Abnormal response method and device, electronic equipment, storage medium and program product
By using a recognition model trained on sample log information features on client devices for feature extraction and anomaly identification, the challenge of detecting rapidly changing attack behaviors in multi-cloud enterprises is solved, enabling timely response and improved security.
Patent Information
- Application Number
- CN202511566223.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-29
- Publication Date
- 2026-01-02
AI Technical Summary
In the complex cloud environment of multi-cloud enterprises, existing technologies struggle to detect and respond to rapidly changing attack behaviors in a timely manner, leading to information leakage on client devices and servers, resulting in poor security.
The client device obtains log information during operation, inputs it into the recognition model for feature extraction and anomaly identification, and executes corresponding anomaly response operations. The recognition model is trained from the features of the sample log information.
It enables timely identification and response to abnormal behavior, prevents information leakage, improves device security, and reduces network resource consumption.
Smart Images

Figure CN121261989A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to an abnormal response method and device, electronic equipment, a storage medium and a program product. BACKGROUND
[0002] At present, with the increasing growth of multi-cloud enterprises, the cloud environment is increasingly complex, and the multi-layer architecture workload environment of the enterprise produces tens of thousands of servers, thereby making the maintenance of network security more difficult. Usually, in the maintenance scene of network security, a plurality of attack behavior characteristics are pre-stored in the client device, so that the client device can detect in real time according to the plurality of attack behavior characteristics, thereby the attack behavior of other devices can be discovered in time, and information leakage in the client device and the server can be avoided.
[0003] However, due to the rapid change of the above attack behavior, the plurality of attack behavior characteristics may not be able to detect new attack behaviors, thereby the client device cannot discover the attack behavior of other devices in time, and information leakage in the client device and the server is caused, so that the security of the device is poor. SUMMARY
[0004] The present application provides an abnormal response method, device, electronic equipment, storage medium and program product, which can improve the security of the device.
[0005] In a first aspect, the present application provides an abnormal response method, comprising: a first client device can acquire first log information generated in the running process of the first client device, and input the first log information into a first identification model, and perform feature extraction according to the first log information through the first identification model to obtain first features, so that the first client device can perform abnormal identification according to the first features through the first identification model, and perform an abnormal response operation corresponding to the abnormal behavior in the case of identifying the abnormal behavior; wherein the first identification model is obtained by training the features of at least one type of sample log information.
[0006] The technical scheme provided in the application brings at least the following beneficial effects: since the attack behavior of other devices will cause the internal indicators of the first client device to change, thereby affecting the log information generated during the running of the first client device, the first client device can directly input the first log information generated during the running of the first client device into the first identification model, and the first identification model is trained by the features of at least one type of sample log information, that is, the first identification model has learned the correlation between the features of log information and various abnormal behaviors by the features of at least one type of sample log information, therefore, the first client device can extract features from the first log information by the first identification model to obtain the first features of the first log information, and accurately identify the abnormality according to the first features, so that the first client device can timely identify the abnormal behavior against the first client device and timely execute the abnormal response operation corresponding to the abnormal behavior, that is, the response operation against the abnormal behavior, thereby avoiding information leakage in the first client device and the server device, and thus the security of the device can be improved.
[0007] In a possible implementation, before the first client device inputs the first log information into the first identification model and extracts features from the first log information by the first identification model, the method further includes that the first client device can receive at least two second identification models from a target platform, each of the at least two second identification models is trained by the features of different types of sample log information, each second identification model is used for abnormality identification according to the features of different types of log information, and a first identification model corresponding to the type of the first log information is determined from the at least two second identification models according to the type of the first log information.
[0008] In another possible implementation, the first client device can identify the abnormality according to the first features by the first identification model, and execute the abnormal response operation corresponding to the abnormal behavior in the case of identifying the abnormal behavior, including: the first client device can identify the abnormality according to the first features by the first identification model, and execute the abnormal response operation corresponding to the abnormal behavior in the case of identifying the abnormal behavior and the first identification model having response authority; or the first client device can identify the abnormality according to the first features by the first identification model, and send event data including the first log information to the server device in the case of identifying the abnormal behavior and the first identification model not having response authority.
[0009] In another possible implementation, after the event data is sent to the server device, the method further includes that the first client device can receive the indication information from the server device, and perform a first operation indicated by the indication information according to the indication information. The first operation includes at least one of the following: performing a global defense strategy; adjusting a firewall rule; and updating a security policy.
[0010] In another possible implementation, after the first feature is obtained, the method further includes that the first client device can perform correlation analysis on the first feature, the abnormal behavior, and a second feature, the second feature being a feature of second log information generated during running of the first client device, the type of the second log information being different from the type of the first log information, and sending a first analysis result obtained through the correlation analysis to the target platform, the first analysis result indicating a correlation between the first feature, the abnormal behavior, and the second feature, the first analysis result being used for training the first identification model.
[0011] In a second aspect, the present application provides an abnormal response method, including: a server device can receive at least one event data from at least one client device, each event data including log information generated during running of a client device, and input at least one log information into a third identification model, perform feature extraction on the at least one log information through the third identification model to obtain at least one third feature, perform abnormal identification on the at least one third feature through the third identification model, and in a case where an abnormal behavior is identified, send indication information to each client device, the indication information being used for indicating a first operation corresponding to the abnormal behavior; wherein the third identification model is obtained by training features of at least two types of sample log information; and the first operation includes at least one of the following: performing a global defense strategy; adjusting a firewall rule; and updating a security policy.
[0012] The technical scheme provided in the application brings at least the following beneficial effects: due to the attack behavior of other devices, the internal indicators of each client device change, thereby affecting the log information generated during the running of each client device, so that the server device can directly input at least one log information included in at least one event data from at least one client device into a third identification model, and the third identification model is obtained by training features of at least two types of sample log information, that is, the third identification model has learned the correlation between the features of the log information and various abnormal behaviors by the features of at least two types of sample log information, therefore, the server device can extract features according to the at least one log information through the third identification model, obtain at least one third feature of the at least one log information, and accurately identify the abnormality according to the at least one third feature, so that the server device can timely identify the abnormal behavior of at least one client device, and timely send indication information to each client device to instruct each client device to timely perform a first operation corresponding to the abnormal behavior, that is, a response operation to the abnormal behavior, thereby avoiding information leakage in each client device and the server device, and thus the security of the device can be improved.
[0013] In a possible implementation, after obtaining the at least one third feature, the method further includes: the server device can perform correlation analysis according to the at least one third feature and the abnormal behavior, and send a second analysis result obtained by the correlation analysis to the target platform, the second analysis result indicating the correlation between the at least one third feature and the abnormal behavior, and the second analysis result being used to train the third identification model.
[0014] In a third aspect, the application provides an abnormal response apparatus, including: an acquisition module and a processing module. The acquisition module is configured to acquire first log information generated during the running of the abnormal response apparatus. The processing module is configured to input the first log information acquired by the acquisition module into a first identification model, extract features from the first log information through the first identification model, obtain first features, identify an abnormal behavior through the first identification model according to the first features, and perform an abnormal response operation corresponding to the abnormal behavior in the case of identifying the abnormal behavior; and the first identification model is obtained by training features of at least one type of sample log information.
[0015] In a possible implementation, the abnormal response apparatus provided by the embodiment of the present application can further include a receiving module. The receiving module is configured to receive at least two second identification models from the target platform before the processing module inputs the first log information into the first identification model and before the first identification model performs feature extraction according to the first log information. Each of the at least two second identification models is trained by features of sample log information of different types, and each second identification model is configured to perform abnormal identification according to the features of log information of different types. The processing module is further configured to determine, according to the type of the first log information, a first identification model corresponding to the type of the first log information from the at least two second identification models received by the receiving module.
