to acquire first log data of the target platform through a first channel, and to acquire second log data of the target platform through a second channel; the first channel and the second channel are different. The processing unit is used to normalize the first log data and the second log data to obtain normalized log data. The processing unit is also used to analyze the normalized log data to obtain the analysis results of the normalized log data; The generation unit is configured to generate a prompt message based on the network intrusion event if the analysis result indicates that the target platform has a network intrusion event; the prompt message is used to indicate the network intrusion event. The sending unit is used to send the prompt information to the management device.

10. A computer device, characterized in that, The computer device includes: A processor is a tool for implementing computer programs. A computer-readable storage medium storing a computer program adapted to be loaded by the processor and executed as described in any one of claims 1-8 for detecting a network intrusion event.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed on a computer, cause the computer to implement the method for detecting network intrusion events as described in any one of claims 1-8.

12. A computer program product, characterized in that, The computer program product includes a computer program or computer instructions, which, when executed by a processor, are used to implement the method for detecting network intrusion events as described in any one of claims 1-8.