Method and system for handling information security events
By leveraging the collaborative decision-making and execution of multiple expert and engineer agents, the challenges of handling information security incidents have been resolved, enabling rapid and accurate handling of such incidents and reducing organizational losses.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-03
- Publication Date
- 2026-03-10
AI Technical Summary
Existing technologies are insufficient for quickly and accurately handling information security incidents, making it difficult to control the scope of their impact and requiring organizations to pay a significant price.
The decision-making process employs multi-expert intelligent agent technology, while the execution process utilizes multi-engineer intelligent agents. By receiving alarm information, expert intelligent agents generate handling actions, the chairman intelligent agent generates handling plans, and the chief engineer intelligent agent allocates and executes handling tasks, thereby achieving automated handling of information security incidents.
It improved the speed and effectiveness of handling information security incidents, reduced organizational losses, and achieved efficient handling and automated management of information security incidents.
Smart Images

Figure CN121637489A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of information security, and more particularly, to a method and system for handling information security incidents, and associated electronic device, computer-readable storage medium and computer program product. BACKGROUND
[0002] An information security incident refers to one or more sudden events that cause real harm or potential threat to the confidentiality, integrity or availability of an organization's information assets, such as data, systems and networks, etc. In order to protect the organization's information assets, it is necessary to monitor information security incidents so as to handle information security incidents in time. SUMMARY
[0003] A brief summary of the present disclosure is presented in the following in order to provide a basic understanding of some aspects of the present disclosure. However, it should be understood that this summary is not an extensive overview of the present disclosure. It is not intended to identify key or critical elements of the present disclosure or to delineate the scope of the present disclosure. Its sole purpose is to present some concepts of the present disclosure in a simplified form as a prelude to the more detailed description that is presented later.
[0004] According to a first aspect of the present disclosure, a method for handling information security incidents is provided, comprising: receiving alarm information, the alarm information indicating a corresponding information security incident; performing a decision process and an execution process for the alarm information, wherein: the decision process comprises: inputting the alarm information into each expert agent of a plurality of expert agents injecting knowledge of different subfields in the technical field of information security, to generate a handling action for the corresponding information security incident by the plurality of expert agents respectively, and inputting the handling actions generated by the plurality of expert agents into a judge chairman agent, to generate a handling plan based on handling action dependency relationships by the judge chairman agent, the handling plan indicating handling actions to be executed and their order; and the execution process comprises: inputting the handling plan generated by the judge chairman agent into a chief engineer agent, to generate handling tasks by the chief engineer agent and assign the generated handling tasks to engineer agents capable of executing corresponding handling tasks in a plurality of engineer agents with different handling skills, and executing the assigned handling tasks via the engineer agents.
[0005] According to a second aspect of the present disclosure, an electronic device is provided, comprising: a processor; a memory storing computer executable instructions, the computer executable instructions, when executed by the processor, causing the processor to perform the method according to the first aspect of the present disclosure.
[0006] According to a third aspect of the present disclosure, there is provided a computer-readable storage medium having computer-executable instructions stored thereon that, when executed by a processor, cause the processor to perform the method according to the first aspect of the present disclosure.
[0007] According to a fourth aspect of the present disclosure, there is provided a computer program product comprising instructions which, when executed by a processor, implement the method according to the first aspect of the present disclosure.
[0008] According to a fifth aspect of the present disclosure, there is provided a system for handling information security incidents, comprising: an acquisition module configured to receive alarm information, the alarm information indicating a corresponding information security incident; and a handling module comprising a plurality of expert agents injected with knowledge in different subfields of the information security technical field, a judge chairman agent, a chief engineer agent, and a plurality of engineer agents with different handling skills, the handling module being configured to, for the alarm information, perform a decision process and an execution process, wherein: the decision process comprises: inputting the alarm information to each of the plurality of expert agents to generate, by the plurality of expert agents, handling actions for the corresponding information security incident respectively, and inputting the handling actions generated by the plurality of expert agents to the judge chairman agent to generate, by the judge chairman agent, a handling plan based on handling action dependency relationships, the handling plan indicating handling actions to be executed and an order thereof; and the execution process comprises: inputting the handling plan generated by the judge chairman agent to the chief engineer agent to generate handling tasks by the chief engineer agent and distribute the generated handling tasks to engineer agents of the plurality of engineer agents capable of executing corresponding handling tasks, and executing the distributed handling tasks via the engineer agents. BRIEF DESCRIPTION OF DRAWINGS
[0009] The foregoing and other features and advantages of the present disclosure will become apparent to those skilled in the art from the following description of embodiments of the present disclosure, taken in conjunction with the accompanying drawings. The drawings are incorporated in and constitute a part of this specification, and are included for further explanation of the principles of the present disclosure and to assist in understanding the application. In the drawings:
[0010] Figure 1 is a flowchart illustrating a method for handling information security incidents according to some embodiments of the present disclosure;
[0011] Figure 2 is a flowchart illustrating a method for handling information security incidents according to some embodiments of the present disclosure;
[0012] Figure 3 is a schematic block diagram illustrating a system for handling information security incidents according to some embodiments of the present disclosure;
[0013] Figure 4 is a schematic block diagram illustrating a system for handling information security events according to some embodiments of the present disclosure;
[0014] Figure 5 is a schematic block diagram illustrating an electronic device according to some embodiments of the present disclosure;
[0015] Figure 6 is a schematic block diagram of a computer system upon which embodiments of the present disclosure can be implemented.
[0016] Note that, in the following embodiments, the same reference numbers are used in different drawings to represent the same or similar parts or parts having the same function, and repeated description thereof is omitted. In some cases, similar reference numbers and letters are used to represent similar items, and once an item is defined in one drawing, it need not be further discussed in subsequent drawings.
[0017] For ease of understanding, the positions, sizes, ranges, and the like of the structures shown in the drawings and the like are sometimes not actual ones. Therefore, the present disclosure is not limited to the positions, sizes, ranges, and the like disclosed in the drawings and the like. DETAILED DESCRIPTION
[0018] Various exemplary embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Note that the relative arrangement of the components and steps, numerical expressions, and numerical values set forth in these embodiments are not limiting to the scope of the present disclosure unless otherwise specifically stated.
[0019] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way limiting to the scope of the disclosure and its applications or uses. That is, the structures and methods herein presented are by way of example only and are illustrative of various embodiments of the structures and methods in the present disclosure. However, those skilled in the art will recognize that they are merely illustrative of the exemplary ways in which the present disclosure can be carried out and are not exhaustive. Further, the drawings are not necessarily drawn to scale, with some features being exaggerated and others omitted in the interest of simplifying the drawings and focus.
[0020] In addition, well-known techniques, methods, and equipment known to those having ordinary skill in the relevant art can not be discussed in detail below, but should be considered as part of the specification, where appropriate.