[0016] In another possible implementation, the processing module is specifically configured to perform abnormal identification according to the first features by using the first identification model, and perform an abnormal response operation corresponding to the abnormal behavior when the abnormal behavior is identified and the first identification model has response authority. Alternatively, the processing module is specifically configured to perform abnormal identification according to the first features by using the first identification model. The abnormal response apparatus provided by the embodiment of the present application can further include a sending module. The sending module is configured to send, by the processing module, event data to a server device when the abnormal behavior is identified and the first identification model does not have response authority, where the event data includes the first log information.
[0017] In another possible implementation, the receiving module is further configured to receive indication information from the server device after the sending module sends the first log information to the server device. The processing module is further configured to perform a first operation indicated by the indication information according to the indication information received by the receiving module. The first operation includes at least one of the following: performing a global defense strategy, adjusting a firewall rule, and updating a security policy.
[0018] In another possible implementation, the processing module is further configured to perform correlation analysis according to the first features, the abnormal behavior, and second features after the first features are obtained. The second features are features of second log information generated in a running process of the abnormal response apparatus, and the type of the second log information is different from the type of the first log information. The abnormal response apparatus provided by the embodiment of the present application can further include a sending module. The sending module is configured to send, to the target platform, a first analysis result obtained by the processing module through correlation analysis. The first analysis result indicates a correlation relationship between the first features, the abnormal behavior, and the second features, and the first analysis result is used to train the first identification model.
[0019] In a fourth aspect, the present application provides an abnormal response apparatus, comprising a receiving module, a processing module and a sending module. The receiving module is configured to receive at least one event data from at least one client device, each event data comprising log information generated during the operation of a client device. The processing module is configured to input the at least one log information received by the receiving module into a third identification model, extract at least one third feature from the at least one log information by the third identification model, and identify an abnormal behavior according to the at least one third feature by the third identification model. The sending module is configured to send an indication information to each client device in the case that the abnormal behavior is identified, the indication information being used to indicate a first operation corresponding to the abnormal behavior. The third identification model is obtained by training features of at least two types of sample log information. The first operation comprises at least one of the following: executing a global defense strategy, adjusting a firewall rule, and updating a security policy.
[0020] In a possible implementation, the processing module is further configured to perform correlation analysis on the at least one third feature and the abnormal behavior after obtaining the at least one third feature. The sending module is further configured to send a second analysis result obtained by the processing module to a target platform, the second analysis result indicating a correlation between the at least one third feature and the abnormal behavior, and the second analysis result being used to train the third identification model.
[0021] In a fifth aspect, the present application provides an electronic device, comprising a processor and a memory. The memory stores instructions executable by the processor. The processor is configured to execute the instructions, so that the electronic device implements the method of the first aspect or the method of the second aspect.
[0022] In a sixth aspect, the present application provides a computer-readable storage medium, comprising computer software instructions. When the computer software instructions are executed in an electronic device, the electronic device implements the method of the first aspect or the method of the second aspect.
[0023] In a seventh aspect, the present application provides a computer program product, comprising a computer program. When the computer program is executed in an electronic device, the electronic device implements the method of the first aspect or the method of the second aspect.
[0024] The beneficial effects of the third aspect to the seventh aspect are described in the corresponding description of the first aspect or the second aspect, and will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0025] Figure 1 An application environment schematic diagram of the abnormal response method provided by the present application; Figure 2 A flowchart of an abnormal response method provided by the present application is shown in FIG. 1. Figure 3 A flowchart of another abnormal response method provided by the present application is shown in FIG. 2. Figure 4 A flowchart of still another abnormal response method provided by the present application is shown in FIG. 3. Figure 5 A flowchart of still another abnormal response method provided by the present application is shown in FIG. 4. Figure 6 A flowchart of still another abnormal response method provided by the present application is shown in FIG. 5. Figure 7 A flowchart of still another abnormal response method provided by the present application is shown in FIG. 6. Figure 8 A flowchart of still another abnormal response method provided by the present application is shown in FIG. 7. Figure 9 A flowchart of still another abnormal response method provided by the present application is shown in FIG. 8. Figure 10 A flowchart of still another abnormal response method provided by the present application is shown in FIG. 9. Figure 11 A structural diagram of an abnormal response device provided by the present application is shown in FIG. 10. Figure 12 A structural diagram of another abnormal response device provided by the present application is shown in FIG. 11. Figure 13 A structural diagram of an electronic device provided by the present application is shown in FIG. 12. DETAILED DESCRIPTION
[0026] A bill data recording method provided by the present application will be described in detail below with reference to the accompanying drawings.
[0027] The term “and / or” in the present document merely describes an association relationship of associated objects, and indicates that there can be three relationships, for example, A and / or B can represent three cases of existence of A alone, existence of A and B simultaneously, and existence of B alone.
[0028] The terms “first” and “second” and the like in the present specification and the accompanying drawings are used to distinguish different objects, or to distinguish different treatments of the same object, and are not used to describe a specific order of the objects.
[0029] Furthermore, the terms “comprising” and “having”, and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such processes, methods, products, or apparatus.
[0030] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0031] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.
[0032] In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0033] Currently, with the increasing growth of multi-cloud enterprises and the growing complexity of cloud environments, enterprise multi-layered workload environments generate tens of thousands of servers, making network security maintenance more difficult and inevitably leading to unmanageable situations. The security failure resulting from server breaches not only causes economic and brand value losses due to information leaks, but also poses significant challenges from a security compliance and regulatory perspective, with many companies facing fines or even orders to rectify the issues. Typically, in network security maintenance scenarios, client devices pre-store various attack behavior characteristics. These characteristics allow client devices to perform real-time detection, enabling timely discovery of attacks from other devices and preventing information leaks from both client devices and servers.
[0034] However, the prior art has the following defects: 1) in a complex cloud environment, asset inventory and management have become a problem faced by many enterprises and organizations. Enterprises lack a continuous and refined asset state detection mechanism, and at the same time, in the face of a large scale of assets, the asset state cannot be quickly and real-timely discovered; 2) the traditional vulnerability security detection technology consumes more network resources, for example, the client device needs to frequently update attack behavior characteristics, thereby consuming more network resources, and there are problems such as high false positives and high false negatives, which cannot help enterprises to predict risks in real time and effectively, accurately monitor and perceive host asset vulnerability problems; 3) the above attack behaviors change rapidly, so the above multiple attack behavior characteristics may not be able to detect new attack behaviors, so that the client device cannot accurately and quickly perceive the real intrusion attack behavior of the host security asset by discovering the attack behavior of other devices in time, resulting in that real-time and effective alarm and response means cannot be provided.
[0035] In view of the above technical problems, the present application provides an abnormal response method and device, electronic equipment, storage medium and program product, and the idea is that the first client device can obtain first log information generated in the running process of the first client device, and input the first log information into a first identification model, and perform feature extraction on the first log information through the first identification model to obtain first features. In this way, the first client device can perform abnormal identification on the first features through the first identification model, and perform an abnormal response operation corresponding to the abnormal behavior in the case of identifying the abnormal behavior; wherein the first identification model is obtained by training features of at least one type of sample log information.
