Network attack source positioning method and device

By accurately filtering alarm information and analyzing external traffic in the bank's network security system, the source of network attacks can be quickly located, solving the problem of low monitoring and early warning efficiency in bank network security protection technology, and achieving efficient identification and isolation of network attacks.

CN121509062APending Publication Date: 2026-02-10中国建设银行股份有限公司湖北省分行
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511850271.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-09
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

The bank's cybersecurity defense system is inadequate in areas such as advanced threat identification, traffic monitoring, data analysis, collaborative defense, and human response efficiency, resulting in low cybersecurity protection efficiency and increasing the risk of cyberattacks.

Method used

By filtering received alarm information using preset rules and utilizing the logs of external traffic monitoring devices and address translation servers, the source address corresponding to the alarm report can be determined, enabling rapid location of the network attack source and isolation of user devices.

Benefits of technology

Effectively eliminate false alarms, improve the quality and efficiency of alarm information processing, shorten the time from detection to response, and enhance the ability to perceive network security situation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509062A_ABST
    Figure CN121509062A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network attack source positioning method and device. The method comprises the following steps: screening received alarm information according to a preset rule, and determining an alarm report; determining a conversion source address corresponding to the alarm report according to the external connection flow; and positioning a network attack source and affected user equipment according to the alarm report and the conversion source address. Through the embodiment of the invention, the problem of low monitoring and early warning efficiency of the network security protection technology in the related technology is solved, and the effect of improving the perception capability of the overall network security situation is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a network attack source positioning method and device. BACKGROUND

[0002] With the rapid development of digital economy, network security has become a key issue in bank operation. The security of bank information system is related to the safety of customers' funds and the stable operation of the bank. However, the existing bank network security defense system has many problems, especially in advanced threat identification, traffic monitoring, data analysis, collaborative defense and artificial response efficiency, which shows obvious shortcomings, for example: advanced threat identification lags behind, traffic monitoring capability is insufficient, massive data analysis capability is insufficient, multi-system collaborative defense is weak, artificial response efficiency is low, etc.

[0003] These deficiencies reduce the overall efficiency of network security protection and increase the risk of network attacks faced by banks. Therefore, a technical solution is needed to overcome these defects to improve the monitoring and early warning efficiency and emergency response speed of bank network and data security, and to ensure the security, stability and compliance of the business system. SUMMARY

[0004] The embodiments of the present application provide a network attack source positioning method and device to at least solve the problem of low monitoring and early warning efficiency of network security protection technology in related technologies.

[0005] According to an embodiment of the present application, a network attack source positioning method is provided, comprising: screening received alarm information according to a preset rule to determine an alarm report; determining a conversion source address corresponding to the alarm report according to external traffic; and positioning a network attack source and affected user equipment according to the alarm report and the conversion source address.

[0006] In one embodiment, before screening received alarm information according to a preset rule to determine an alarm report, the method further comprises: monitoring and analyzing system traffic according to the log of a network traffic monitoring device to determine the alarm information.

[0007] In one embodiment, the preset rule includes exclusion rules and matching rules, and screening received alarm information according to a preset rule to determine an alarm report comprises: deleting false alarm information in the alarm information according to the exclusion rules to obtain true alarm information; and screening alarm information corresponding to a target abnormal level from the true alarm information according to the matching rules to determine the alarm report.

[0008] In one embodiment, the exclusion rule is a rule defined based on the contextual characteristics of historical alarm information and historical business operation experience.

[0009] In one embodiment, the matching rule is a rule defined based on the severity threshold, impact range threshold, and correlation characteristics corresponding to the alarm information.

[0010] In one embodiment, after locating the source of the network attack and the affected user equipment based on the alarm report and the source address of the conversion, the method further includes: forwarding the alarm report to the affected user equipment according to a multi-channel mechanism, and blocking the source of the network attack.