[0021] In all examples shown and discussed herein, any specific values should be interpreted as merely illustrative and not as a limitation. Thus, other examples of the exemplary embodiments can have different values.
[0022] With the continuous development of information technology, the attack means for information security is more and more concealed and rapid, the number of information security events caused by the attack is more and more, and the severity of the information security events is more and more, so that the disposal difficulty of the information security events is more and more high. If the information security events cannot be disposed quickly and accurately, the influence range of the information security events cannot be controlled, and the organization needs to pay a greater cost. In order to facilitate the description, “event” can be used as the abbreviation of “information security event” in the present disclosure.
[0023] The present disclosure proposes a method for disposing information security events. The method realizes efficient disposal of information security events by adopting a decision-making process of a multi-expert agent technology and an execution process of a multi-engineer agent. In addition, before decision-making and execution, the method can also perform alarm convergence to comprehensively manage a series of information security events, thereby improving disposal speed and effectiveness. Through the method provided by the present disclosure, automated disposal of information security events can be realized, and disposal efficiency and reliability of information security events can be improved, so that attack means can be timely defended, and the loss of the organization can be reduced.
[0024] The method for disposing information security events according to some embodiments of the present disclosure will be described in detail below in combination with the drawings. It can be understood that the actual method can also include other steps, but in order not to obscure the key points of the present disclosure, these other steps are not discussed herein and the drawings also do not show these other steps.
[0025] Figure 1 FIG. 1 is a flowchart illustrating a method 100 for disposing information security events according to some embodiments of the present disclosure.
[0026] As shown in FIG. 1, the method 100 can include a step S102 and a step S108. Figure 1
[0027] At the step S102, alarm information is received. The alarm information can indicate a corresponding information security event.
[0028] In some embodiments, the alarm information can be received from a plurality of data sources, and the plurality of data sources can include devices having at least one of computing capability, storage capability, and network communication capability. For example, the plurality of data sources can include a computer network, a computer terminal, a server, a network device, an access control system, a camera system, etc. By collecting alarm information of a plurality of data sources, comprehensive disposal of information security events of an organization can be realized, and the probability of missed disposal can be reduced. In some examples, the alarm information can be obtained through a situational awareness capability of the system, which is a capability of dynamically and holistically understanding security risks based on the environment. For example, the alarm information can be obtained from data sources such as network traffic, logs, websites (Websit, Web), emails, terminals, etc. through the situational awareness capability.
[0029] The alert information is usually generated in response to the occurrence of the information security event. For example, when the information security event occurs, the system generates a piece of alert information to describe the occurrence time of the information security event, the attacker identity and the attacker type, the attacked identity and the attacked type, the attack behavior type (i.e., the attack means of the attacker), and the event evidence, etc. The attacker identity and the attacked identity can be in any suitable form. For example, the attacker identity can include at least one of an Internet Protocol (IP) address, a source port, an IP version, a service type, a reassembly identity, a header check, a Transmission Control Protocol (TCP) flag, and a User Datagram Protocol (UDP) flag of the attacker. The attacked identity can include at least one of an IP address, a terminal user, a terminal Media Access Control (MAC) address, a terminal asset code, and a location code of the attacked. In addition, each of the attacked type, the attacker type, and the attack behavior type can be encoded in a tree-like hierarchy. The tree-like hierarchy can subdivide the types level by level, thereby facilitating tracing the same types at different levels. In some examples, the tree-like hierarchy can include three levels in turn from high to low, and each level is represented by 2 digits, and if a level is empty, the digit of the level is filled with 0. For example, for the attacker type: 600000 can represent a network device, 601000 can represent a switch subordinate to the network device, and 602000 can represent a router subordinate to the network device; 700000 can represent an Internet of Things (IoT) device, 701000 can represent a video device subordinate to the IoT device, and 701010 can represent a camera subordinate to the video device. For example, for the attack behavior type: 200000 can represent a hacker tool, 201000 can represent a scanning tool subordinate to the hacker tool, 201200 can represent a penetration tool subordinate to the hacker tool, and 201202 can represent Metasploit (a kind of penetration tool) subordinate to the penetration tool.
[0030] As a non-limiting illustrative example, the alarm information can include the following content: "2025-09-26 14:00:00 |!alarm |!201.100.100.2 |!{ "gpt_log_ids": [], "attack_classify_id": 500000,......, "attack_type": 201000,......, "suffer_ip": "20.20.20.21", "tags": "Nmap tool scanning", "damage": "Attackers can use scanning tools to obtain website sensitive information and security vulnerabilities.", "multi_deal_status": 0, "event_evidence": "url path: / nice ports, / Trinity.txt.bak status code: 503 request header: GET / nice%20ports%2C / Tri%6Eity.txt%2ebak HTTP / 1.0\r\n\r\n response header: HTTP / 1.1 503 Service Unavailable\r\nDate: Fri Sep 26 09:10:40 2025 GMT\r\nContent-Length: 798\r\nConnection: close\r\nContent-Type: text / html\r\n\r\n response body: <!DOCTYPE HTML PUBLIC \"- / / W3C / / DTD HTML 4.01 Transitional / / EN\" \"http: / / www.w3c.org / TR / 1999 / REC-html401-19991224 / loose.dtd\"> <meta http-equiv="\"Content-Type\"" content="\"text / html;" charset="UTF-8\""> <table style="\"margin:" auto;font-size:35;position: relative;top:20%;\"> <a style="\"margin:" margin-top:60px;auto;font-size:40px;color:orange \">Hello, very sorry, your access has been intercepted by network security device (SHPE WAF). <a style="\"margin:" auto;font-size:40px;color:orange\">Please contact system administrator Qian Jing. J <astyle="margin: auto; font-size:10px; color:black"> URL: / nice ports, / Trinity.txt.bak <a style="\"margin:" auto;font-size:10px;color:black\">Client IP: 66.175.211.202 GRE source IP: - GRE destination IP: - ", "suffer_classify1_id_name": "terminal", "suffer_classify_id": 200000......}".