[0036] The technical scheme provided in the application brings at least the following beneficial effects: 1) since the first identification model is obtained by training features of at least one type of sample log information, that is, the first identification model has learned the correlation between features of log information and various abnormal behaviors by features of at least one type of sample log information, therefore, after the first client device inputs the first log information into the first identification model, the first identification model can extract features from the first log information to obtain first features, and the first identification model can identify abnormalities according to the first features, so as to determine the asset state according to whether an abnormal behavior is identified, thereby realizing rapid and real-time discovery of the asset state; 2) since the first identification model is a trained model, the first client device does not need to consume network resources to update attack behavior features, thereby avoiding consuming too many network resources; 3) since the attack behavior of other devices will cause the internal indicators of the first client device to change, thereby affecting the log information generated during the running of the first client device, the first client device can directly input the first log information generated during the running of the first client device into the first identification model, and the first identification model is obtained by training features of at least one type of sample log information, that is, the first identification model has learned the correlation between features of log information and various abnormal behaviors by features of at least one type of sample log information, therefore, the first client device can extract features from the first log information by the first identification model to obtain first features of the first log information, and accurately identify abnormalities according to the first features, so that the first client device can timely identify abnormal behaviors against the first client device and timely perform abnormal response operations corresponding to the abnormal behaviors, thereby avoiding information leakage in the client device and the server device.
[0037] The embodiments provided in the application will be specifically introduced below in conjunction with the drawings of the specification.
[0038] The abnormal response method provided in the application can be applied in an application environment as shown in Figure 1 As shown in Figure 1 , the application environment includes a server device 101 and a client device 102. The server device 101 and the client device 102 are connected to each other.
[0039] In some embodiments, the server device 101 can be a server cluster composed of multiple servers, or a single server, or a computer, or a processor or processing chip in the server or computer, etc. The specific device form of the server device 101 is not limited in the embodiments of the application. Figure 1 In the embodiment, the server device 101 is taken as a single server as an example.
[0040] In some embodiments, the client device 102 can be a device with wireless transceiver function, such as a mobile phone, a tablet computer, a wearable device, a vehicle-mounted device, an augmented reality (AR) / virtual reality (VR) device, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), etc. The embodiments of the present application do not limit the specific device form of the client device 102. Figure 1 The client device 102 is taken as a mobile phone terminal in the embodiments of the present application.
[0041] In some embodiments, the client device 102 can send event data to the server device 101, the event data including log information generated in the running process of the client device 102, so that the server device 101 can input the log information into a third identification model, perform feature extraction according to the log information through the third identification model, and perform abnormality identification according to the extracted features through the third identification model, and in the case of identifying abnormal behavior, send indication information to the client device 102, the indication information being used to instruct to perform an operation corresponding to the abnormal behavior.
[0042] It should be noted that the system architecture described in the embodiments of the present application is for more clearly illustrating the technical solutions of the embodiments of the present application, and does not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems as the system architecture evolves.
[0043] Referring to Figure 2 , a flowchart of an abnormal response method provided by the embodiments of the present application is shown. As shown in Figure 2 , the abnormal response method provided by the present application can be implemented by the above-mentioned client device, and specifically includes the following S201-S203.
[0044] S201, the first client device acquires first log information generated in the running process of the first client device.
[0045] In some embodiments, the above-mentioned first log information can include at least one of the following: system running log information; program running log information; Web access log information; system update log information; security notification information.
[0046] In some examples, the first log information can be all log information generated by the first client device during the running process, or a certain type of log information generated by the first client device during the running process. The certain type can be determined by a monitoring mode (or a monitoring scenario) or a user setting of the first client device.
[0047] In some examples, the number of the first log information can be at least one. For example, the first log information can be at least one system running log information, or at least one program running log information, and the like.
[0048] In some examples, the first client device can generate log information in real time during the running process of the first client device, and store the generated log information in a predetermined storage area of the first client device, so that the first client device can obtain the first log information from the predetermined storage area.
[0049] S202, the first client device inputs the first log information into the first identification model, and extracts features from the first log information by the first identification model to obtain first features.
[0050] In some examples, the first identification model can be a neural network model, and the first identification model can also be other models, which are not limited in the embodiments of the present application.
[0051] In the embodiments of the present application, the first identification model is obtained by training features of at least one type of sample log information.
[0052] In some examples, the at least one type of sample log information can include but is not limited to at least one of the following: sample system running log information; sample program running log information; sample Web access log information; sample system update log information; sample security notification information.
[0053] It can be understood that, since the internal indicators of the first client device change when other devices perform abnormal behaviors (such as attack behaviors) on the first client device, thereby affecting the log information generated by the first client device during the running process, at least one type of sample log information can be used to train the first preset model, so that the first preset model can learn the correlation between the features of the log information and various abnormal behaviors, and obtain the first identification model, so that the first identification model can be used to accurately and timely identify abnormal behaviors against the first client device in subsequent steps.
[0054] The abnormal behavior can include at least one of the following: abnormal login, privilege escalation, Structured Query Language (SQL) injection, Cross-Site Scripting (XSS), Shell rebound, brute force, abnormal process.
[0055] In some examples, the first identification model can be any one of the following: a log analysis model; a network attack detection model; a system abnormal behavior monitoring model.
[0056] Optionally, the log analysis model is used to analyze system and application log information to find abnormal behaviors such as abnormal login and privilege escalation. The network attack detection model is used to monitor World Wide Web (Web) access behavior to find attack abnormal behaviors such as Structured Query Language (SQL) injection and Cross-Site Scripting (XSS). The system abnormal behavior monitoring model is used to detect Shell rebound, brute force, abnormal process, and the like, and provide preliminary alarms and response actions.
[0057] It can be understood that through the first identification model, behaviors such as Shell rebound, backdoor investigation, brute force, or abnormal login can be monitored (e.g., traceability audit), so that the threat perception capability of the first client device to discover, record, and trace attack behaviors can be improved in combination with deception and camouflage technology.
[0058] Optionally, the first identification model can be determined by the type of the first log information. For example, in the case where the type of the first log information includes at least one of system running log information, program running log, Web access log, and system update log, the first identification model can be a log analysis model; or in the case where the type of the first log information is Web access log information, the first identification model can include a network attack detection model; or in the case where the type of the first log information includes at least one of system running log, program running log, Web access log, system update log, and security notification information, the first identification model can be a system abnormal behavior monitoring model.
[0059] In some examples, the first identification model can be obtained by model training of a first preset model according to at least one type of sample log information. The model training can include, but is not limited to, supervised learning model training and unsupervised learning model training.
[0060] Optionally, in the case that the model training includes supervised learning model training, the at least one type of sample log information corresponding to each time an abnormal behavior is identified and the type of the abnormal behavior can be taken as a training set, a plurality of training sets are obtained, and the first preset model is subjected to supervised learning model training using the plurality of training sets, thereby obtaining the first identification model. That is, the first identification model can learn the correlation between the features of the log information and various abnormal behaviors from the features of the at least one type of sample log information, thereby having the ability to identify whether an abnormal behavior occurs and the type of the abnormal behavior according to the log information.
[0061] Optionally, the first preset model can be a small model, and of course, the first preset model can also be other models (such as a large model, etc.), and the embodiments of the present application do not limit this.
[0062] It should be noted that the small model can be understood as a model with a parameter quantity less than or equal to a parameter quantity threshold.
[0063] It can be understood that since the first preset model can be a small model, the first identification model trained based on the first preset model can also be a small model, so that the first client device can achieve the effects of lightweight, low delay and fast response through the first identification model.
[0064] In some examples, the first client device can perform operations on the first log information through the first identification model to obtain first features.
[0065] S203, the first client device performs abnormality identification according to the first features through the first identification model, and in the case that an abnormal behavior is identified, performs an abnormal response operation corresponding to the abnormal behavior.
[0066] In some examples, the first client device can determine the deviation degree between the first features and the at least one first abnormal feature through the first identification model, and in the case that the deviation degree between the first features and any one of the first abnormal features is less than or equal to a first deviation degree threshold, determine that an abnormal behavior is identified.
