Alarm strategy generation method and device, equipment and medium

By obtaining alarm information categories, generating query statements, and processing them using artificial intelligence models, the problems of low efficiency and poor accuracy in alarm strategy generation in existing technologies are solved. This achieves automated alarm strategy generation, improves efficiency and accuracy, and reduces enterprise risk.

CN121441718APending Publication Date: 2026-01-30BEIJING YOUTEJIE INFORMATION TECH
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202511549071.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-28
Publication Date
2026-01-30

AI Technical Summary

Technical Problem

Existing alarm handling methods cannot automatically generate alarm policies, resulting in high human resource consumption and low accuracy and feasibility of alarm policies. In particular, they are difficult to respond quickly in complex attack scenarios, increasing enterprise risks.

Method used

By acquiring target alarm information and its category, a matching query statement is generated, and a pre-trained artificial intelligence model is used to process the alarm information to generate a target alarm strategy.

Benefits of technology

It enables the automated generation of alarm policies, improving generation efficiency, saving human resources, increasing the correctness and feasibility of policies, reducing response time, and lowering enterprise risk.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121441718A_ABST
    Figure CN121441718A_ABST
Patent Text Reader

Abstract

The invention discloses an alarm strategy generation method and device, equipment and a medium. The method comprises the following steps: acquiring target alarm information and an alarm category of the target alarm information; generating a target query statement matched with the alarm information according to the alarm category; and processing the target alarm information and the target query statement by using a pre-trained artificial intelligence model to obtain a target alarm strategy matched with the target alarm information. Through the technical scheme of the invention, the generation of the alarm strategy for the alarm information can be realized, the generation efficiency of the alarm strategy is improved, and the correctness and feasibility of the alarm strategy are improved while human resources are saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing, and in particular to a method, apparatus, device, and medium for generating alarm strategies. Background Technology

[0002] In today's cyber environment, the complexity of security threats is increasing daily, and enterprises are bearing the brunt of massive security incidents and alerts. Most of this information converges on Security Information and Event Management (SIEM) platforms. While SIEM platforms do possess powerful data processing capabilities, efficiently collecting various log data and performing correlation and analysis, the sheer volume of alerts generated by these platforms is enormous, and their quality varies greatly. A large number of redundant, low-value alerts flood the platform, overwhelming analysts in security operations centers and placing them under immense pressure.

[0003] Currently, analysts primarily handle alerts manually, requiring investigation, tracing, and analysis for each alert. This method is not only extremely inefficient but also highly dependent on the analyst's personal experience and expertise. In practice, attack scenarios are constantly evolving. When analysts face unfamiliar or complex attack scenarios, relying solely on manual investigation makes it difficult to make accurate judgments in a timely manner. In such cases, analysts may need to spend a significant amount of time, based on their personal experience and knowledge, to trace attack paths and analyze attack characteristics, which undoubtedly prolongs the response time to alerts. This extended response time translates to increased potential business risks for enterprises. Attackers may use this time to further expand their attack scope, steal critical business data, disrupt normal system operations, and cause incalculable losses to the enterprise. For example, in financial institutions, if attackers manage to penetrate the system undetected for an extended period, they may tamper with transaction data, steal customer funds, and severely damage the company's reputation and economic interests.

[0004] In summary, existing alarm handling methods suffer from several drawbacks, including the inability to automatically generate alarm strategies based on alarm information, high human resource consumption, and low accuracy and feasibility of alarm strategies. Summary of the Invention

[0005] This invention provides a method, apparatus, device, and medium for generating alarm strategies, which can solve the problems of existing alarm processing methods that cannot automatically generate alarm strategies based on alarm information, consume a lot of human resources, and have low accuracy and feasibility of alarm strategies.

[0006] In a first aspect, embodiments of the present invention provide a method for generating an alarm policy, the method comprising:

[0007] Obtain the target alarm information and the alarm category of the target alarm information;

[0008] Generate a target query statement that matches the alarm information based on the alarm category;

[0009] The target alarm information and target query statement are processed using a pre-trained artificial intelligence model to obtain a target alarm strategy that matches the target alarm information.