[0031] In this illustrated example, the occurrence time of the information security event is "2025-09-26 14:00:00", the attacker identification is "201.100.100.2", the attacker type (attack_classify_id) is "500000", the attacked party identification (suffer_ip) is "20.20.20.21", the attacked party type (suffer_classify_id) is "200000", and the attack behavior type (attack_type) is "201000", and the event evidence (event_evidence) is "url path: / niceports, / Trinity.txt.bak status code: 503 request header: GET / nice%20ports%2C / Tri%6Eity.txt%2ebak HTTP / 1.0\r\n\r\n response header: HTTP / 1.1 503 Service Unavailable\r\nDate: Fri Sep 26 09:10:40 2025 GMT\r\nContent-Length: 798\r\nConnection:close\r\nContent-Type: text / html\r\n\r\n response body: <!DOCTYPE HTML PUBLIC \"- / / W3C / / DTD HTML 4.01 Transitional / / EN\" \"http: / / www.w3c.org / TR / 1999 / REC-html401-19991224 / loose.dtd\"> <meta http-equiv="\"Content-Type\"content=\"text / html;" charset="UTF-8\""> <table style="\"margin:" auto;font-size:35;position: relative;top:20%;\"> <a style="\"margin:margin-top:60px;" auto;font-size:40px;color:orange \">Hello, very sorry, your access has been intercepted by network security device (SHPE WAF). Please contact system administrator Qian Jing. J <a style="\"margin:" auto;font-size:10px;color:black\">URL: / niceports, / Trinity.txt.bak <a style="\"margin:" auto;font-size:10px;color:black\">Client IP: 66.175.211.202 GRE source IP: - GRE destination IP: - "”.
[0032] At step S108, a decision process and an execution process are performed for the alarm information.
[0033] The decision process can include: inputting the alarm information into each of a plurality of expert agents of knowledge injected in different subfields of the information security technical field, to generate, by the plurality of expert agents respectively, a disposal action for the corresponding information security event; and inputting the disposal actions generated by the plurality of expert agents into a judge chairman agent, to generate, by the judge chairman agent based on a disposal action dependency relationship, a disposal plan indicating disposal actions to be executed and an order thereof.
[0034] Here, each expert agent can be constructed based on a pre-trained large language model and fine-tuned with knowledge from the corresponding sub-domains of information security technology, and the judge chairman agent can also be constructed based on a pre-trained large language model and fine-tuned with knowledge from the information security technology field.
[0035] Supervised fine-tuning (SFT) can be used to fine-tune pre-trained large language models to obtain the various agents in this disclosure.
[0036] For expert agents, training data can include descriptions of information security incidents and the corresponding actions to be taken. Taking a data security expert agent as an example, training data could include: discovering that IP address 20.20.20.10 attempted to connect to port 22 of 192.168.10.10 hundreds of times within a short period; 20.20.20.10 may be attempting to brute-force SSH login passwords; and recommending that this IP address be blocked from accessing the target at the firewall. Thus, a data security expert agent can possess the capability to handle information security incidents falling under the data security domain.
[0037] For the judge chair agent, the training data may include data on converting the expert agent's suggested actions into JSON descriptions and data on topology sorting tool calls. For example, the training data for converting the expert agent's suggested actions into JSON descriptions may include:
[0038] .
[0039] The training data invoked by the topology sorting tool may include, for example:
[0040] .
[0041] Therefore, by fine-tuning the large language model based on training data, the ability of the large language model to call tools can be improved, thereby obtaining the judge chairman intelligent agent. This enables the judge chairman intelligent agent to use tools to complete the tasks of "converting natural language into JSON language" and "using tools to perform topological sorting of handling actions" when actually handling information security incidents.
[0042] For example, the judges' chair agent can use tools to convert the natural language description of the action "Configure the firewall to block all access from 20.20.20.10" into a JSON description of the action "{"object":"firewall", "action":"add_rule", "params":{"source":"20.20.20.10", "disable":True}}".
[0043] For example, the judges' chair agent can use a topology sorting tool to perform a topology sort on the transformed actions "[{"code":"A","object":"firewall", "action":"xx", ...}, {"code":"B","object":"server", "action":"xx", ...}, {"code":"C","object":"pc", "action":"xx", ...}]", and the topology sorting tool can return the sorting result:
[0044] Therefore, the disposal plan generated by the judges' chair agent can include the sorting results returned by the topology sorting tool, which are described in JSON language.
[0045] In some embodiments, each of the multiple expert agents is provided with a corresponding toolset and is configured to: determine whether a tool needs to be used based on received alarm information; and in response to determining that a tool needs to be used, select a tool from the toolset and generate a disposition action based on the selected tool, or in response to determining that a tool does not need to be used, not generate a disposition action.
[0046] In some examples, multiple expert agents can include intrusion detection expert agents, data security expert agents, network security expert agents, virus analysis expert agents, and encryption / decryption expert agents. Intrusion detection expert agents can analyze network traffic and system logs to identify unauthorized access attempts, data breaches, and other anomalous behaviors and potential attacks. They are familiar with common network attack methods and intrusion detection techniques, such as port scanning, vulnerability exploitation, and Distributed Denial of Service (DDoS) attacks. Data security expert agents can understand enterprise data classification standards, conduct security audits of enterprise data assets, identify and rectify data security vulnerabilities, and ensure that enterprise data security complies with relevant domestic and international laws, regulations, and industry standards. They possess common data security risk assessment models and tools, have a deep understanding of data security architecture, and master key technologies such as data encryption, access control, and data backup and recovery. Network security expert agents can detect security incidents such as internet network attacks, industrial control network attacks, and network vulnerabilities. They are familiar with mainstream security devices and tools. The virus analysis expert agent can identify and analyze malicious code and recognize new virus techniques. It is familiar with common executable file formats, such as Portable Executable (PE) and Executable and Linkable Format (ELF), and possesses analytical capabilities for various scripting languages, such as VBScript and JavaScript. The encryption / decryption expert agent is familiar with symmetric encryption, asymmetric encryption, hash algorithms, and other encryption / decryption techniques, and is also knowledgeable about data security and fundamental cryptographic principles.
[0047] In some cases, the specific areas of expertise of different expert agents may overlap, so different expert agents may give the same action for the same alarm. If multiple identical actions exist, the chair agent can combine them into a single action when generating the subsequent action plan.
[0048] In some embodiments, each of the multiple expert agents is provided with a corresponding whitelist and configured to determine whether to use a tool based on received alarm information and the whitelist. In some examples, the whitelist may be a document developed by the enterprise based on actual operational experience, guiding the multiple expert agents to identify which information security events indicated by alarm information are normal operational behaviors rather than attack behaviors. For example, in actual enterprise operations, there may be situations where system scanning is required to obtain operational data, generating corresponding alarm information. In this case, based on the whitelist, it can be determined that the information security event indicated by the alarm information is a normal behavior, and no action is taken on the information security event. This improves the accuracy of information security event handling and reduces the impact on enterprise operational efficiency.
[0049] In some embodiments, the chairperson agent is provided with a pre-action table indicating the dependencies between action actions. The pre-action table includes a description of the execution conditions for each action action. For example, the pre-action table may include: action "isolate host," execution condition "normal network communication"; action "IP address blocking," no execution condition, etc. By integrating the action actions determined by multiple expert agents into a pre-action table according to their dependencies through the chairperson agent, it is ensured that each action can be executed smoothly during subsequent execution, thus improving the efficiency of information security incident handling.