[0067] Each first abnormal feature can be a feature of a type of abnormal behavior, and the at least one first abnormal feature can be a feature in the first identification model, that is, a feature learned by the first identification model in the process of model training.
[0068] It can be understood that if the deviation degree between the first features and any one of the first abnormal features is less than or equal to the first deviation degree threshold, it can be considered that the internal indicators of the first client device recorded in the first log information have deviated from the normal internal indicators, and therefore, it can be considered that an abnormal behavior is identified.
[0069] In some embodiments, the above abnormal response operation comprises at least one of: blocking a login session associated with the first log information; locking an account associated with the first log information; restoring a system configuration associated with the first log information; intercepting a network request associated with the first log information; masking an Internet Protocol (IP) address associated with the first log information; preventing execution of a script associated with the first log information; terminating a process associated with the first log information; isolating a file associated with the first log information; triggering a local alarm; recording trace information associated with the first log information; sending event data to a server device, the event data comprising the first log information.
[0070] Optionally, the above "associated with the first log information" can be understood as information (such as a session, an account, a system configuration, etc.) involved in the first log information.
[0071] Optionally, the above trace information can include but is not limited to a timestamp, an account, an IP address, a device identifier, a destination IP address, a protocol / service, a session identifier, an operation type, an operation object, etc.
[0072] In some instances, in a case where it is determined that the abnormal behavior is identified, the first client device can further determine, through the first identification model, a type of abnormal behavior corresponding to a first abnormal feature whose deviation degree from the first feature is less than or equal to a first deviation degree threshold, and determine an abnormal response operation according to the type.
[0073] Optionally, a corresponding relationship between the type and the operation is configured in the first client device, so that the first client device can determine the abnormal response operation corresponding to the type according to the corresponding relationship.
[0074] In some embodiments, in combination with Figure 2 As shown in Figure 3 The above S203 can be implemented by S2031 or S2032 as follows.
[0075] S2031, the first client device performs abnormal identification according to the first feature through the first identification model, and in a case where an abnormal behavior is identified and the first identification model has a response right, performs an abnormal response operation corresponding to the abnormal behavior.
[0076] Optionally, the above response right comprises at least one of: a permission to block abnormal login sessions; a permission to lock affected accounts or limit abnormal operations; a permission to intercept suspicious HTTP requests; a permission to shield attack source IPs or prevent malicious script execution; a permission to terminate suspicious processes; a permission to isolate abnormal files or trigger local alarms.
[0077] In a case where the first identification model is a log analysis model, the response permission includes at least one of a permission to block abnormal login sessions and a permission to lock affected accounts or limit abnormal operations. In a case where the first identification model is a network attack detection model, the response permission includes at least one of a permission to intercept suspicious HTTP requests and a permission to shield attack source IPs or prevent malicious script execution. In a case where the first identification model is a system abnormal behavior monitoring model, the response permission includes at least one of a permission to terminate suspicious processes and a permission to isolate abnormal files or trigger local alarms.
[0078] Optionally, in a case where the first identification model has a response permission, the abnormal response operation includes at least one of blocking a login session associated with the first log information, locking an account associated with the first log information, restoring a system configuration associated with the first log information, intercepting a network request associated with the first log information, shielding an IP address associated with the first log information, preventing execution of a script associated with the first log information, terminating a process associated with the first log information, isolating a file associated with the first log information, triggering a local alarm, and recording trace information associated with the first log information.
[0079] In a case where the first identification model is a log analysis model, the abnormal response operation includes at least one of blocking a login session associated with the first log information, locking an account associated with the first log information, and restoring a system configuration associated with the first log information. In a case where the first identification model is a network attack detection model, the abnormal response operation includes at least one of intercepting a network request associated with the first log information, shielding an IP address associated with the first log information, and preventing execution of a script associated with the first log information. In a case where the first identification model is a system abnormal behavior monitoring model, the abnormal response operation includes at least one of terminating a process associated with the first log information, isolating a file associated with the first log information, triggering a local alarm, and recording trace information associated with the first log information.
[0080] It is understood that when the first identification model has the response permission, the first identification model can correspond to at least one operation, thereby determining the corresponding abnormal response operation from at least one operation corresponding to the first identification model based on the type of abnormal behavior.
[0081] Thus, it can be seen that, since the first identification model can directly execute the abnormal response operation through the first identification model when abnormal behavior is detected, the response speed of the first client device to abnormal behavior can be improved, thereby enhancing the security of the device.
[0082] S2032. The first client device performs anomaly identification based on the first feature using the first identification model, and sends event data to the server device when an abnormal behavior is identified and the first identification model does not have the authority to respond.
[0083] In this embodiment of the application, the event data includes first log information.
[0084] It is understandable that, in the case that the first identification model does not have the authority to respond, the abnormal response operation includes: sending event data to the server device.
[0085] Optionally, the aforementioned event data may also include relevant information from the first log information and the type of abnormal behavior identified. This relevant information may include, but is not limited to, source tracing information.
[0086] Thus, when abnormal behavior is detected and the first identification model does not have the authority to respond, the first client device can send event data to the server device to indicate the first log information. Therefore, the server device can perform in-depth analysis by combining the log information of multiple client devices and the first log information, and instruct the first client device to respond to abnormalities based on the results of the in-depth analysis. This can improve the accuracy of the first client device's response to abnormalities, thereby enhancing the security of the device.
[0087] In some embodiments, combined with Figure 3 ,like Figure 4 As shown, after S2032 above, the abnormal response method provided in this application embodiment may further include S301 and S302.
[0088] S301, The first client device receives instruction information from the server device.
[0089] In this embodiment of the application, the above-mentioned instruction information is used to instruct the first client device to perform a first operation.
[0090] Optionally, the first operation can be determined by the server device according to the first log information and log information of the plurality of client devices.
[0091] In the embodiments of the present application, the first operation includes at least one of the following: executing a global defense strategy; adjusting a firewall rule; updating a security policy.
[0092] S302, the first client device executes the first operation indicated by the indication information according to the indication information.
[0093] Optionally, in the case where the first operation includes executing a global defense strategy, the indication information can include the global defense strategy, so that the first client device can execute the global defense strategy. In the case where the first operation includes adjusting a firewall rule, the indication information can explicitly or implicitly indicate the adjusted firewall rule, so that the first client can adjust the firewall rule to the adjusted firewall rule indicated by the indication information. In the case where the first operation includes updating a security policy, the indication information can include the updated security policy, so that the first client device can update the security policy according to the updated security policy included in the indication information.
[0094] As can be seen, after the first client device sends the event data to the server device, the first client device can receive the indication information from the server device, which can be obtained by the server device according to the first log information in the event data, so that the first client device can execute the first operation indicated by the indication information according to the indication information, thus the abnormal behavior can be accurately responded to, and the security of the device can be improved.
[0095] The embodiment of the application provides an abnormal response method, a first client device can acquire first log information generated in a running process of the first client device, and input the first log information into a first identification model, and performs feature extraction on the first log information through the first identification model to obtain first features, so that the first client device can perform abnormal identification according to the first features through the first identification model, and perform an abnormal response operation corresponding to the abnormal behavior in the case of identifying the abnormal behavior; wherein the first identification model is obtained by training features of at least one type of sample log information. Since the attack behavior of other devices will cause the internal indicators of the first client device to change, thereby affecting the log information generated in the running process of the first client device, so that the first client device can directly input the first log information generated in the running process of the first client device into the first identification model, and the first identification model is obtained by training features of at least one type of sample log information, that is, the first identification model has learned the correlation between the features of the log information and various abnormal behaviors by at least one type of sample log information. Therefore, the first client device can extract features from the first log information through the first identification model, obtain the first features of the first log information, and accurately identify the abnormal behavior according to the first features, so that the first client device can timely identify the abnormal behavior of the first client device, and timely perform the abnormal response operation corresponding to the abnormal behavior, that is, the response operation for the abnormal behavior, to avoid information leakage in the first client device and the server device, so that the security of the device can be improved.