[0010] Secondly, embodiments of the present invention provide an alarm policy generation apparatus, the apparatus comprising:

[0011] The data acquisition module is used to acquire target alarm information and the alarm category of the target alarm information;

[0012] The statement generation module is used to generate a target query statement that matches the alarm information based on the alarm category;

[0013] The strategy generation module is used to process the target alarm information and target query statement using a pre-trained artificial intelligence model to obtain a target alarm strategy that matches the target alarm information.

[0014] Thirdly, embodiments of the present invention provide an electronic device, the electronic device comprising:

[0015] At least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform a method for generating an alarm strategy according to any embodiment of the present invention.

[0018] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer instructions, which are used to cause a processor to execute and implement a method for generating an alarm strategy as described in any embodiment of the present invention.

[0019] The technical solution of this invention obtains target alarm information and the alarm category of the target alarm information, then generates a target query statement matching the alarm information based on the alarm category, and finally uses a pre-trained artificial intelligence model to process the target alarm information and the target query statement to obtain a target alarm strategy matching the target alarm information. This solves the problems of existing alarm processing methods, such as the inability to automatically generate alarm strategies for alarm information, high manpower consumption, and low accuracy and feasibility of alarm strategies. It realizes the generation of alarm strategies for alarm information, improves the generation efficiency of alarm strategies, saves manpower, and increases the accuracy and feasibility of alarm strategies.

[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a flowchart of a method for generating an alarm strategy according to Embodiment 1 of the present invention;

[0023] Figure 2 This is a flowchart of a method for generating an alarm strategy according to Embodiment 2 of the present invention;

[0024] Figure 3 This is a schematic diagram of the structure of an alarm strategy generation device provided in Embodiment 3 of the present invention;

[0025] Figure 4 This is a schematic diagram of the structure of an electronic device that implements a method for generating an alarm strategy according to an embodiment of the present invention. Detailed Implementation

[0026] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, any variations of the terms "comprising" and "having" are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0028] Example 1

[0029] Figure 1 This is a flowchart of an alarm policy generation method provided in Embodiment 1 of the present invention. This embodiment is applicable to the generation of alarm policies for alarm information of security information and event management platform. The method can be executed by an alarm policy generation device, which can be implemented in hardware and / or software. The alarm policy generation device can be configured in a terminal or server with alarm policy generation function.

[0030] like Figure 1 As shown, the method includes:

[0031] S110. Obtain the target alarm information and the alarm category of the target alarm information.

[0032] The target alarm information includes at least one key entity, which includes at least one of the following: IP address, domain name, hostname, email address, file hash value, vulnerability name and number, user account, process name, file path, and port number.

[0033] In this embodiment, the target alarm information can originate from a Security Information and Event Management (SIEM) platform. This platform aggregates log data generated by various devices in the enterprise network, such as firewalls, servers, terminal devices, and IDS / IPS. After preliminary correlation analysis, it generates security alarms, which are then received in real time by the alarm collector in the alarm receiving and preprocessing module to determine the target alarm information to be investigated. Furthermore, the Security Information and Event Management platform is a network security management system that integrates log collection, correlation analysis, alarm generation, and security monitoring. It helps enterprises perceive security anomalies in the network in real time and is one of the core tools for current enterprise network security operations.

[0034] The alarm categories specifically include: network type alarms, terminal type alarms, phishing email type alarms, and identity security type alarms.

[0035] S120. Generate a target query statement that matches the alarm information according to the alarm category.

[0036] The step of generating a target query statement that matches the alarm information based on the alarm category includes: finding a target statement template that matches the alarm category in a pre-set statement template table based on the alarm category; filling the target statement template with each key entity in the target alarm information as a parameter to generate the target query statement.