[0050] In some embodiments, the decision-making process may further include: multiple expert agents generating evaluations for the corresponding information security incidents; and inputting the evaluations generated by the multiple expert agents, along with corresponding handling actions, into a chairperson agent, so that the chairperson agent can generate a first incident report and handling plan for the corresponding information security incident, the first incident report indicating the evaluation of the chairperson agent. The first incident report may be given in natural language. The chairperson agent may integrate the evaluations of various expert agents and give its own evaluation based on them. For example, even if the various expert agents may have differing opinions or give opinions that the chairperson agent does not agree with, the chairperson agent may still provide its own additional opinions while retaining the original opinions of the various expert agents.
[0051] The execution process includes: inputting the disposal plan generated by the chairman agent into the chief engineer agent, so that the chief engineer agent generates disposal tasks and assigns the generated disposal tasks to the engineer agents among multiple engineer agents with different disposal skills who are able to perform the corresponding disposal tasks; and executing the assigned disposal tasks through the engineer agents.
[0052] Here, each engineer agent can be constructed based on a pre-trained large language model and fine-tuned using knowledge of corresponding handling skills, and the chief engineer agent can be constructed based on a pre-trained large language model and fine-tuned using knowledge of various handling skills to improve the accuracy of tool invocation. It is understood that in this disclosure, handling skills can correspond to tools.
[0053] The training process for the chief engineer agent is similar to that for the judges' chair agent. For the chief engineer agent, training data can include multi-turn dialogues, which can include action plans described in JSON language and the corresponding execution results of the engineer agents.
[0054] For example, multi-turn dialogues can include the following:
[0055]
[0056]
[0057]
[0058]
[0059]
[0060]
[0061]
[0062]
[0063] .
[0064] Therefore, by fine-tuning the large language model based on training data, the large language model can generate disposal tasks according to the disposal plan and also understand the execution status of a series of disposal tasks, thus obtaining the chief engineer intelligent agent.
[0065] For an engineer agent, training data can include data on selecting appropriate tools to perform a disposal task based on a disposal task described in JSON language.
[0066] For example, for a firewall configuration engineer agent, training data could include:
[0067] user:
[0068] You are a professional firewall configuration engineer. Please select the appropriate tool to perform the task based on the following JSON data.
[0069] {"object":"firewall", "action":"add_rule", "params":{"source":"20.20.20.10", "disable":True}}
[0070] Tools: firewall_add_rule, firewall_nat_add, firewall_configure...
[0071] system:
[0072] firewall_add_rule(source="20.20.20.10", disable=True).
[0073] Therefore, by fine-tuning the large language model based on training data, the large language model can acquire the ability to call tools in the corresponding domain according to the disposal task described in JSON language, and the ability to use the tools to execute the disposal task, thereby obtaining an engineer intelligent agent in the corresponding domain.
[0074] It is understood that, in this disclosure, the pre-training of all agents is optional, and fine-tuning is not required when the large language model can achieve a single pass rate of over 80% on a multi-domain tool call evaluation dataset (e.g., τ2-Bench).
[0075] In some embodiments, multiple engineer agents may include network device engineer agents, firewall engineer agents, Web Application Firewall (WAF) engineer agents, terminal engineer agents, and server engineer agents. The network device engineer agent is familiar with switch and router configurations and can achieve network security goals through technologies such as Access Control Lists (ACLs), Network Address Translation (NAT), Virtual Private Networks (VPNs), Virtual Local Area Networks (VLANs), routing table management, and port security. It can also prevent devices from becoming security vulnerabilities through a series of protections (such as disabling protocols and ports). The network device engineer agent's handling skills may include ACL configuration, routing table configuration (such as routing black holes), NAT configuration, VPN configuration, and authentication and access control (such as 802.1x port authentication). Firewall engineer agents are familiar with network policies and various layers of network protocols, such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and Hypertext Transfer Protocol (HTTP). Their skills include policy configuration and routing configuration. WAF engineer agents are familiar with the HTTP protocol, Web Shell (a type of malicious script), and WAF configuration management, and can block network attacks through configuration. Their skills include protection configuration, real-time monitoring service configuration, and inbound traffic configuration (blocking traffic). Terminal engineer agents are familiar with Windows and Linux operating systems and can isolate terminal programs, restrict process execution, and manage local services through commands or code. Their skills include process isolation, file isolation, stopping processes / services, deleting files, and operating system commands (including privileged system commands). Server engineer agents are familiar with configuring and modifying WWW (World Wide Web) servers, mail servers, File Transfer Protocol (FTP) servers, and Domain Name System (DNS) servers. The server engineer agent's processing skills can include modifying WWW configuration, DNS configuration, and mail server configuration.
[0076] The chief engineer agent can analyze the action plan provided by the chairperson agent, breaking down the actions in the plan into one or more action tasks (there may be one action corresponding to one or more action tasks, or multiple action tasks corresponding to one action task), and assign tasks according to the capabilities of each engineer agent. In some examples, after receiving an action task from the chief engineer agent, the engineer agents can translate the action task into appropriate instructions based on their own environment. For example, the chief engineer agent can send an action task to the server engineer agent to "modify server configuration." Upon receiving this action task, the server engineer agent will discover that the target server is using Nginx as its WWW server, and therefore will modify the Nginx configuration.
[0077] In some embodiments, the execution process may further include: providing the execution results of the engineer agents' assigned disposal tasks to the chief engineer agent; the chief engineer agent generating a second event report for a corresponding series of information security events, the second event report indicating the execution results. The second event report may be given in natural language. The chief engineer agent may integrate the execution results of the various engineer agents to generate the second event report. The chief engineer agent may also receive a first event report generated by the chairperson of the review committee agent and supplement the first event report with its generated second event report, thereby obtaining an event report for this information security event.
[0078] In some examples, the chief engineer agent is configured not to generate a second event report if all received execution results indicate that no action is required. In this case, the first event report can serve as the sole event report for this information security incident.
[0079] In some examples, if all execution results indicate success, a prompt to read the report is output to remind human engineers to read the incident report of this information security incident.
[0080] In some examples, if at least one execution result indicates execution failure, a human intervention prompt is output to alert a human engineer to intervene.
[0081] In some embodiments, method 100 may further include inputting alarm information and a first event report, a handling plan and a second event report generated in response to the alarm information into a reporting agent, so that the reporting agent can generate a final event report as an event report of this information security incident.
[0082] In some examples, alarm information can be assigned a unique number and stored in a database. Decision information generated during the decision-making process (e.g., the handling plan and first event report determined by the chairperson agent in response to the alarm information, and / or the handling actions and evaluations generated by individual expert agents in response to the alarm information) and execution information generated during the execution process (e.g., the second event report related to the alarm information generated by the chief engineer agent, and / or the execution results of individual engineer agents) can be associated with the alarm information and stored in the database. The reporting agent can retrieve the alarm information, decision information, and execution information associated with that number from the database based on the number and generate a final event report based on this information.