[0011] According to another embodiment of the present invention, a device for locating the source of a network attack is provided, comprising: a filtering module for filtering received alarm information according to preset rules to determine alarm reports; a determining module for determining the conversion source address corresponding to the alarm report based on external traffic; and a locating module for locating the source of the network attack and the affected user equipment based on the alarm report and the conversion source address.

[0012] According to yet another embodiment of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored therein, wherein the computer program, when executed by a processor, implements the steps in any of the above method embodiments.

[0013] According to yet another embodiment of the present invention, an electronic device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps in any of the above method embodiments.

[0014] According to yet another embodiment of the present invention, a computer program product is also provided, comprising a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0015] Through the above embodiments of the present invention, received alarm information is accurately filtered according to preset rules, effectively eliminating false alarms and improving the quality and processing efficiency of alarm information. By utilizing external traffic logs to determine the source address of the attack and deeply analyzing the attack path, rapid location of the network attack source is achieved. Furthermore, affected user devices can be quickly identified and isolated, significantly shortening the time from detection to response. Therefore, this invention can solve the problem of low monitoring and early warning efficiency in related network security protection technologies, thereby improving the overall network security situation awareness. Attached Figure Description

[0016] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0017] Figure 1 This is a hardware structure block diagram of a computer terminal for a method of locating the source of a network attack according to an embodiment of the present invention.

[0018] Figure 2 This is the network architecture of the branch network attack source location system according to an embodiment of the present invention;

[0019] Figure 3 This is a schematic diagram of the technical architecture for locating the source of a network attack according to an embodiment of the present invention;

[0020] Figure 4 This is a flowchart of a method for locating the source of a network attack according to an embodiment of the present invention;

[0021] Figure 5 This is a flowchart illustrating the alarm location analysis according to an embodiment of the present invention;

[0022] Figure 6 This is a schematic diagram of a multi-dimensional emergency notification process according to an embodiment of the present invention;

[0023] Figure 7 This is a schematic diagram of an automated blocking process according to an embodiment of the present invention;

[0024] Figure 8 This is a structural block diagram of a network attack source location device according to an embodiment of the present invention. Detailed Implementation

[0025] The present invention will be described in detail below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in the present application can be combined with each other.

[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0027] The method embodiment provided in Embodiment 1 of this application can be executed on a computer terminal or similar computing device. Taking running on a computer terminal as an example, Figure 1 This is a hardware structure block diagram of a computer terminal for a method of locating the source of a network attack according to an embodiment of the present invention. Figure 1 As shown, computer terminal 10 may include one or more ( Figure 1Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. Optionally, the computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the computer terminal described above. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0028] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the network attack source location method in this embodiment of the invention. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0029] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0030] The embodiments of the present invention can be run on a network attack source location system, which can be a network attack source location system for the head office or a network attack source location system for a branch.

[0031] Taking the branch network attack source location system as an example, Figure 2 This is the network architecture of the branch network attack source location system according to an embodiment of the present invention, such as... Figure 2 As shown, the system for locating the source of the network attack at this branch includes:

[0032] External Unit 21 refers to an external organization or system that has a direct or indirect connection with the branch's network attack source location system or network.

[0033] External entities may include, but are not limited to: other banks or financial institutions, regulatory agencies, third-party service providers, customer information systems, and information exchange platforms.

[0034] Network security device 22 is used to perform real-time monitoring and in-depth analysis of the bank's traffic based on logs from network traffic monitoring devices. It can initially identify potential security threats and generate alarm information, providing basic data support for subsequent alarm analysis services. Here, "the entire bank" means that the monitoring scope of network security device 22 covers all connection points between the bank's internal and external networks, ensuring comprehensive monitoring of the bank's overall network activities.

[0035] The alarm analysis server 23, also known as the branch alarm analysis server, is used to receive alarm information generated by network device 22, further process the data through the rule engine filtering function, filter out high-risk events and generate security alarm reports.

[0036] The core function of the rules engine is to establish a preset rule base based on the historical experience of regulators, the head office, and branches, and then to "filter" and "classify" alarms. That is, to eliminate false alarms through exclusionary rules and to identify high-risk events through matching rules.