[0037] The statement template table is a structured collection of templates pre-built in the query template manager of the tool orchestration module. Its core is the categorization and storage of alerts by type and statement template. Different alert types correspond to different statement templates. For example, network type alerts (such as malicious IP connections or DDoS attacks) typically require querying firewall logs or network traffic logs; therefore, the statement template table will be configured with index=network_traffic | time_range = for this type of alert.<start_time> to<end_time> | filter src_ip =<src_ip> and dest_ip =<dest_ip> | Fields src_ip, dest_ip, protocol, port, etc., are network traffic log templates; furthermore, after obtaining the corresponding target statement template, the key entities in the target alarm information extracted by S110 are used as variable values ​​to fill the placeholders in the target statement template. These placeholders are designed to correspond one-to-one with the key entity types, for example, in the template...<start_time><end_time> The corresponding time range for alarm occurrence.<src_ip><dest_ip> Based on the IP addresses and other information in the corresponding key entities, a target query statement matching the alarm information is generated. Furthermore, the target query statement is used to call SIEM's log query tool to obtain network communication data between two IPs within a specified time range.

[0038] Optionally, after generating a target query statement matching the alarm information based on the alarm category, the method further includes: performing a syntax check on the target query statement based on preset log query syntax rules to obtain a check result; if the check result is incorrect, then returning to execute the operation of generating a target query statement matching the alarm information based on the alarm category.

[0039] The preset log query syntax rules are based on a validation standard formulated according to the query syntax supported by the SIEM platform, including field validity validation, syntax format validation, and parameter type validation of the target query statement. Those skilled in the art should understand that using the API gateway or tool adapter in the orchestration module of the SIEM platform to perform syntax validation on the target query statement is a mature existing technology, and its principles and specific steps will not be elaborated upon in this embodiment.

[0040] S130. The target alarm information and target query statement are processed using a pre-trained artificial intelligence model to obtain a target alarm strategy that matches the target alarm information.

[0041] The technical solution of this invention obtains target alarm information and the alarm category of the target alarm information, then generates a target query statement matching the alarm information based on the alarm category, and finally uses a pre-trained artificial intelligence model to process the target alarm information and the target query statement to obtain a target alarm strategy matching the target alarm information. This solves the problems of existing alarm processing methods, such as the inability to automatically generate alarm strategies for alarm information, high manpower consumption, and low accuracy and feasibility of alarm strategies. It realizes the generation of alarm strategies for alarm information, improves the generation efficiency of alarm strategies, saves manpower, and increases the accuracy and feasibility of alarm strategies.

[0042] Example 2

[0043] Figure 2 This is a flowchart of a method for generating an alarm strategy according to Embodiment 2 of the present invention. This embodiment is a refinement based on the above embodiment. Specifically, this embodiment refines the method of using a pre-trained artificial intelligence model to process the target alarm information and the target query statement to obtain a target alarm strategy that matches the target alarm information.

[0044] like Figure 2 As shown, the method includes:

[0045] S210. Obtain the target alarm information and the alarm category of the target alarm information.

[0046] S220. Generate a target query statement that matches the alarm information according to the alarm category.

[0047] S230. The target alarm information and the preset entity guidance template are input into the entity module of the artificial intelligence model for processing to obtain each key entity that matches the target alarm information.

[0048] The artificial intelligence model includes: an entity module, a question module, an investigation module, and a comprehensive judgment module connected in sequence.

[0049] The entity guidance template is a pre-configured instruction template used to guide the model in accurately extracting information. This template ensures that the entity module extracts information according to the professional dimensions of a security investigation, avoiding the omission of key elements. In actual execution, the target alarm information must first undergo standardized processing by the alarm receiving and preprocessing module before being input into the entity module of the artificial intelligence model along with the entity guidance template. Furthermore, the entity module incorporates a large-scale language model invocation engine, which performs semantic understanding and analysis of the alarm information and guidance template based on the large-scale language model, ultimately outputting a structured list of key entities.

[0050] S240. Input each key entity, the preset problem guidance template, and the pre-configured interface tool mapping table into the problem module for processing to obtain tool suggestions matching the target alarm information and at least one auxiliary problem.