[0083] For example, the final incident report may include an incident overview, victim information, attack indicators, and remediation measures. The incident overview may include a description of the relevant information security incident, which may include, for example, a first incident report or be generated based on a first incident report. Attack indicators may include "incident evidence" from alert information or be generated based on "incident evidence." Remediation measures may include the results of the execution of the remediation plan, for example, a second incident report or be generated based on a second incident report. The final incident report generated by the reporting agent can be presented on a user interface to provide human engineers with comprehensive analytical details about the information security incident.
[0084] Therefore, by using multiple expert agents, judge chairman agents, chief engineer agents, multiple engineer agents, and reporting agents, the handling of information security incidents can be automated, intelligent, and visualized, reducing the time spent handling information security incidents and improving the efficiency and accuracy of handling.
[0085] In most cases, information security incidents do not occur in isolation but are likely interconnected. For example, the same cause may trigger a series of information security incidents, resulting in a large number of alerts. To improve response efficiency, alert convergence can be performed before taking action.
[0086] Figure 2 This is a flowchart illustrating a method 100' for handling information security incidents according to some embodiments of the present disclosure. As an example implementation of method 100, method 100' further includes an alarm convergence process (specifically, steps S104' to S106'). Method 100' can group alarm information according to set grouping rules, such that each group of alarm information indicates a corresponding series of information security incidents. Then, method 100' can execute the aforementioned decision-making process and execution process separately for each group of alarm information. By comprehensively handling the same group of alarm information through multiple expert agents, a chairperson agent, a chief engineer agent, and multiple engineer agents, the efficiency and accuracy of handling can be improved.
[0087] like Figure 2 As shown, method 100' includes steps S102' to S108'.
[0088] At step S102', multiple alarm messages are received.
[0089] At step S104', the occurrence time, first information about the attacker, and second information about the victim are extracted from each of the multiple alarm messages.
[0090] At step S106', for alarm information whose occurrence time falls within the time window, the alarm information is grouped according to at least one of the first information and the second information and the grouping rules, and each group of alarm information indicates a corresponding series of information security events.
[0091] In step S108', a decision-making process and an execution process are performed for each group of alarm information.
[0092] Here, the decision-making process may include: inputting the set of alarm information into each of the multiple expert agents, so that the multiple expert agents can generate handling actions for the corresponding series of information security events; and inputting the handling actions generated by the multiple expert agents into the judge chair agent, so that the judge chair agent can generate a handling plan based on the handling action dependencies. The execution process may include: inputting the handling plan generated by the judge chair agent into the chief engineer agent, so that the chief engineer agent can generate handling tasks and assign the generated handling tasks to the engineer agents among the multiple engineer agents that can execute the corresponding handling tasks; and executing the assigned handling tasks through the engineer agents.
[0093] In some embodiments, extracting the occurrence time, first information, and second information from each alarm message can be performed using a large language model. In some examples, the large language model can be built upon a pre-trained large language model and fine-tuned using an information security corpus. For example, the large language model can employ, but is not limited to, the Transformer architecture.
[0094] In some embodiments, the first information may include at least one of an attacker identifier, an attacker type, and an attack behavior type, and the second information may include at least one of a victim identifier and a victim type. For example, the attacker identifier in the first information may include at least one of the attacker's IP address, source port, IP version, service type, reassembly identifier, header checksum, TCP flag, and UDP flag, and the victim identifier in the second information may include at least one of the victim's IP address, terminal user, terminal MAC address, terminal asset code, and location code.
[0095] Referring back to the example above, the large language model can extract the following information from the alert message: the time of the information security incident ("2025-09-26 14:00:00"), the attacker identifier ("201.100.100.2"), the attacker type (attack_classify_id) ("500000"), the attack behavior type (attack_type) ("201000"), the victim identifier (suffer_ip) ("20.20.20.21"), and the victim type (suffer_classify_id) ("200000"). Furthermore, the large language model can also extract event evidence from the alert message. The above alert information can be summarized by a large language model as follows: Attacker 201.100.100.2 is an internet device (attack_classify_id=500000), which performs a security scan (attack_type=201000) on victim 20.20.20.21, which is an end device (suffer_classify_id=200000), and the evidence is event_evidence. Event evidence can be used to subsequently verify relevant information in the alert information, such as attacker identifier, attacker type, attack behavior type, victim identifier, and victim type, to achieve a double verification effect.
[0096] In some embodiments, grouping rules may include one or more first pieces of information that are the same or partially the same; and / or one or more second pieces of information that are the same or partially the same. In some examples, where the victim type, attacker type, or attack behavior type is encoded in a hierarchical tree structure and included in the grouping rules, the grouping rules may include the highest level or multiple levels of the type being the same.
[0097] By using a primary division of time windows and a secondary division of grouping rules, we can more accurately filter out the same group of alarm messages that indicate the same series of information security events.
[0098] In some embodiments, method 100 may further include: sliding a time window; regrouping alarm information whose occurrence time falls within the slidable time window according to at least one of a first piece of information and a second piece of information and a grouping rule; and performing the aforementioned decision-making and execution processes for each group of regrouped alarm information. In some examples, the sliding step size of the time window is in the range of one-quarter to three-quarters of the length of the time window.
[0099] For example, the first alarm message occurred at 14:00:00 on September 26, 2025; the second alarm message occurred at 14:02:00 on September 26, 2025; the third alarm message occurred at 14:04:00 on September 26, 2025; the fourth alarm message occurred at 14:06:00 on September 26, 2025; the fifth alarm message occurred at 14:08:00 on September 26, 2025; and the sixth alarm message occurred at 14:10:00 on September 26, 2025. Assuming the time window width is 10 minutes and the sliding step size is 5 minutes, then the first to third alarm messages belong to the same time window "13:55:00 to 14:05:00", and the fourth to sixth alarm messages belong to the next time window "14:00:00 to 14:10:00".
[0100] Since alarm information is dynamically generated, alarm information that may occur at any time can be dynamically grouped by sliding time windows, and these alarm information can be dealt with in a timely manner.
[0101] In some embodiments, when addressing a set of alarm messages, the final event report may include an attack timeline in addition to an event overview, victim information, attack metrics, and remedial actions. The attack timeline may indicate the sequence of alarm messages ordered from earliest to latest occurrence.
[0102] For illustrative purposes only, a sample final event report is provided below.
[0103] 1. Event Overview
[0104] On October 15, 2025 at 09:21:42, it was discovered that the attacker 10.10.10.1 gained initial access to the victim host 172.16.74.52 by uploading a WebShell (which can be called a "script Trojan") file. Subsequently, the attacker carried out a variety of attack activities on the victim host, including network scanning, information gathering, lateral movement attempts, and malware implantation.
[0105] 2. Information of the victim
[0106] The primary victim host was 172.16.74.52 (a security testing machine).