[0037] 1) Exclusionary rules: These are defined based on the contextual characteristics and content matching of alarm information generated by network device 22, as well as industry operational experience. They include rules for the Internet zone, intranet zone, and external connection failure zone.

[0038] The Internet exclusion rules focus on filtering alerts originating from the Internet to avoid unnecessary false alarms. For example, Internet exclusion rules can be set to automatically exclude alerts whose event names contain "large packet bypass monitoring" or whose threat information mentions "private cloud traffic upload data capacity".

[0039] "Large packet bypass monitoring" typically refers to the detection of abnormally large data packets at the internet entry point. However, in some cases, such as large-scale data backups or normal data transmission in cloud services, such large traffic volumes are part of normal business operations and not malicious activity. "Private cloud traffic upload data volume," on the other hand, focuses on data transmission behavior in a private cloud environment. If analysis confirms that these large data uploads occur during pre-planned maintenance or upgrade operations, such alerts are considered normal and should not be counted as a security threat.

[0040] Internal network exclusion rules focus on activities within the bank's internal network. For example, internal network exclusion rules can be configured to treat alerts whose event names contain "login behavior," "denial of service," and "URL redirection" as feedback from routine operations rather than attack signals.

[0041] Among these, "login behavior" might be triggered by multiple login attempts by staff during work hours, which is usually a legitimate business need in an intranet environment. "Denial of service" might be caused by system maintenance operations in some cases; "URL redirection" might originate from users' normal browsing behavior between intranet websites. This exclusion rule allows the system to ignore alerts generated during routine business activities, reducing the time the security team spends dealing with invalid alerts and ensuring that resources are used to address genuine threats.

[0042] The external connectivity exclusion rules target network communications between the bank and external entities, i.e., the connection points between the bank and the internet or other financial institutions, suppliers, and partners. For example, the external connectivity exclusion rules can be set to automatically exclude alarms when the event name contains "large packet bypass monitoring" or "URL redirection," and the threat information is associated with "private cloud traffic upload data capacity" or "public cloud traffic upload data," while the data source originates from "UASS login" (Unified Identity Authentication System).

[0043] High-volume data transfers are extremely common in normal business dealings with cloud providers, and "URL redirection" may be due to the integration of a bank's website with third-party services. Once "UASS login" confirms the user's legitimacy, these actions are no longer considered potential attacks, but rather normal enterprise-level internet operations.

[0044] 2) Matching Rules: Based on the severity, scope of impact, and relevance of alarms, "hit rules" are defined. Matching rules include internet zone hit rules, intranet zone hit rules, and external connection zone hit rules.

[0045] Internet Zone Hit Rules: The system can preset a list, including known malicious or high-risk domains. If any alarm message mentions a domain on the list in the event details, it will be marked as a high-risk alarm, immediately triggering subsequent analysis and response processes.

[0046] Internal network zone hit rules: These are set for the internal network environment. For example, if the event name contains keywords such as "weak password", "proxy tool", or "directory traversal", or if the threat information description contains words such as "VPN tool discovered", "traversal", or "leakage of sensitive user information", it will be considered a high-risk alert.

[0047] External Connection Zone Hit Rules: For the interaction points between the bank and external networks, the system will also check the list. Once the alarm involves key high-risk domain names related to external connections, the system will immediately initiate the alarm process, assess the potential threat to the internal network, and take appropriate action.

[0048] External address translation server 24 is used to analyze the external traffic logs of the Network Address Translation (NAT) gateway, track source address alarms after translation in real time, provide key data support for accurate diagnosis of alarm analysis services, and enhance security response capabilities.

[0049] The hierarchical location server 25, by combining network traffic and historical databases, can quickly locate the source of the attack and the affected end users, branches and departments, providing accurate decision-making basis for emergency response.