[0051] The question guidance template predefines the dimensions and professional requirements for generating investigation questions, ensuring that the generated auxiliary questions comprehensively cover the core dimensions of the security investigation and avoid blind spots. Furthermore, the pre-configured interface tool mapping table is the core data asset of the tool orchestration module, recording the association between various security tools (such as SIEM alarm query tools, asset information query tools, threat intelligence query tools, etc.) and their corresponding calling interfaces, while also indicating the applicable investigation scenarios for each tool. During execution, the question module first receives the key entities output by S230, and, combined with the dimensional requirements of the question guidance template, generates at least one auxiliary question matching the target alarm information. Simultaneously, the question module refers to the interface tool mapping table, matches corresponding tool suggestions based on the investigation scenario of the auxiliary questions, and finally outputs a list of associations between auxiliary questions and tool suggestions.

[0052] S250. Input each auxiliary question, target query statement, and the tool suggestion into the survey module, so that the survey module determines the target interface based on the target query statement and tool suggestion, obtains target data through the target interface, and obtains each target question strategy matching each auxiliary question based on the target data and the preset survey guidance template.

[0053] Based on the above steps, the investigation module first receives the auxiliary questions output by S240, the target query statement generated by S120, and the corresponding tool suggestions. Then, the investigation module matches the corresponding target interface in the interface tool mapping table based on the tool suggestions, passes the target query statement as a parameter to the target interface, and simultaneously initiates a data request to the SIEM platform to obtain target data related to the auxiliary questions. After obtaining the target data, the investigation module interprets and analyzes the target data using a preset investigation guidance template to form target question strategies for each auxiliary question. For example, regarding the auxiliary question of whether the victim host has abnormal network connections, if the target data shows that the host communicated with a malicious IP multiple times during the alarm period, the corresponding target question strategy is that the victim host had 12 abnormal TCP connections with a malicious IP during the alarm period, with the connection port being the malicious port 4444. This connection behavior is deemed abnormal, and further investigation of the communication content is required. Such strategies must clearly include data conclusions, judgment criteria, and subsequent investigation directions.

[0054] S260. The comprehensive analysis module and the preset analysis guidance template are used to perform a comprehensive analysis operation on each target problem strategy to obtain the analysis results of each target that match each target problem strategy. Based on the analysis results of each target and each target problem strategy, a target alarm strategy that matches the target alarm information is generated.

[0055] The process involves performing a comprehensive analysis of each target problem strategy using the comprehensive analysis module and a preset analysis guidance template to obtain target analysis results that match each target problem strategy. This includes: using the comprehensive analysis module to search for historical alarm data with a similarity greater than a preset threshold to the target alarm information; after finding at least one historical alarm data, obtaining each historical alarm strategy that matches each historical data; and inputting each historical alarm strategy, the target alarm information, and each target problem strategy into the comprehensive analysis module to obtain target analysis results that match each target problem strategy.

[0056] Furthermore, the preset analysis guidance template is used to define the output requirements of the comprehensive analysis to ensure that the analysis results are professional, interpretable, and traceable.

[0057] Specifically, the target assessment results are obtained through the comprehensive assessment module and the assessment guidance template. This includes: First, the comprehensive assessment module calls a pre-configured search engine to retrieve historical alarm data stored in the knowledge graph manager. A case similarity calculator is used to determine if there are historical alarm data with a similarity greater than a preset threshold to the target alarm information. The similarity is calculated based on dimensions such as key entities, alarm categories, and attack characteristics. If at least one historical alarm data matching the criteria is retrieved, historical alarm strategies matching these historical data are further obtained. Subsequently, the comprehensive assessment module inputs each historical alarm strategy, the target alarm information, and each target problem strategy together, and performs a fusion analysis based on a large language model and the assessment guidance template. If the strategy of a similar historical alarm is determined to be malicious and the handling solution is effective, and the current target problem strategy also shows multiple abnormal characteristics, the comprehensive assessment module outputs the target assessment results corresponding to each target problem strategy. After obtaining all target assessment results, the comprehensive assessment module will integrate the assessment results of each target with the corresponding target problem strategy, evaluate the threat level, impact scope and response priority of the target alarm from an overall perspective, and finally generate a target alarm strategy that matches the target alarm information.

[0058] It should be noted that, based on the above steps, the specific content of the entity guidance template, question guidance template, investigation guidance template, and analysis guidance template can be set and adjusted by relevant personnel according to the needs of the actual implementation scenario. This embodiment does not limit their specific content.