[0096] Also, since the first identification model is obtained by training features of at least one type of sample log information, that is, the first identification model has learned the correlation between the features of the log information and various abnormal behaviors by at least one type of sample log information, after the first client device inputs the first log information into the first identification model, the first identification model can extract features from the first log information to obtain the first features, and identify the abnormal behavior through the first identification model according to the first features, to determine the asset state according to whether the abnormal behavior is identified, to realize rapid and real-time discovery of the asset state.
[0097] Also, since the first identification model is a trained model, the first client device does not need to consume network resources to update attack behavior features, thereby avoiding consuming more network resources.
[0098] In some embodiments, in combination with Figure 2 As Figure 5As shown, before S202, the method for responding to an exception provided in the embodiments of the present application can further include S401 and S402.
[0099] S401, the first client device receives at least two second identification models from the target platform.
[0100] It should be noted that the embodiments of the present application do not limit the execution order of S401 and S201, that is, the first client device can execute S201 first and then execute S401, or execute S401 first and then execute S201, or execute S201 and S401 at the same time. Figure 5 In the embodiments of the present application, S201 is executed first and then S401 is executed.
[0101] In the embodiments of the present application, each of the at least two second identification models is obtained by training features of different types of sample log information, and each second identification model is used for abnormal identification according to the features of different types of log information.
[0102] Optionally, the target platform can be a centralized data center or a cloud platform, of course, the target platform can also be other platforms, and the embodiments of the present application do not limit this.
[0103] Optionally, the target platform can be deployed with a big data training program, so that the target platform can use different types of sample log information to train the first preset model through the big data training program to obtain at least two second identification models.
[0104] It can be understood that each second identification model can be applicable to one monitoring mode (or monitoring scene).
[0105] It should be noted that the description of different types of sample log information and the first preset model can refer to the specific description in the above embodiments, and the embodiments of the present application will not be repeated here.
[0106] Optionally, the at least two second identification models include at least one of the following: a log analysis model; a network attack detection model; a system abnormal behavior monitoring model.
[0107] S402, the first client device determines a first identification model corresponding to the type of the first log information from the at least two second identification models according to the type of the first log information.
[0108] Optionally, the first client device is configured with a correspondence between types and models, so that the first client device can determine the first identification model corresponding to the first log information according to the correspondence.
[0109] As such, since the first client device can receive at least two second identification models from the target platform, and the at least two second identification models are respectively applicable to performing one kind of monitoring, the first client device can determine the first identification model applicable to performing monitoring using the first log information from the at least two second identification models according to the type of the first log information, so that the accuracy of identifying abnormal behaviors in the subsequent steps can be improved, so as to accurately and timely perform abnormal response in the case of abnormal behaviors, avoid information leakage in the first client device and the server device, and thus the security of the device can be improved.
[0110] In some embodiments, the method further includes Figure 2 As shown in FIG. 5, after S202, the method provided by the embodiments of the present application can further include S501 and S502. Figure 6
[0111] S501, the first client device performs correlation analysis according to the first feature, the abnormal behavior and the second feature.
[0112] It should be noted that the embodiments of the present application do not limit the execution order of S501 and S203, that is, the first client device can execute S501 first and then execute S203, or can execute S203 first and then execute S501, or can execute S501 at the same time as executing S203. Figure 6 In the embodiment shown in FIG. 5, S501 is executed first and then S203 is executed.
[0113] In the embodiments of the present application, the second feature is a feature of second log information generated during the running of the first client device, and the type of the second log information is different from the type of the first log information.
[0114] For example, assuming that the first log information is system running log information, and the second log information can be program running log information; or assuming that the first log information includes system running log information and Web access log information, the second log information can be system update log information.
[0115] Optionally, the first client device can detect and identify potential complex attack chains and hidden threats according to the first feature, the type of the abnormal behavior and the second feature, so as to obtain the first analysis result.
[0116] S502, the first client device sends the first analysis result obtained by the correlation analysis to the target platform.
[0117] It can be understood that the first analysis result indicates the correlation relationship between the first feature, the abnormal behavior and the second feature, and the first analysis result is used to indicate the complex attack chain and the hidden threat.
[0118] In the embodiment of the application, the first analysis result is used to train the first identification model.
[0119] It can be understood that after the first client device sends the first analysis result to the target platform, the target platform can further train the first identification model using the first analysis result, obtain an updated first identification model, and indicate the updated first identification model to the first client device, so that the first client device can update the first identification model.
[0120] As can be seen, since the first client device can also perform correlation analysis according to the first feature, the abnormal behavior and the second feature, and report the first analysis result to the target platform, the target platform can further train the first identification model and indicate the first client device to update the first identification model, so that the accuracy of the first identification model in the first client device for abnormal identification can be improved, and thus the first client device can accurately and timely identify abnormal behaviors through the first identification model, thereby avoiding information leakage in the first client device and the server device, so that the security of the device can be improved.
[0121] It can be understood that the application can perform aggregated correlation analysis on log information, so as to dataize deep analysis of various dimension information, and effectively support and adapt to the new security management situation.
[0122] Referring to Figure 7 , a flowchart of an abnormal response method provided by an embodiment of the application is shown. As Figure 7 shown, the abnormal response method provided by the application can be implemented by the above-mentioned client device, and specifically includes the following S601-S603.
[0123] S601, the server device receives at least one event data from at least one client device.
[0124] In the embodiment of the application, the at least one client device includes the first client device, and the first client device can be any one of the at least one client device.
[0125] In the embodiment of the application, each event data in the at least one event data includes log information generated in the running process of a client device.
[0126] It should be noted that the description of the event data can refer to the specific description in the above embodiments, and the description of the log information can refer to the specific description of the first log information in the above embodiments, and the embodiments of the present application will not be repeated here.
[0127] S602, the server device inputs at least one log information into a third identification model, and performs feature extraction on the at least one log information through the third identification model to obtain at least one third feature.
[0128] In some examples, the third identification model described above can be a neural network model, and of course the third identification model can also be other models, which are not limited by the embodiments of the present application.
[0129] In the embodiments of the present application, the third identification model described above is obtained by training features of at least two types of sample log information.
[0130] In some examples, the at least two types of sample log information described above can include but are not limited to at least two of the following: Sample system running log information; Sample program running log information; Sample Web access log information; Sample system update log information; Sample security notification information.
[0131] In some examples, the first identification model described above can be obtained by model training of the second preset model according to at least two types of sample log information. The model training can include but is not limited to supervised learning model training and unsupervised learning model training.
[0132] Optionally, the second preset model described above can be a large model, and of course the second preset model can also be other models (such as small models, etc.), which are not limited by the embodiments of the present application.
[0133] It should be noted that the large model described above can be understood as a model with a parameter quantity greater than a parameter quantity threshold.
[0134] It can be understood that since the second preset model can be a large model, the third identification model trained based on the second preset model can also be a large model, so that the server device can realize global vision and strong computing power through the third identification model, and can perform cross-host, multi-dimensional correlation analysis to identify complex attack chains and potential hidden threats.
[0135] In some examples, the third identification model described above can include: Log analysis model; Network attack detection model; System abnormal behavior monitoring model.