[0050] Monitoring server 26, the branch system can be configured to provide monitoring services to receive reports generated by alarm analysis services. The branch will assign corresponding staff to monitor the server 24 / 7 and notify the branch network security administrator by telephone of the reported information, providing full-time support for the branch's security threat handling work.

[0051] The linked blocking server 27 supports automatic blocking of high-risk attack sources corresponding to high-risk alerts. This service can work in real time with the alert analysis service to quickly implement blocking and simultaneously send the blocking results to monitoring services and network and security personnel, providing data support for subsequent threat analysis and refined handling.

[0052] The multi-dimensional notification server 28 employs a multi-channel mechanism, including SMS, email, and employee-specific communication software, to ensure that information about security incidents can be quickly transmitted to relevant administrators, minimizing emergency response time, and is responsible for forwarding reports from the alarm analysis service.

[0053] This physical architecture integrates network equipment and service modules for branches and headquarters. Its modular design ensures the flexibility, scalability, and efficiency of the architecture, providing comprehensive protection for the network security of the financial metropolitan area network.

[0054] In terms of technical architecture, the system for locating the source of a network attack includes: access layer, network layer, gateway, application service layer, basic framework layer, persistence layer, database, and external interface layer. Figure 3 This is a schematic diagram of the technical architecture for locating the source of a network attack according to an embodiment of the present invention, such as... Figure 3 As shown:

[0055] Access layer: This is the outermost layer of the system for locating the source of a network attack. It can interact with the direct user, receive user requests, and return responses.

[0056] In this embodiment, the access layer can use technologies such as Thymeleaf, Jinja2, and Graylog, which are not only convenient and easy to use, but also ensure the security of the system.

[0057] Network layer: Used to protect the system from network attacks and unauthorized access.

[0058] like Figure 3 As shown, in this embodiment, the network layer includes devices such as a NAT gateway and intrusion detection systems to ensure network security. The NAT gateway serves as the system's entry point, handling all incoming and outgoing requests and responses. It routes, filters, and load-balances requests to ensure system availability and performance.

[0059] Application Service Layer: This layer includes various technical services and components, such as alarm message queue analysis (i.e., alarm analysis), hierarchical location historical data query, linked IP blocking, and notification invocation. In other words, some or all of the functions of the aforementioned network security device 22, alarm analysis server 23, external address translation server 24, hierarchical location server 25, monitoring server 26, and linked blocking server 27 reside in the application service layer.

[0060] Among them, alarm analysis, hierarchical location, and notification services can use the Spring Boot framework, which has good decoupling; linkage blocking can use Flask, which is suitable for agile development. Due to the large number of network device types and the variety of automated operation methods, using this framework can provide a certain degree of flexibility.

[0061] Persistence layer: Used for data storage and management; includes components such as databases and file systems to ensure data reliability and consistency. The design of the persistence layer fully considers issues such as data backup, recovery, and migration.

[0062] Database: This is the core component of the persistence layer, used to store the system's data, and employs technologies such as Redis, MySQL, SQLite, and Elasticsearch. The database design fully considers issues such as data structure, query efficiency, and security.

[0063] External interface layer: used to monitor traffic alarms of various external units and call other bank-related services; the systems that the external interface layer can interface with include, but are not limited to: external unit systems and other bank systems, such as the head office system.

[0064] The platform architecture of this invention is designed to be secure and reasonable. Each module is deployed independently and can be dynamically expanded according to the needs of monitoring and emergency response processes, thereby improving the system's resource utilization, security, high availability, maintainability, and scalability.

[0065] This embodiment provides a method for locating the source of a network attack using a location system running on the aforementioned computer terminal or network attack source. Figure 4 This is a flowchart of a method for locating the source of a network attack according to an embodiment of the present invention, such as... Figure 4 As shown, the process includes the following steps:

[0066] Step S402: Filter the received alarm information according to preset rules to determine the alarm report;

[0067] Step S404: Determine the conversion source address corresponding to the alarm report based on the external traffic;

[0068] Step S406: Based on the alarm report and the source address of the conversion, locate the source of the network attack and the affected user equipment.