[0107] 3. Attack Timeline
[0108] (1) Upload the WebShell file ( / www / wwwroot / 101.52.128.83 / pikachu123 / vul / unsafeupload / uploads / 001.php) at 09:21:42;
[0109] (2) At 09:24:04, malware was implanted, specifically by connecting to dnslog.cn via ping and curl to implant the dnslog hacking tool;
[0110] (3) At 09:25:04, a network scan was performed, specifically using the fscan_amd64 tool to scan the 172.16.74.52 / 24 network segment;
[0111] (4) At 09:45:04, privilege escalation is performed, specifically by executing `python -c import pty; pty.spawn(" / bin / bash")` to obtain an interactive shell;
[0112] (5) At 09:50:03, information was collected, specifically by executing the ping command to detect the liveness status of host 172.16.74.7;
[0113] (6) At 09:53:04, malicious software activity was carried out, specifically phishing software (ping deepseek-go.com).
[0114] 4. Attack indicators
[0115] (1) The indicator type is "file path", the indicator value is " / www / wwwroot / 101.52.128.83 / pikachu123 / vul / unsafeupload / uploads / 001.php", and the indicator description is "WebShell file upload";
[0116] (2) The indicator type is "Uniform Resource Locator (URL)", the indicator value is "http: / / custom flag / pikachu123 / vul / unsafeupload / uploads / 001.php", and the indicator description is "WebShell accessing resources".
[0117] (3) The indicator type is "file hash", the indicator value is "MD5: ba53af4e9b05b69e1ef1e8828bdb08c3", and the indicator description is "WebShell file verification".
[0118] (4) Indicator type: "Execute command", indicator value: "python -c import pty; pty.spawn(" / bin / bash")", indicator description: "Get interactive shell";
[0119] (5) The indicator type is "Execute command", the indicator value is "ping -c 1 -w 1 172.16.74.7 > / dev / null &&echo true || echo false", and the indicator description is "Detect the liveness status of other hosts".
[0120] (6) Indicator type: "URL / domain name", indicator value: "222.dnslog.cn", indicator description: "Malicious DNS log description";
[0121] (7) Indicator type: "URL / domain", indicator value: "deepseek-go.com", indicator description: "The website connected by the phishing software";
[0122] (8) Indicator type: “Execute command”, indicator value: “. / fscan_amd64 -h 172.16.74.52 / 24”, indicator description: “Network scanning tool description”.
[0123] 5. Handling Measures
[0124] (1) The network equipment engineer agent performs isolation measures: immediately isolate the victim host 172.16.74.52, block all outbound and inbound connections of the host on the network equipment, and check for abnormal connections of other hosts in the same network segment;
[0125] (2) The server engineer intelligent agent performs evidence collection and preservation measures: backing up the WebShell file ( / www / wwwroot / 101.52.128.83 / pikachu123 / vul / unsafeupload / uploads / 001.php), collecting system logs ( / var / log / auth.log, / var / log / syslog), recording the current process list (ps aux), and saving the network connection status (netstat -tulnp);
[0126] (3) The server engineer agent performs malicious cleanup measures: delete the WebShell file (rm -f / www / wwwroot / 101.52.128.83 / pikachu123 / vul / unsafeupload / uploads / 001.php), check and terminate suspicious processes (kill -9 [suspicious PID]), and check crontab and other persistence mechanisms (crontab -l).
[0127] The implementation process of the method disclosed herein will be described in detail below through examples.
[0128] As a non-restrictive example, assume a time window width of 10 minutes, and grouping rules based on the same victim IP address, the same primary category of attack behavior, and the same primary category of attacker type. This means that alerts occurring within the same 10-minute time window (e.g., 13:59:00 to 14:09:00) will be grouped together if the victim IP address, the first two digits of the attack behavior type, and the first two digits of the attacker type are identical. Table 1 below shows some examples of alert messages.
[0129]
[0130] It can be observed that the three alarm messages in Table 1 fall within the same time window, "13:59:00 to 14:09:00". Alarm messages 1 and 2 share the same attacked IP address, the same primary attacker type classification (both "50"), and the same primary attack behavior type classification (both "20"). Therefore, alarm messages 1 and 2 can be grouped together. However, although alarm message 3 shares the same attacked IP address and primary attacker type classification as alarm messages 1 and 2, its primary attacker behavior type classification ("30") differs from that of alarm messages 1 and 2. Therefore, alarm message 3 cannot be grouped with alarm messages 1 and 2. Ultimately, the three alarm messages are divided into two groups: the first group includes alarm messages 1 and 2, and the second group includes alarm message 3. Each group can be assigned a unique group number, and the alarm messages in each group can be stored in the database.
[0131] Next, the first set of alarm information, including alarm information 1 and alarm information 2, is input into the intrusion detection expert agent, data security expert agent, network security expert agent, virus analysis expert agent, and encryption / decryption expert agent, respectively. Based on this set of alarm information, the intrusion detection expert agent can make the following assessment: Malicious host 201.100.100.2 is probing the victim 20.20.20.21 in an attempt to access a non-existent URL address. Therefore, the intrusion detection expert agent can generate the following actions: "Policy configuration (block IP)" (additionally, it can be recommended that the firewall engineer agent execute this) and "Protection configuration" (additionally, it can be recommended that the WAF engineer agent execute this). Based on this set of alarm information, the data security expert agent can make the following assessment: The server has leaked its own software information, and it is recommended to add a WAF policy. Therefore, the data security expert agent can generate the following action: "Protection configuration" (additionally, it can be recommended that the WAF engineer agent execute this). Based on this alert information, the network security expert agent can conclude the following: Excessive scanning will affect normal access; blocking the malicious host IP address is recommended. Therefore, the network security expert agent can generate the following action: "Policy Configuration (Block IP)" (Additionally, it can be suggested that this be executed by the firewall engineer agent). Based on this alert information, the virus analysis expert agent can conclude the following: No virus is involved. Therefore, the virus analysis expert agent does not need to generate any action. Based on this alert information, the encryption / decryption expert agent can conclude the following: No encryption / decryption is involved. Therefore, the encryption / decryption expert agent does not need to generate any action.
[0132] The evaluations and actions generated by each expert agent are aggregated by the chair agent to generate textual information (e.g., the first incident report) and a handling plan (e.g., an action execution table) for use in the final event report. Specifically, the chair agent generates the handling plan based on action dependencies (e.g., an action prerequisite table) and the actions generated by the intrusion detection expert agent, data security expert agent, and network security expert agent, respectively. The handling plan can be shown in Table 2 below. For example, the output of the chair agent is as follows:
[0133] Between 13:59:00 and 14:09:00 on September 26, 2025, the victim 20.20.20.21 underwent extensive network scanning. This may be the hacker's preparation for a subsequent attack by collecting data. Therefore, we need to take the following actions to prevent further attacks:
[0134]
[0135] In Table 2, action 2 is dependent on action 1, meaning action 2 needs to be executed after action 1. Action 3, on the other hand, is independent of action 1 or 2 and can be executed independently.