[0059] The technical solution of this invention involves acquiring target alarm information and the alarm category of the target alarm information, then generating a target query statement matching the alarm information based on the alarm category. Next, the target alarm information and a preset entity guidance template are input into the entity module of the artificial intelligence model for processing to obtain key entities matching the target alarm information. Then, each key entity, a preset question guidance template, and a pre-configured interface tool mapping table are input into the question module for processing to obtain tool suggestions matching the target alarm information and at least one auxiliary question. Finally, each auxiliary question, the target query statement, and the tool suggestions are input into the investigation module to enable... The investigation module determines the target interface based on the target query statement and tool suggestions, obtains target data through the target interface, and obtains target question strategies matching each auxiliary question based on the target data and a preset investigation guidance template. Then, the comprehensive judgment module and a preset judgment guidance template perform a comprehensive judgment operation on each target question strategy to obtain target judgment results matching each target question strategy. Based on each target judgment result and each target question strategy, a target alarm strategy matching the target alarm information is generated. This realizes the generation of alarm strategies for alarm information, improves the generation efficiency of alarm strategies, saves human resources, and increases the correctness and feasibility of alarm strategies.

[0060] Specific implementation scenarios

[0061] To more clearly illustrate the technical solutions provided by the embodiments of the present invention, this embodiment will briefly introduce a specific implementation scenario obtained according to this embodiment.

[0062] Assume an internet company's security operations center has deployed a Security Information and Event Management (SIEM) platform. On October 18, 2025, at 14:30, the SIEM platform collected a terminal alarm message. Under the above conditions, the alarm policy generation method described in this embodiment performs the following steps:

[0063] Step 1: Obtain target alarm information and alarm category. The target alarm information includes: alarm time (2025-10-18 14:28:15), alarm name (malicious file execution behavior on the terminal), associated host name (PC-2025-08-01-Lee), executable file path (C:\Users\Lee\Downloads\update.exe), file SHA256 hash value (a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234567890), executing process name (update.exe), associated user account (Lee), and the alarm category is determined to be a terminal-type alarm.

[0064] Step Two: Generate the target query statement and perform syntax validation. Based on the terminal type alarm category, the system proceeds to the target query statement generation process: The first step is to find the target statement template. Using the log query template, the matched Windows event log query template is: index=windows_events | time_range =<start_time> to<end_time> | filter hostname = <hostname>and process_name = <process_name> |fields event_id, event_time, process_path, user, file_hash, the template is completely matched with the process execution log demand of the terminal alarm to be queried. The second step is to fill in the key entity parameters. The key entities (start_time = 2025-10-18 14:25:00, end_time = 2025-10-18 14:30:00, hostname = PC-2025-08-01-Lee, process_name = update.exe, file_hash = a1b2c3d4e5f6...) in the target alarm information are filled in as parameters in the template placeholders, and the target query statement is initially generated.

[0065] Then, a syntax checking operation is performed. The generated query statement is checked through a preset log query syntax rule. It is found that the file_hash field in the initial statement is actually named file_sha256 in the windows_events index. The checking result is an error. The system immediately returns to the step of generating the target query statement according to the alarm category. After the field name is modified to file_sha256, the query statement is regenerated. The checking is passed again, and the final executable target query statement is obtained.

[0066] Step three: pre-trained artificial intelligence model processing, the specific processing process is as follows:

[0067] 1) Entity module extracts key entities: input the target alarm information and the preset entity guide template into the entity module, wherein the content of the entity guide template is as follows: you are a security expert, please extract key entities from the following alarm information, types include IP address, host name, file hash, process name, file path, user account, output in JSON format. The entity module triggers the large language model analysis through the AI inference engine large language model calling engine, and finally outputs a structured key entity list.