[0069] By employing the above steps and accurately filtering received alarm information according to preset rules, false alarms can be effectively eliminated, improving the quality and processing efficiency of alarm information. Utilizing external traffic logs to determine the source address of the attack and deeply analyzing the attack path enables rapid location of the network attack source. It also allows for the swift identification and isolation of affected user devices, significantly shortening the time from detection to response. Therefore, this approach addresses the problem of low monitoring and early warning efficiency in related network security protection technologies, thereby enhancing the overall awareness of network security situation.

[0070] In one embodiment, before filtering the received alarm information according to preset rules and determining the alarm report, the method further includes: monitoring and analyzing system traffic according to the logs of the network traffic monitoring device to determine the alarm information.

[0071] In an exemplary embodiment, monitoring and analyzing system traffic based on the logs of a network traffic monitoring device to determine the alarm information includes: receiving, storing, analyzing, and processing the logs of the network traffic monitoring device in real time to determine the alarm information.

[0072] In one embodiment, the preset rules include exclusion rules and matching rules. The step of filtering the received alarm information according to the preset rules to determine the alarm report includes: deleting false alarm information from the alarm information according to the exclusion rules and obtaining positive alarm information; and filtering out alarm information corresponding to the target abnormality level from the positive alarm information according to the matching rules and determining the alarm report.

[0073] In one embodiment, the exclusion rule is a rule defined based on the contextual characteristics of historical alarm information and historical business operation experience.

[0074] In one embodiment, the matching rule is a rule defined based on the severity threshold, impact range threshold, and correlation characteristics corresponding to the alarm information.

[0075] In one exemplary embodiment, network and data security events are monitored, alerted, and intelligently analyzed by combining standard analysis rules from the head office and customized analysis rules specific to each branch, and alarm information is categorized and prioritized. The exclusion rules include standard analysis rules from the head office and / or customized analysis rules specific to each branch; the matching rules also include standard analysis rules from the head office and / or customized analysis rules specific to each branch.

[0076] In this embodiment, the Spring Boot framework can be used to quickly build a network alarm analysis module by integrating components such as log collection, message queue, and rule engine, focusing on data collection, processing and analysis, storage and display. This network alarm analysis module can be set on the alarm analysis server 23.

[0077] Raw alarm information is obtained from all network devices. After parsing and rule-based judgment to identify and persist valid alarm information, the alarm content is presented through interfaces and visualization tools, and a notification mechanism is triggered simultaneously to achieve real-time response to network anomalies. Valid alarms are those filtered through exclusion and matching rules. The specific implementation of the above process is as follows:

[0078] 1) Data Acquisition: Obtaining network alarm information. This primarily utilizes the Graylog distributed log management platform to collect, store, and analyze logs from multiple sources in real time.

[0079] 2) Data Processing and Analysis: Alarm parsing and identification. On one hand, alarm analysis is performed by integrating multiple systems and manually defined basic databases, and the attacked addresses are located by institution and network segment. This mainly includes the terminal security database, the extranet baseline database (including IP addresses of the financial metropolitan area network, etc.), the smart operation equipment database, and the security IoT equipment database, etc. On the other hand, Redis is used to record alarm IDs, and information that needs to be processed is filtered according to preset rules (standard analysis rules for the head office and custom analysis rules for the branch).

[0080] 3) Data storage: Persistent alarm information. JDBC is primarily used to permanently store the data for easy subsequent querying and statistics.

[0081] 4) Alarm Display: Thymeleaf is mainly used to render alarm information pages, making it easier for network security administrators to obtain useful information from alarm content.

[0082] In this embodiment, the system can focus on the analysis and processing of various security events such as viruses, Trojans, weak passwords, vulnerability scanning, and unauthorized software.