[0136] Furthermore, the judge chair agent can also output suggested executors and action parameters for each action, which can be included together in the additional column of Table 2 above. For example, the suggested executor for action 1 is the firewall engineer agent, and the action parameters include the malicious host's IP address 201.100.100.2; the suggested executor for action 2 is the WAF engineer agent, and the action parameters include the protected domain name www.xxx.com; the suggested executor for action 3 is the server engineer agent, and the action parameters include blocking servers whose response headers contain information about the victim 20.20.20.21, with the server IP address xxx.xxx.xx.
[0137] In some cases, such as when the expert agent does not provide evaluations to the chair agent, the actions generated by the expert agent can be more detailed, for example, by including specific action parameters. For instance, an intrusion detection expert agent could generate the following action: "Block the IP address of the malicious host 201.100.100.2".
[0138] The aforementioned decision information can be recorded in the database and associated with the group number of the first set of alarm information.
[0139] Subsequently, the disposal plan shown in Table 2 can be input into the chief engineer agent. The chief engineer agent generates disposal tasks based on the disposal plan and assigns them to appropriate engineer agents. The chief engineer agent may refer to the suggestions of expert agents and / or the chairperson of the review committee, or may decide on the executor independently. Table 3 below shows the assigned disposal tasks.
[0140]
[0141] The chief engineer agent can delegate tasks 1 and 3, which have no dependencies, to the firewall engineer agent and the server engineer agent, respectively. Then, the WAF engineer agent executes task 2. As shown in Table 3, the firewall engineer agent first configures policies to block the malicious host's IP address, and then the WAF engineer agent configures protection for the victim's server domain name. Additionally, independently, the server engineer agent prevents response headers from including the victim's server information.
[0142] The firewall engineer agent, WAF engineer agent, and server engineer agent execute the assigned disposal tasks and report the results to the chief engineer agent upon completion. When all disposal tasks have been completed, the chief engineer agent can output the execution result of each disposal action (e.g., a second event report), as shown in Table 4 below.
[0143]
[0144] Here, "no action required" means the system already has the corresponding configuration, possibly because the same actions have already been performed for similar situations (e.g., for a previous time window). For example, information security incidents occurred at 8:10, 8:12, and 8:15 on September 26, 2025. The sliding time window first included the information security incident occurring at 8:10 in the decision-making scope and executed the corresponding action. When the sliding time window included the information security incident occurring at 8:12 in the decision-making scope for the second time, although a action task was generated (completing the decision-making process), if the action had already been executed, it did not need to be executed again. This saves system resources and avoids repeatedly executing the same action task.
[0145] The second incident report may include: "Between 13:59:00 and 14:09:00 on September 26, 2025, victim 20.20.20.21 was subjected to a large number of network scans. Therefore, the firewall engineer agent successfully blocked the malicious host's IP address 201.100.100.2, and the server engineer agent successfully modified the configuration of victim 20.20.20.21's WWW server to disable the inclusion of server information in response headers. Thus, this information security incident has been successfully handled." The second incident report generated by the chief engineer agent can be presented on the user interface to provide human engineers with information on the handling and execution of the information security incident.
[0146] The aforementioned execution information can be recorded in the database and associated with the group number of the first set of alarm information.
[0147] The reporting agent can retrieve the first set of alarm information, along with its decision and execution information, from the database based on the group number of the first set of alarm information, and then generate the final event report accordingly.
[0148] The following describes in detail, with reference to the accompanying drawings, a system for handling information security incidents according to some embodiments of the present disclosure. It will be understood that actual systems may include other components, but to avoid obscuring the essential points of this disclosure, these other components will not be discussed herein and are not shown in the accompanying drawings.
[0149] Figure 3 This is a schematic block diagram illustrating a system 200 for handling information security incidents according to some embodiments of the present disclosure. Figure 3 As shown, system 200 includes an acquisition module 202 and a processing module 218. The acquisition module 202 can be configured to receive alarm information indicating a corresponding information security event. The processing module 218 can include multiple expert agents, a chairperson agent, a chief engineer agent, and multiple engineer agents with different processing skills, all infused with knowledge of different sub-fields of information security technology. It can be configured to perform decision-making and execution processes in response to alarm information (details can be found in the preceding description). In some embodiments, the processing module 218 may also include a reporting agent.
[0150] In some embodiments, the system 200 may further include an extraction module and a grouping module. Figure 3 (Not shown). The acquisition module 202 can be configured to receive multiple alarm messages. The extraction module can be configured to extract the occurrence time, first information about the attacker, and second information about the victim from each of the multiple alarm messages. The grouping module can be configured to group the alarm messages whose occurrence time falls within a time window according to at least one of the first and second information and grouping rules, with each group of alarm messages indicating a corresponding series of information security events. The handling module 218 can be configured to perform a decision-making process and an execution process for each group of alarm messages (see the previous description for details, which will not be repeated here).
[0151] Various embodiments of system 200 can be referred to similarly to the various embodiments of methods 100 and 100' above, and will not be described in detail here.
[0152] Figure 4 A non-limiting example implementation 200' of system 200 is shown. For example... Figure 4 As shown, system 200' includes an acquisition module 202, an extraction module 204, a grouping module 206, a processing module 218, and a database 220. The processing module 218 includes an expert agent module 208, a chairman of the panel of judges agent 210, a chief engineer agent 212, an engineer agent module 214, and a reporting agent 216.
[0153] The acquisition module 202 can be equipped with situational awareness capabilities and can be configured to acquire multiple alarm messages from various data sources and input these alarm messages into the extraction module 204. The extraction module 204 can be deployed with a large language model and can be configured to extract the occurrence time, first information, and second information from each alarm message using the large language model, and input the multiple alarm messages and the extracted occurrence time, first information, and second information into the grouping module 206. The grouping module 206 can group the alarm messages whose occurrence time falls within a time window according to at least one of the first and second information and a grouping rule to obtain multiple sets of alarm messages, and input these multiple sets of alarm messages into each expert agent in the expert agent module 208. The expert agent module 208 may include an intrusion detection expert agent 2081, a data security expert agent 2083, a network security expert agent 2085, a virus analysis expert agent 2087, and an encryption / decryption expert agent 2089. Each expert agent analyzes each set of alarm information to determine whether a response action needs to be generated, and if so, generates the response action and inputs it into the chairperson agent 210. The chairperson agent 210 generates a response plan based on the response actions and their dependencies among the multiple expert agents and inputs the response plan into the chief engineer agent 212. The chief engineer agent 212 generates response tasks based on the response plan and assigns these tasks to multiple engineer agents in the engineer agent module 214, such as network device engineer agent 2141, firewall engineer agent 2143, WAF engineer agent 2145, terminal engineer agent 2147, and server engineer agent 2149.