[0068] 2) Problem module generates auxiliary questions and tool suggestions: input the above key entities, preset question guide templates, and pre-configured interface tool mapping tables into the problem module, wherein the question guide template is: for terminal type alarm and extracted key entities, generate 6 auxiliary questions covering attack impact, file maliciousness, and process behavior, and match SIEM platform interface tools. After reasoning by the large language model, the problem module outputs auxiliary questions and tool suggestions. The final auxiliary questions include: ① Is the file hash value (a1b2c3d4e5f6...) involved in the alarm marked as malicious in the threat intelligence library? ② Does the host PC-2025-08-01-Lee have abnormal sub-processes of the process during the alarm period? ③ Does the user Lee have operation records of actively downloading the file? The tool suggestion is: for question ①, call the check_file_reputation interface (threat intelligence query tool), for question ②, call the query_windows_events interface (terminal log query tool), and for question ③, call the get_user_behavior interface (user behavior query tool).

[0069] 3) The investigation module obtains target data and target problem strategy: the auxiliary problem, the aforementioned target query statement passed through the check, and the tool suggestion are input into the investigation module. The investigation module matches the target interface based on the tool suggestion: for question 1, the check file reputation interface is called, the file hash value is input, and the target data is obtained: the hash value is associated with the ransomware family 'LockBit', and 12 enterprises have reported that the file launched an encryption attack within the past 7 days; for question 2, the target query statement is executed, the query windows events interface is called, and the target data is obtained: 'update.exe' generated 3 abnormal sub-processes (cmd.exe, regedit.exe) during the alarm period, and there is a behavior of modifying the registry 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'; for question 3, the get user behavior interface is called, and the target data is obtained: the user 'Lee' downloaded the file through a phishing email attachment at 14:27, and there is no active execution record. The investigation module analyzes the above target data in combination with a preset investigation guide template to generate a target problem strategy, and the investigation guide template can be specifically: please generate the corresponding query execution statement according to the following questions and the available security investigation tools. Please ensure that the statement can be directly run in SIEM or other integrated tools. Tool list and description: query_logs(index, time_range, filters), get_asset_info(hostname), check_ip_reputation(ip)]. The final target problem strategy obtained is as follows: 1) The file hash value is associated with a malicious ransomware, and the file execution needs to be blocked as a priority; 2) The process has a persistent behavior (modifying the registry), and the malicious process and registry item need to be cleaned up; 3) The user is infected due to a phishing email, and the user's mailbox and the phishing risk of other accounts in the same department need to be investigated.

[0070] 4) The comprehensive research and judgment module generates target research and judgment results and target alarm strategies: input each target problem strategy into the comprehensive research and judgment module, and simultaneously input a preset research and judgment guide template; wherein, the research and judgment guide template is: in combination with target alarm information, target problem strategies and historical alarm data, judging the threat level of each strategy, and finally generating an alarm strategy containing a disposal suggestion. First, the comprehensive research and judgment module calls the retrieval engine and case similarity calculator of the knowledge management module, retrieves historical alarm data, finds that there was an alarm with a similarity of 92% three months ago, then obtains the historical alarm strategy of the historical alarm: isolate the victim host → terminate malicious processes → clean the registry → notify the user to modify the password → investigate the hosts in the same network segment, and no attack spread occurred after the execution of the strategy. Subsequently, the comprehensive research and judgment module inputs the historical alarm strategy, the current target alarm information and each target problem strategy into the large language model, and generates the target research and judgment results through reasoning: ① problem strategy ① threat level high risk; ② problem strategy ② threat level medium-high risk; ③ problem strategy ③ threat level medium risk. Finally, the comprehensive research and judgment module integrates each target research and judgment result and target problem strategy to generate a target alarm strategy: immediately isolate the host PC-2025-08-01-Lee, prohibit it from accessing the enterprise intranet; terminate update.exe and child processes through EDR tools, notify the user Lee to modify the domain account password and email password, call the SIEM platform asset query interface, investigate whether there are 20 terminals in the same department with the same file hash value, if there are, repeat the emergency disposal steps, add the file hash value a1b2c3d4e5f6... to the EDR blacklist, and monitor whether there is a download or execution behavior of the file in the enterprise. The target alarm strategy is finally written back to the SIEM platform, and stored as a historical alarm strategy in the SIEM platform.