[0083] By monitoring intranet traffic in real time and screening it through a rule engine, the system can identify key security threats such as viruses, Trojans, weak passwords, vulnerability scans, and unauthorized software, thereby achieving comprehensive and accurate security situation awareness and ensuring the stable operation of business systems.

[0084] This invention, through real-time traffic monitoring and custom rule analysis, achieves closed-loop management of the entire process from alarm detection to coordinated response. Based on the branch's actual network environment, the platform focuses on efficiently identifying and handling security risks such as viruses, Trojans, weak passwords, vulnerability scanning, and unauthorized software. Compared to traditional security protection methods that rely on manual alarm screening, the platform innovatively adopts automated analysis rules, which can accurately capture suspicious behavior and generate alarms. Simultaneously, through a linkage mechanism, it notifies the technical team to complete emergency response immediately, significantly improving the efficiency of security incident handling.

[0085] In this embodiment, the system can complete the storage and analysis of multiple batches of alarm data in a short period of time, generate detailed alarm reports, and ensure that abnormal behavior can be identified and handled in a timely manner. Figure 5 This is a flowchart illustrating the alarm location analysis according to an embodiment of the present invention, as shown below. Figure 5 As shown, the process includes the following steps:

[0086] Step S501: The external unit initiates a business traffic request;

[0087] Step S502: The front-end module of the external unit forwards the business traffic request through the Nginx middleware;

[0088] In step S503, the front-end module of the branch system receives the business traffic request from the external unit, performs address translation, and sends the business traffic request and the corresponding translation address to the alarm analysis server.

[0089] In step S504, the external address translation server records the address translation information and forwards the address translation information to business servers such as P8, as well as storing it in Elasticsearch-related components;

[0090] In one embodiment, the external address translation server displays a log interface through Graylog, which facilitates further manual analysis of the translated address.

[0091] Step S505: The alarm analysis server receives alarm information sent by network devices within a preset time period based on the business traffic request, and parses and locates the alarm information according to preset rules and the converted address resolved by the external unit. The located content includes, but is not limited to, the organization where the attack source is located and the network segment corresponding to the attack source.

[0092] In this embodiment, the external address translation server can locate alarm information by querying the location server's cache or database.

[0093] Step S506: Based on the analysis results and location results of the alarm information, generate an alarm report.

[0094] In one embodiment, after locating the source of the network attack and the affected user equipment based on the alarm report and the source address of the conversion, the method further includes: forwarding the alarm report to the affected user equipment according to a multi-channel mechanism, and blocking the source of the network attack.

[0095] The system in this invention embodiment is designed with flexible and diverse emergency notification functions to ensure that alarm information can reach relevant technical personnel and management teams as soon as possible. For example, it uses the unified interface of China Construction Bank headquarters to implement multiple notification formats such as SMS, email, telephone, and system pop-ups, and sets multi-level notification strategies according to the severity of the event.

[0096] For different types of alarms, the system will notify the branch monitoring personnel immediately, and push high-risk alarms to the operation monitoring center and technical team leaders to achieve hierarchical notification and rapid response.

[0097] Figure 6 This is a schematic diagram of a multi-dimensional emergency notification process according to an embodiment of the present invention, such as... Figure 6 As shown, the process includes the following steps:

[0098] Step S601: The multi-dimensional notification server queries the alarm report from the monitoring server. The query method can be to query periodically according to a preset time; or to query irregularly according to a preset trigger condition; or a combination of periodic and irregular queries.

[0099] Step S602: Based on the alarm report, determine the target network, the corresponding staff member's mobile phone number, email address, employee number, and other information;

[0100] Step S603: Invoke the multi-dimensional notification method to send a notification to the affected user devices.

[0101] Among them, the multi-dimensional notification methods include:

[0102] Method 1: Utilize SMS service; send the alarm report to the target network and corresponding staff via SMS.

[0103] Method 2: Access the bank's internal email system; that is, send the alarm report to the relevant staff via email.