[0136] It can be understood that the third identification model can analyze system and application log information to discover abnormal behaviors such as abnormal login and privilege escalation, and can monitor World Wide Web (Web) access behaviors to discover attack abnormal behaviors such as Structured Query Language (SQL) injection and Cross-Site Scripting (XSS) attacks, and can monitor models for detecting rebound shells, brute force attacks, abnormal processes, and the like, and provide preliminary alarms and response actions.
[0137] It can be understood that through the third identification model, behaviors such as rebound shells, backdoor investigation, brute force attacks, and abnormal login can be monitored (for example, traceability audit), so that the threat perception capability of the server device to discover, record, and trace attack behaviors can be improved in combination with deception and camouflage technology.
[0138] In some examples, the server device can operate at least one log information through the third identification model to obtain at least one third feature.
[0139] S603, the server device performs abnormal identification according to the at least one third feature through the third identification model, and sends indication information to each client device in the case of identifying an abnormal behavior.
[0140] In the embodiments of the present application, the above-mentioned indication information is used to indicate the execution of a first operation corresponding to the abnormal behavior.
[0141] In the embodiments of the present application, the above-mentioned first operation includes at least one of the following: executing a global defense strategy; adjusting a firewall rule; updating a security policy.
[0142] It should be noted that the description of the first operation can refer to the specific description in the above embodiments, and the embodiments of the present application will not be repeated here.
[0143] In some examples, the server device can determine the deviation degree between the at least one third feature and the at least one second abnormal feature through the third identification model, and determine that an abnormal behavior is identified in the case that the deviation degree between the at least one third feature and any one of the second abnormal features is less than or equal to a second deviation degree threshold.
[0144] Each second abnormal feature can be a feature of a type of abnormal behavior, and the at least one second abnormal feature can be a feature in the third identification model, that is, a feature learned by the third identification model in the process of model training.
[0145] In some examples, in a case where it is determined that the abnormal behavior is recognized, the server-side device can further determine, through the third identification model, a type of abnormal behavior corresponding to a second abnormal feature whose deviation degree from the at least one third feature is less than or equal to a second deviation degree threshold, and determine the first operation according to the type.
[0146] Optionally, a correspondence relationship between the type and the operation is configured in the server-side device, so that the server-side device can determine the first operation corresponding to the type according to the correspondence relationship.
[0147] In some embodiments, the server-side device can further output an abnormal response suggestion according to the type of abnormal behavior through the third identification model, so that a user (for example, an administrator) of the server-side device can quickly take an abnormal response measure according to the abnormal response suggestion.
[0148] The embodiment of the present application provides an abnormal response method, a server device can receive at least one event data from at least one client device, each event data includes log information generated in the running process of a client device, and input at least one log information into a third identification model, perform feature extraction on at least one log information through the third identification model, obtain at least one third feature, and perform abnormal identification on at least one third feature through the third identification model, and in the case of identifying abnormal behavior, send indication information to each client device, the indication information is used to indicate to execute a first operation corresponding to the abnormal behavior; wherein the third identification model is obtained by training the features of at least two types of sample log information; the first operation includes at least one of the following: executing a global defense strategy; adjusting the firewall rule; updating the security policy. Since the attack behavior of other devices will cause the internal indicators of each client device to change, thereby affecting the log information generated in the running process of each client device, so that the server device can receive at least one event data from at least one client device, and directly input at least one log information included in the at least one event data into the third identification model, and the third identification model is obtained by training the features of at least two types of sample log information, that is, the third identification model has learned the correlation between the features of the log information and various abnormal behaviors by at least two types of sample log information. Therefore, the server device can perform feature extraction on the at least one log information through the third identification model, obtain at least one third feature of the at least one log information, and accurately perform abnormal identification according to the at least one third feature, so that the server device can identify the abnormal behavior of at least one client device in time, and send indication information to each client device in time to indicate each client device to execute the first operation corresponding to the abnormal behavior, that is, the response operation of the abnormal behavior, avoiding information leakage in each client device and the server device. Therefore, the security of the device can be improved.
[0149] In some embodiments, in combination Figure 7 As shown in the above S602, before the above S602, the embodiment of the present application provides an abnormal response method, which can further include the following S701. Figure 8
[0150] S701, the server device receives the third identification model from the target platform.
[0151] It should be noted that the execution order of the above S701 and S601 is not limited by the embodiment of the present application, that is, the server device can execute S601 first and then execute S701, or execute S701 first and then execute S601, or execute S601 and S701 simultaneously.Figure 8 The example shown is based on the server device executing S601 first and then S701.
[0152] Optionally, the target platform may be equipped with a big data training program, which allows the target platform to train the second preset model using at least two types of sample log information to obtain the third recognition model.
[0153] It should be noted that the descriptions of at least two types of sample log information and the second preset model can be found in the specific descriptions in the above embodiments, and will not be repeated here in the embodiments of this application.
[0154] Thus, since the server-side device can receive the third recognition model from the target platform without training its own third recognition model, the complexity of the server-side device can be reduced, and the cost of the device can be decreased.
[0155] In some embodiments, combined with Figure 7 ,like Figure 9 As shown, after S602 above, the abnormal response method provided in this application embodiment may further include S801 and S802 as described below.
[0156] S801. The server-side device performs correlation analysis based on at least one third characteristic and abnormal behavior.
[0157] Optionally, the server-side device can perform detection based on at least one third characteristic and the type of abnormal behavior to identify potential complex attack chains and covert threats, thereby obtaining a second analysis result.
[0158] S802, The server device sends the second analysis result obtained from the correlation analysis to the target platform.
[0159] In this embodiment of the application, the second analysis result indicates the correlation between at least one third feature and abnormal behavior, and the second analysis result is used to train the third identification model.
[0160] It is understandable that after the server device sends the second analysis result to the target platform, the target platform can use the second analysis result to further train the third recognition model, obtain the updated third recognition model, and indicate the updated third recognition model to the server device, so that the server device can update the third recognition model.
[0161] Therefore, the target platform can further train the third identification model, and instruct the service end device to update the third identification model, so that the accuracy of the third identification model in the service end device for deep abnormality identification can be improved, and the service end device can accurately and timely identify abnormal behaviors through the third identification model, thereby avoiding information leakage in at least one client end device and the service end device, so that the security of the device can be improved.
[0162] It can be understood that the present application can perform aggregated correlation analysis on log information, so as to dataize deep analysis of various dimension information, and effectively support and adapt to the new security management situation.
[0163] Next, an abnormal response method of an embodiment of the present application will be introduced with reference to a specific embodiment, and the specific implementation process of the method is as shown in Figure 10
[0164] S1, the target platform obtains at least two types of sample log information, and performs cleaning, labeling and feature extraction on the at least two types of sample log information through a big data training program of the target platform, to obtain features of the at least two types of sample log information.
[0165] S2, the target platform uses at least one type of sample log information to perform model training on a first preset model through the big data training program, to obtain at least two second identification models, and uses at least two types of sample log information to perform model training on a second preset model, to obtain a third identification model.
[0166] Among them, each second identification model can be applicable to one monitoring mode (or monitoring scene), and the third identification model can be applicable to all monitoring modes (or monitoring scenes).
[0167] S3, the target platform sends at least two second identification models to each client end device, and sends the third identification model to the service end device.
[0168] S4, the first client end device obtains first log information generated in the running process of the first client end device.
[0169] S5, the first client end device determines a first identification model corresponding to the type of the first log information from the at least two second identification models according to the type of the first log information.
[0170] S6, the first client device inputs the first log information into the first identification model, extracts features from the first log information through the first identification model to obtain first features, and performs abnormality recognition according to the first features, and in the case of identifying abnormal behavior, performs an abnormal response operation corresponding to the abnormal behavior.
[0171] In the case that the first identification model does not have response permission, the first client device can send event data to the server device.