[0071] Embodiment three

[0072] Figure 3 A structural schematic diagram of an alarm strategy generation device provided for embodiment three of the application. As shown in the figure, Figure 3 the device comprises:

[0073] A data acquisition module 310 is configured to acquire target alarm information and an alarm category of the target alarm information.

[0074] A sentence generation module 320 is configured to generate a target query statement matched with the alarm information according to the alarm category.

[0075] A strategy generation module 330 is configured to process the target alarm information and the target query statement using a pre-trained artificial intelligence model to obtain a target alarm strategy matched with the target alarm information.

[0076] The technical scheme of the embodiment of the present application obtains target alarm information and an alarm category of the target alarm information, then generates a target query statement matched with the alarm information according to the alarm category, and finally processes the target alarm information and the target query statement by using a pre-trained artificial intelligence model to obtain a target alarm strategy matched with the target alarm information, thereby solving the problems of the existing alarm processing mode, such as the incapability of automatically generating an alarm strategy for alarm information, large consumption of human resources, and low correctness and feasibility of the alarm strategy, and realizing the generation of an alarm strategy for alarm information, improving the generation efficiency of the alarm strategy, saving human resources, and increasing the correctness and feasibility of the alarm strategy.

[0077] On the basis of the above embodiment, the sentence generation module 320 comprises:

[0078] The template matching unit is configured to search a pre-set sentence template table according to the alarm category to obtain a target sentence template matched with the alarm category.

[0079] The parameter filling unit is configured to fill each key entity in the target alarm information into the target sentence template as a parameter to generate the target query statement.

[0080] On the basis of the above embodiment, the strategy generation module 330 comprises:

[0081] The first guide processing unit is configured to input the target alarm information and a pre-set entity guide template into an entity module of the artificial intelligence model for processing to obtain each key entity matched with the target alarm information.

[0082] The second guide processing unit is configured to input each key entity, a pre-set question guide template, and a pre-configured interface tool mapping table into the question module for processing to obtain a tool suggestion and at least one auxiliary question matched with the target alarm information.

[0083] The third guide processing unit is configured to input each auxiliary question, the target query statement, and the tool suggestion into the investigation module, so that the investigation module determines a target interface based on the target query statement and the tool suggestion, acquires target data through the target interface, and obtains each target question strategy matched with each auxiliary question based on the target data and a pre-set investigation guide template.

[0084] The fourth guide processing unit is configured to perform comprehensive research and judgment operation on each target question strategy by the comprehensive research and judgment module and a pre-set research and judgment guide template to obtain each target research and judgment result matched with each target question strategy, and generate a target alarm strategy matched with the target alarm information based on each target research and judgment result and each target question strategy.

[0085] On the basis of the above-mentioned embodiments, the fourth guidance processing unit comprises:

[0086] The historical data retrieval unit is configured to retrieve, by the comprehensive analysis module, whether there is historical alarm data with a similarity to the target alarm information greater than a preset threshold;

[0087] The historical strategy acquisition unit is configured to, after retrieving that there is at least one historical alarm data, acquire each historical alarm strategy matched with each historical data;

[0088] The comprehensive analysis unit is configured to input each historical alarm strategy, the target alarm information and each target problem strategy into the comprehensive analysis module to obtain each target analysis result matched with each target problem strategy.

[0089] On the basis of the above-mentioned embodiments, the sentence generation module 320 is further configured to, after generating the target query sentence matched with the alarm information according to the alarm category, perform a syntax checking operation on the target query sentence based on a preset log query syntax rule to obtain a checking result; and if the checking result is an error, return to perform the operation of generating the target query sentence matched with the alarm information according to the alarm category.

[0090] The alarm strategy generation device provided in the embodiments of the present application can execute the alarm strategy generation method provided in any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of the execution method.

[0091] Embodiment Four

[0092] Figure 4 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.

[0093] As Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded into the RAM 13 from storage unit 18. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0094] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0095] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as a method for generating an alarm policy.

[0096] Accordingly, the method includes:

[0097] Obtain the target alarm information and the alarm category of the target alarm information;

[0098] Generate a target query statement that matches the alarm information based on the alarm category;

[0099] The target alarm information and target query statement are processed using a pre-trained artificial intelligence model to obtain a target alarm strategy that matches the target alarm information.