[0104] Method 3: Call the monitoring server to send the alarm report to the on-duty staff, who will then send the alarm report to the corresponding staff. Alternatively, the on-duty staff can create a work order in the work order system and send the alarm report to the corresponding staff.

[0105] Upon receiving an alarm report, the relevant staff will coordinate with various units and teams to handle the alarm.

[0106] In one exemplary embodiment, the system also integrates a linkage mechanism to automatically block and coordinate responses to alarm events.

[0107] The automated blocking mechanism utilizes the Flask framework within the Python Web framework. By writing shell scripts, it automatically triggers blocking operations for high-risk alerts that are repeatedly triggered within a short period of time (such as multiple scanning attacks from the same source IP). The blocking information is then synchronized to relevant teams and systems to ensure that the blocking results are accurate and timely.

[0108] In addition to Flask, Django is another Python web framework that can be used. Django provides many built-in features, such as user authentication, content management, ORM, form processing, site mapping, and caching, which can usually be used directly without additional configuration.

[0109] The system also features a well-designed collaborative response process, with the technical team and business departments working closely together to efficiently handle various security incidents through steps such as source identification, impact assessment, and risk mitigation strategy development.

[0110] Figure 7 This is a schematic diagram of an automated blocking process according to an embodiment of the present invention, such as... Figure 7 As shown, the process includes the following steps:

[0111] Step S701: The alarm analysis server sends the high-risk IPs to be blocked to the linkage blocking server;

[0112] Step S702: In conjunction with the blocking server, identify the network device corresponding to the high-risk IP and log in to that network device;

[0113] Step S703: The linkage blocking server sets up a black hole route based on the high-risk IP to block the network device.

[0114] Step S704: If the blocking is successful, the blocking server will send a blocking success notification message to the multi-dimensional notification server.

[0115] Step S705: The multi-dimensional notification server sends a notification message to the corresponding staff member based on the received successful blocking notification message.

[0116] In this embodiment, after receiving the notification message, the relevant staff will further notify the relevant technical team and relevant business departments / units of the successful blocking notification message, until the relevant technical team and relevant business departments / units confirm that the risk has been eliminated and log back into the system to remove the IP blocking.

[0117] In summary, by establishing a multi-dimensional alarm and automatic blocking mechanism, this invention can quickly identify, locate, and handle high-risk attack sources, significantly shortening emergency response time, solving the problem of insufficient timeliness caused by human intervention, and ensuring efficient handling of cybersecurity incidents. Simultaneously, it also builds a cross-team collaboration platform that integrates cybersecurity equipment, system logs, and personnel scheduling resources, achieving seamless integration from alarm generation to blocking execution, ensuring business security and system stability.

[0118] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0119] This embodiment also provides a device for locating the source of a network attack. This device is used to implement the above embodiments and preferred embodiments, and details already described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0120] This invention also provides a device for locating the source of a network attack, which can be installed on the aforementioned network attack source locating system. Figure 8 This is a structural block diagram of a network attack source location device according to an embodiment of the present invention, such as... Figure 8 As shown, the device includes:

[0121] The filtering module 81 is used to filter the received alarm information according to preset rules and determine the alarm report;

[0122] The determination module 82 is used to determine the conversion source address corresponding to the alarm report based on the external traffic.

[0123] The location module 83 is used to locate the source of the network attack and the affected user equipment based on the alarm report and the source address of the conversion.

[0124] In one embodiment, the device for locating the source of a cyberattack further includes:

[0125] The monitoring module 84 is used to monitor and analyze system traffic based on the logs of the network traffic monitoring device, and determine the alarm information.

[0126] In one embodiment, the preset rules include exclusion rules and matching rules. The filtering module 81 is further configured to delete false alarm information from the alarm information according to the exclusion rules and obtain positive alarm information; and is further configured to filter out alarm information corresponding to the target abnormality level from the positive alarm information according to the matching rules and determine the alarm report.

[0127] In one embodiment, the exclusion rule is a rule defined based on the contextual characteristics of historical alarm information and historical business operation experience.