[0172] S7, the server device receives at least one event data from at least one client device.
[0173] Among the at least one client device, the first client device is included.
[0174] S8, the server device inputs at least one log information into the third identification model, extracts at least one third feature from the at least one log information through the third identification model, and performs feature recognition according to the at least one third feature, and in the case of identifying abnormal behavior, sends indication information to each client device.
[0175] And in the above steps, the first client device can perform correlation analysis according to the first features and the abnormal behavior and the second features, the second features being the features of the second log information generated in the running process of the first client device, the type of the second log information being different from the type of the first log information, and sending the first analysis result obtained by the correlation analysis to the target platform, and the server device performs correlation analysis according to the at least one third feature and the abnormal behavior, and sends the second analysis result obtained by the correlation analysis to the target platform. Thus, the target platform can use the first analysis result and the second analysis result to train at least two second identification models and a third identification model, and send the at least two second identification models to the client devices respectively, and send the third identification model to the server device.
[0176] In some embodiments, the present application also provides an abnormal response device. The abnormal response device can include one or more functional modules for implementing the abnormal response method of the above method embodiments.
[0177] For example, Figure 11 A structural schematic diagram of an abnormal response device provided by an embodiment of the present application. As shown in Figure 11As shown, the abnormal response apparatus 900 can include an acquisition module 901 and a processing module 902. The acquisition module 901 is configured to acquire first log information generated in the running process of the abnormal response apparatus 900. The processing module 902 is configured to input the first log information acquired by the acquisition module 901 into a first identification model, extract features from the first log information according to the first identification model, obtain first features, and perform abnormality identification according to the first features through the first identification model, and execute an abnormal response operation corresponding to the abnormal behavior in the case of identifying the abnormal behavior. The first identification model is obtained by training features of at least one type of sample log information.
[0178] The embodiment of the present application provides an abnormal response apparatus. Since the attack behavior of other devices can cause the internal indicators of the abnormal response apparatus to change, thereby affecting the log information generated in the running process of the abnormal response apparatus. Thus, the abnormal response apparatus can directly input the first log information generated in the running process of the abnormal response apparatus into the first identification model, and the first identification model is obtained by training features of at least one type of sample log information. That is, the first identification model has learned the correlation between the features of the log information and various abnormal behaviors by at least one type of sample log information. Therefore, the abnormal response apparatus can extract features from the first log information according to the first identification model, obtain first features of the first log information, and accurately perform abnormality identification according to the first features, so that the abnormal response apparatus can timely identify the abnormal behavior against the abnormal response apparatus and timely execute the abnormal response operation corresponding to the abnormal behavior, that is, the response operation against the abnormal behavior, thereby avoiding information leakage of the abnormal response apparatus and the server device. In this way, the security of the device can be improved.
[0179] In some embodiments, the abnormal response apparatus 900 provided by the embodiment of the present application can further include a receiving module. The receiving module is configured to receive at least two second identification models from a target platform before the processing module 902 inputs the first log information into the first identification model and extracts features from the first log information according to the first identification model through the first identification model. Each of the at least two second identification models is obtained by training features of different types of sample log information, and each second identification model is configured to perform abnormality identification according to features of different types of log information. The processing module 902 is further configured to determine the first identification model corresponding to the type of the first log information from the at least two second identification models received by the receiving module according to the type of the first log information.
[0180] In some embodiments, the processing module 902 is specifically configured to perform the abnormality identification according to the first feature through the first identification model, and perform an abnormality response operation corresponding to the abnormal behavior in a case where the abnormal behavior is identified and the first identification model has response authority. Alternatively, the processing module 902 is specifically configured to perform the abnormality identification according to the first feature through the first identification model. The abnormality response apparatus 900 provided in the embodiments of the present application can further include a sending module. The sending module is configured to send event data to a server device in a case where the processing module 902 identifies the abnormal behavior and the first identification model does not have the response authority, the event data including the first log information.
[0181] In some embodiments, the receiving module is further configured to receive indication information from the server device after the sending module sends the first log information to the server device. The processing module 902 is further configured to perform a first operation indicated by the indication information according to the indication information received by the receiving module. The first operation includes at least one of the following: performing a global defense strategy, adjusting a firewall rule, and updating a security policy.
[0182] In some embodiments, the processing module 902 is further configured to perform correlation analysis according to the first feature, the abnormal behavior, and a second feature after obtaining the first feature. The second feature is a feature of second log information generated during the running of the first client device, and the type of the second log information is different from that of the first log information. The abnormality response apparatus 900 provided in the embodiments of the present application can further include a sending module. The sending module is configured to send a first analysis result obtained by the processing module 902 through the correlation analysis to a target platform. The first analysis result indicates a correlation between the first feature, the abnormal behavior, and the second feature, and the first analysis result is used to train the first identification model.
[0183] For example, Figure 12 Another abnormality response apparatus provided in the embodiments of the present application is shown in a structural schematic diagram. As shown in FIG. 6, the abnormality response apparatus 600 includes a receiving module 601, a processing module 602, and a sending module 603. Figure 12As shown, the abnormal response apparatus 1000 can include a receiving module 1001, a processing module 1002, and a sending module 1003. The receiving module 1001 is configured to receive at least one event data from at least one client device, each event data including log information generated in a running process of a client device. The processing module 1002 is configured to input the at least one log information received by the receiving module 1001 into a third identification model, extract at least one third feature from the at least one log information by the third identification model, and identify an abnormal behavior according to the second feature by the third identification model. The sending module 1003 is configured to send an indication information to each client device in a case where an abnormal behavior is identified, the indication information being used to instruct to perform a first operation corresponding to the abnormal behavior determined by the processing module 1002. The third identification model is obtained by training features of at least two types of sample log information. The first operation includes at least one of the following: performing a global defense strategy, adjusting a firewall rule, and updating a security policy.
[0184] The embodiment of the present application provides an abnormal response apparatus. Since the attack behavior of other devices can cause the internal indicators of each client device to change, thereby affecting the log information generated in the running process of each client device, the abnormal response apparatus can directly input the at least one log information included in the at least one event data from at least one client device into a third identification model, and the third identification model is obtained by training features of at least two types of sample log information, that is, the third identification model has learned the correlation between the features of the log information and various abnormal behaviors by the features of at least two types of sample log information. Therefore, the abnormal response apparatus can extract at least one third feature of the at least one log information according to the at least one log information by the third identification model, and accurately identify an abnormal behavior according to the at least one third feature, so that the abnormal response apparatus can identify the abnormal behavior of the at least one client device in time, and send an indication information to each client device in time to instruct each client device to perform a first operation corresponding to the abnormal behavior, that is, a response operation to the abnormal behavior, thereby avoiding information leakage of each client device and the abnormal response apparatus. In this way, the security of the device can be improved.
[0185] In some embodiments, the processing module 1002 is further configured to, after obtaining the at least one third feature, perform correlation analysis according to the at least one third feature and the abnormal behavior. The sending module 1003 is further configured to send, to the target platform, a second analysis result obtained by the processing module 1002 through the correlation analysis, the second analysis result indicating a correlation between the at least one third feature and the abnormal behavior, and the second analysis result being used for training the third identification model.
[0186] In the case where the functions of the above-mentioned integrated modules are implemented in the form of hardware, the embodiments of the present application provide a possible structural schematic diagram of the electronic device involved in the above-mentioned embodiments. As shown in the figure, the electronic device 1100 includes a processor 1102, a communication interface 1103, and a bus 1104. Optionally, the electronic device 1100 can further include a memory 1101. Figure 13
[0187] The processor 1102 can be various exemplary logical blocks, modules and circuits described in combination with the disclosure of the present application. The processor 1102 can be a central processing unit, a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic device, transistor logic device, hardware component or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure of the present application. The processor 1102 can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of DSP and microprocessor, etc.