[0100] In some embodiments, a method for generating an alarm policy may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the method for generating an alarm policy described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform a method for generating an alarm policy by any other suitable means (e.g., by means of firmware).

[0101] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0102] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0103] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0104] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0105] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0106] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0107] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.< / hostname>

Claims

1. A method for generating an alarm strategy, characterized in that, The method comprises the following steps: obtaining target alarm information and an alarm category of the target alarm information; generating a target query statement matched with the alarm information according to the alarm category; processing the target alarm information and the target query statement by using a pre-trained artificial intelligence model to obtain a target alarm strategy matched with the target alarm information.

2. The method of claim 1, wherein, The target alarm information comprises at least one key entity, and the key entity comprises at least one of an IP address, a domain name, a host name, an email address, a file hash value, a vulnerability name and number, a user account, a process name, a file path and a port number.

3. The method according to any of claims 1-2, characterized by, The method comprises the following steps: finding a target statement template matched with the alarm category in a pre-set statement template table according to the alarm category; filling each key entity in the target alarm information into the target statement template as a parameter to generate the target query statement.

4. The method of claim 1, wherein, The artificial intelligence model comprises an entity module, a question module, an investigation module and a comprehensive research and judgment module connected in sequence.

5. The method according to any one of claims 1 to 4, characterized in that, The method comprises the following steps: inputting the target alarm information and a pre-set entity guide template into the entity module of the artificial intelligence model to process and obtain each key entity matched with the target alarm information; inputting each key entity, a pre-set question guide template and a pre-configured interface tool mapping table into the question module to process and obtain a tool suggestion and at least one auxiliary question matched with the target alarm information; inputting each auxiliary question, the target query statement and the tool suggestion into the investigation module to enable the investigation module to determine a target interface based on the target query statement and the tool suggestion, acquire target data through the target interface, and obtain each target question strategy matched with each auxiliary question based on the target data and a pre-set investigation guide template; performing comprehensive research and judgment operations on each target question strategy by the comprehensive research and judgment module and a pre-set research and judgment guide template to obtain each target research and judgment result matched with each target question strategy, and generating a target alarm strategy matched with the target alarm information based on each target research and judgment result and each target question strategy.

6. The method of claim 5, wherein, The method comprises the following steps: searching, by the comprehensive research and judgment module, whether there is historical alarm data with a similarity greater than a pre-set threshold to the target alarm information; after searching that there is at least one historical alarm data, acquiring each historical alarm strategy matched with each historical data; inputting each historical alarm strategy, the target alarm information and each target question strategy into the comprehensive research and judgment module to obtain each target research and judgment result matched with each target question strategy.

7. The method of claim 1, wherein, After generating the target query statement matched with the alarm information according to the alarm category, the method further comprises the following steps: The target query statement is subjected to a syntax checking operation based on a preset log query syntax rule, and a checking result is obtained; If the checking result is incorrect, an operation of generating a target query statement matching the alarm information according to the alarm category is returned.

8. An alarm strategy generation apparatus, characterized in that, Comprise: A data acquisition module configured to acquire target alarm information and an alarm category of the target alarm information; A statement generation module configured to generate a target query statement matching the alarm information according to the alarm category; A strategy generation module configured to process the target alarm information and the target query statement using a pre-trained artificial intelligence model to obtain a target alarm strategy matching the target alarm information.

9. An electronic device, comprising: The electronic device comprises: At least one processor; and A memory connected in communication with the at least one processor; wherein The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the alarm strategy generation method of any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for causing the processor to execute the alarm strategy generation method of any one of claims 1-7 when executed.

Citation Information

Patent Citations

  • Alarm processing method and device based on micro-service and electronic device

    CN110943851A

  • Network attack analysis method and device, readable storage medium and computer equipment

    CN112351008A

  • Method and device for monitoring operation of server

    CN114816945A

  • Alarm analysis method and device, electronic equipment and storage medium

    CN115150261A

  • Alarm processing method and device and electronic equipment

    CN115629945A