[0128] In one embodiment, the matching rule is a rule defined based on the severity threshold, impact range threshold, and correlation characteristics corresponding to the alarm information.

[0129] In one embodiment, the device for locating the source of a network attack further includes a blocking module 85, which is used to forward the alarm report to the affected user equipment according to a multi-channel mechanism and to block the source of the network attack.

[0130] The embodiments of this invention closely integrate network security monitoring with daily bank operations, forming an integrated security service system covering "monitoring-analysis-response". Compared to traditional traffic alarm handling methods, which rely on manual analysis and processing after alarm generation and are inefficient, this invention achieves automated alarm filtering and intelligent analysis, not only reducing interference from redundant alarms but also significantly improving the efficiency of handling suspicious alarms. Through SMS notification and visual display of alarm reports, security administrators can obtain and process critical information in the shortest possible time, optimizing workflows and improving the timeliness and accuracy of emergency response.

[0131] Furthermore, this embodiment of the invention is based on a distributed architecture, fully utilizing the elastic scalability of cloud computing to support high-concurrency data analysis and processing. Through modular design, the platform's various functions (such as alarm analysis, multi-dimensional notifications, and linked blocking) are deployed independently without affecting each other.

[0132] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0133] Embodiments of the present invention also provide a storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above method embodiments when running.

[0134] Optionally, in this embodiment, the storage medium may be configured to store a computer program for performing the following steps:

[0135] S1, Filter the received alarm information according to preset rules and determine the alarm report;

[0136] S2, determine the conversion source address corresponding to the alarm report based on the external traffic;

[0137] S3. Based on the alarm report and the source address of the conversion, locate the source of the network attack and the affected user equipment.

[0138] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0139] Embodiments of the present invention also provide an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.

[0140] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0141] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:

[0142] S1, Filter the received alarm information according to preset rules and determine the alarm report;

[0143] S2, determine the conversion source address corresponding to the alarm report based on the external traffic;

[0144] S3. Based on the alarm report and the source address of the conversion, locate the source of the network attack and the affected user equipment.

[0145] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated here.

[0146] It is obvious to those skilled in the art that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.

[0147] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for locating the source of a network attack, characterized in that, include: The received alarm information is filtered according to preset rules to determine the alarm report; The source address corresponding to the alarm report is determined based on the external traffic. Based on the alarm report and the source address of the translation, the source of the network attack and the affected user equipment can be located.

2. The method according to claim 1, characterized in that, Before filtering the received alarm information according to preset rules and determining the alarm report, the method further includes: Based on the logs from the network traffic monitoring device, the system traffic is monitored and analyzed to determine the alarm information.

3. The method according to claim 1, characterized in that, in, The preset rules include exclusion rules and matching rules. The step of filtering received alarm information according to the preset rules to determine alarm reports includes: According to the exclusion rule, false alarm information in the alarm information is deleted, and positive alarm information is obtained; According to the matching rules, alarm information corresponding to the target anomaly level is filtered out from the positive alarm reports, and the alarm report is determined.

4. The method according to claim 3, characterized in that, in, The exclusion rule is a rule defined based on the contextual features of historical alarm information and historical business operation experience.

5. The method according to claim 3, characterized in that, in, The matching rules are defined based on the severity threshold, impact range threshold, and correlation characteristics corresponding to the alarm information.

6. The method according to claim 1, characterized in that, After locating the source of the network attack and the affected user equipment based on the alarm report and the source address of the translation, the method further includes: According to the multi-channel mechanism, the alarm report is forwarded to the affected user equipment, and the source of the network attack is blocked.

7. A device for locating the source of a network attack, characterized in that, include: The filtering module is used to filter the received alarm information according to preset rules and determine the alarm report; The determination module is used to determine the conversion source address corresponding to the alarm report based on the external traffic. The location module is used to locate the source of the network attack and the affected user equipment based on the alarm report and the source address of the conversion.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method described in any one of claims 1 to 6.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 6.