[0188] The communication interface 1103 is used to connect with other devices through a communication network. The communication network can be Ethernet, wireless access network, wireless local area network (WLAN) and the like.
[0189] The memory 1101 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but is not limited thereto.
[0190] As a possible implementation, the memory 1101 can exist in the form of a separate entity from the processor 1102, or the memory 1101 can be connected to the processor 1102 through the bus 1104, for storing instructions or program codes. When the processor 1102 invokes and executes the instructions or program codes stored in the memory 1101, the processor 1102 can implement the method for responding to an exception provided by the embodiments of the present application.
[0191] In another possible implementation, the memory 1101 can also be integrated with the processor 1102.
[0192] The bus 1104 can be an extended industry standard architecture (EISA) bus, or the like. The bus 1104 can be divided into an address bus, a data bus, a control bus, or the like. For the sake of brevity and simplicity, only one bus is shown in the figure, but it does not mean that there is only one bus or only one type of bus. Figure 13 The bus 1104 can be an extended industry standard architecture (EISA) bus, or the like. The bus 1104 can be divided into an address bus, a data bus, a control bus, or the like. For the sake of brevity and simplicity, only one bus is shown in the figure, but it does not mean that there is only one bus or only one type of bus.
[0193] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of brevity and simplicity, only the above-mentioned division of functional modules is exemplified, and in actual application, the above-mentioned functions can be completed by different functional modules according to needs, that is, the internal structure of the service calling device is divided into different functional modules to complete all or part of the functions described above.
[0194] The embodiments of the present application also provide a computer readable storage medium. All or part of the processes in the above method embodiments can be completed by computer instructions related to hardware, and the program can be stored in the above computer readable storage medium. When the program is executed, the processes of the above method embodiments can be included. The computer readable storage medium can be the memory of any of the preceding embodiments. The above computer readable storage medium can also be an external storage device of the service calling device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, or the like. Further, the above computer readable storage medium can include both the internal storage unit of the service calling device and the external storage device. The above computer readable storage medium is used to store the above computer program and other programs and data required by the service calling device. The above computer readable storage medium can also be used to temporarily store data that has been output or will be output.
[0195] The embodiment of the present application further provides a computer program product, which comprises a computer program, and when the computer program product runs on a computer, the computer program product enables the computer to execute any one of the abnormal response methods provided in the above embodiments.
[0196] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited to this. Any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An anomaly response method, characterized in that, include: The first client device acquires the first log information generated during the operation of the first client device; The first client device inputs the first log information into the first recognition model, and the first recognition model extracts features based on the first log information to obtain the first feature; The first client device uses the first identification model to identify anomalies based on the first feature, and if an abnormal behavior is detected, it executes an abnormal response operation corresponding to the abnormal behavior. The first identification model is trained using features from at least one type of sample log information.
2. The method according to claim 1, characterized in that, Before the first client device inputs the first log information into the first recognition model, and before the first recognition model performs feature extraction based on the first log information, the method further includes: The first client device receives at least two second identification models from the target platform. Each of the at least two second identification models is trained using features of different types of sample log information. Each second identification model is used to identify anomalies based on the features of different types of log information. The first client device determines the first identification model corresponding to the type of the first log information from the at least two second identification models based on the type of the first log information.
3. The method according to claim 1, characterized in that, The first client device uses the first recognition model to perform anomaly identification based on the first feature, and upon detecting abnormal behavior, executes an anomaly response operation corresponding to the abnormal behavior, including: The first client device uses the first identification model to perform anomaly identification based on the first feature, and if an abnormal behavior is identified and the first identification model has the necessary permissions, it executes an abnormal response operation corresponding to the abnormal behavior; or... The first client device uses the first identification model to identify anomalies based on the first feature. If an abnormal behavior is detected and the first identification model does not have the authority to respond, the first client device sends event data to the server device. The event data includes the first log information.
4. The method according to claim 3, characterized in that, After sending the first log information to the server device, the method further includes: The first client device receives instruction information from the server device; The first client device executes the first operation indicated by the indication information according to the indication information; The first operation includes at least one of the following: Implement a global defense strategy; Adjust firewall rules; Update security policies.
5. The method according to claim 1, characterized in that, After obtaining the first feature, the method further includes: The first client device performs correlation analysis based on the first feature, the abnormal behavior, and the second feature. The second feature is a feature of the second log information generated during the operation of the first client device. The type of the second log information is different from the type of the first log information. The first client device sends a first analysis result obtained from the correlation analysis to the target platform. The first analysis result indicates the correlation between the first feature, the abnormal behavior, and the second feature. The first analysis result is used to train the first recognition model.
6. An anomaly response method, characterized in that, include: The server device receives at least one event data from at least one client device, and each event data includes log information generated during the operation of a client device; The server device inputs at least one log information into the third recognition model, and the third recognition model performs feature extraction based on the at least one log information to obtain at least one third feature. The server device uses the third identification model to perform anomaly identification based on at least one third feature, and sends an instruction message to each client device when an abnormal behavior is detected. The instruction message is used to instruct the execution of a first operation corresponding to the abnormal behavior. The third identification model is trained using features from at least two types of sample log information. The first operation includes at least one of the following: Implement a global defense strategy; Adjust firewall rules; Update security policies.
7. The method according to claim 6, characterized in that, After obtaining at least one third feature, the method further includes: The server-side device performs correlation analysis based on the at least one third feature and the abnormal behavior; The server device sends a second analysis result obtained from the correlation analysis to the target platform. The second analysis result indicates the correlation between the at least one third feature and the abnormal behavior. The second analysis result is used to train the third identification model.
8. An anomaly response device, characterized in that, The anomaly response device includes: an acquisition module and a processing module; The acquisition module is used to acquire the first log information generated during the operation of the abnormal response device; The processing module is used to input the first log information acquired by the acquisition module into the first recognition model, extract features based on the first log information through the first recognition model to obtain a first feature, and perform anomaly recognition based on the first feature through the first recognition model, and execute an anomaly response operation corresponding to the anomaly when an anomaly behavior is detected. The first identification model is trained using features from at least one type of sample log information.
9. An anomaly response device, characterized in that, The anomaly response device includes: a receiving module, a processing module, and a sending module; The receiving module is configured to receive at least one event data from at least one client device, each event data including log information generated during the operation of a client device; The processing module is used to input at least one log information received by the receiving module into a third identification model, extract features based on the at least one log information through the third identification model to obtain at least one third feature, and perform anomaly identification based on the at least one third feature through the third identification model. The sending module is used to send indication information to each client device when abnormal behavior is detected. The indication information is used to instruct the execution of a first operation corresponding to the abnormal behavior. The third identification model is trained using features from at least two types of sample log information. The first operation includes at least one of the following: Implement a global defense strategy; Adjust firewall rules; Update security policies.
10. An electronic device, characterized in that, The device includes a processor and a memory, the processor being coupled to the memory; the memory is used to store computer instructions, which are loaded and executed by the processor to enable the computer device to implement the exception response method as described in any one of claims 1 to 5, or to implement the exception response method as described in any one of claims 6 to 7.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions that, when executed on a computer, cause the computer to perform an exception response method as described in any one of claims 1 to 5, or to perform an exception response method as described in any one of claims 6 to 7.
12. A computer program product, characterized in that, The computer program product includes a computer program that, when run on an electronic device, causes the electronic device to perform an anomaly response method as described in any one of claims 1 to 5, or to perform an anomaly response method as described in any one of claims 6 to 7.