[0154] Grouping module 206, judge chairman agent 210, and chief engineer agent 212 can store alarm grouping information, decision information, and execution information into database 220, respectively. Reporting agent 216 can access database 220 and obtain relevant information to generate the final event report.
[0155] This disclosure also provides an electronic device. (See reference...) Figure 5 This illustrates a schematic block diagram of an electronic device 300 according to some embodiments of the present disclosure. Figure 5As shown, electronic device 300 includes processor 302 and memory 304 storing computer-executable instructions that, when executed by processor 302, cause processor 302 to perform the method 100 according to any of the foregoing embodiments. Processor 302 may be, for example, a central processing unit (CPU) of electronic device 300. Processor 302 may be any type of general-purpose processor or may be a processor specifically designed for handling information security incidents, such as an application-specific integrated circuit (“ASIC”). Memory 304 may be coupled to processor 302 and may include various computer-readable media accessible by processor 302. In various embodiments, memory 304 described herein may include volatile and non-volatile media, removable and non-removable media. For example, memory 304 may include any combination of: random access memory (“RAM”), dynamic RAM (“DRAM”), static RAM (“SRAM”), read-only memory (“ROM”), flash memory, cache memory, and / or any other type of non-transitory computer-readable media. The memory 304 may store instructions that, when executed by the processor 302, cause the processor 302 to execute the method 100 according to any of the foregoing embodiments of the present disclosure.
[0156] The electronic device 300 is configured to perform the method 100 described in any of the foregoing embodiments, and therefore reference can be made to the description of the various embodiments of method 100 above, which will not be repeated here.
[0157] This disclosure also provides a computer-readable storage medium having computer-executable instructions stored thereon, which, when executed by a processor, cause the processor to perform a method for handling information security incidents according to any of the foregoing embodiments of this disclosure.
[0158] This disclosure also provides a computer program product that may include instructions that, when executed by a processor, implement the method for handling information security incidents according to any of the foregoing embodiments of this disclosure. The instructions may be any set of instructions that can be executed directly by one or more processors, such as machine code, or any set of instructions that can be executed indirectly, such as a script. The instructions may be stored in an object code format for direct processing by one or more processors, or stored in any other computer language, including scripts or sets of independent source code modules that are interpreted on demand or compiled in advance.
[0159] Figure 6A schematic block diagram of a computer system 400 on which embodiments of the present disclosure may be implemented is shown. The computer system 400 includes a bus 402 or other communication mechanism for transmitting information, and a processing means 404 coupled to the bus 402 for processing information. The computer system 400 also includes a memory 406 coupled to the bus 402 for storing instructions to be executed by the processing means 404; the memory 406 may be random access memory (RAM) or other dynamic storage device. The memory 406 may also be used to store temporary variables or other intermediate information during the execution of instructions to be executed by the processing means 404. The computer system 400 also includes a read-only memory (ROM) 408 or other static storage device coupled to the bus 402 for storing static information and instructions for the processing means 404. A storage device 410, such as a magnetic disk or optical disk, is provided and coupled to the bus 402 for storing information and instructions. Computer system 400 may be coupled via bus 402 to output device 412 for providing output to a user, such as, but not limited to, a display (such as a cathode ray tube (CRT) or liquid crystal display (LCD)), speakers, etc. Input device 414, such as a keyboard, mouse, microphone, etc., is coupled to bus 402 for transmitting information and command selections to processing device 404. Computer system 400 may perform embodiments of this disclosure. Consistent with certain implementations of this disclosure, results are provided by computer system 400 in response to processing device 404 executing one or more sequences of one or more instructions contained in memory 406. Such instructions may be read into memory 406 from another computer-readable medium, such as storage device 410. Execution of the sequence of instructions contained in memory 406 causes processing device 404 to perform the methods described herein. Alternatively, the teachings may be implemented using hardwired circuitry in place of or in combination with software instructions. Therefore, implementations of this disclosure are not limited to any particular combination of hardware circuitry and software. In various embodiments, computer system 400 may be connected across a network to one or more other computer systems, such as computer system 400, via network interface 416 to form a networked system. This network may include a private network or a public network such as the Internet. In a networked system, one or more computer systems may store data and supply data to other computer systems. As used herein, the term "computer-readable medium" refers to any medium that participates in providing instructions to processing device 404 for execution. Such media may take many forms, including but not limited to non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical discs or magnetic disks such as storage device 410. Volatile media include dynamic memory such as memory 406. Transmission media include coaxial cables, copper wires, and optical fibers, including wiring that includes bus 402.Common forms of computer-readable media or computer program products include, for example, floppy disks, flexible disks, hard disks, magnetic tapes, or any other magnetic media, CD-ROMs, digital video discs (DVDs), Blu-ray discs, any other optical media, thumb drives, memory cards, RAM, PROMs and EPROMs, fast EPROMs, any other memory chips or cartridges, or any other tangible media from which a computer can read. Various forms of computer-readable media may be involved when carrying one or more sequences of one or more instructions to processing device 404 for execution. For example, instructions may initially be carried on a disk of a remote computer. The remote computer may load the instructions into its dynamic memory and transmit the instructions over a telephone line using a modem. A modem local to computer system 400 may receive data over a telephone line and convert the data into an infrared signal using an infrared transmitter. An infrared detector coupled to bus 402 may receive the data carried in the infrared signal and place the data on bus 402. Bus 402 carries the data to memory 406, from which processing device 404 retrieves and executes the instructions. Optionally, the instructions received by the memory 406 may be stored on the storage device 410 before or after execution by the processing device 404.
[0160] According to various embodiments, instructions configured to be executed by a processing device to perform a method are stored on a computer-readable medium. The computer-readable medium may be a device for storing digital information. For example, a computer-readable medium includes a compact disc read-only memory (CD-ROM) as known in the art for storing software. The computer-readable medium is accessed by a processor adapted to execute the instructions configured to be executed.
[0161] The foregoing has described one or more exemplary embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0162] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. A typical implementation device is a server system. Of course, this disclosure does not exclude the possibility that, with the future development of computer technology, the computer implementing the functions of the above embodiments can be, for example, a personal computer, a laptop computer, an in-vehicle human-machine interaction device, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0163] While one or more embodiments of this disclosure provide the method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-inventive means. The order of steps listed in the embodiments is merely one possible execution order among many and does not represent the only execution order. In actual device or terminal product execution, the methods shown in the embodiments or drawings can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment, or even a distributed data processing environment).
[0164] The terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitation, the presence of other identical or equivalent elements in the process, method, product, or apparatus that includes said elements is not excluded. For example, the use of terms such as "first" or "second" to denote names does not indicate any particular order.
[0165] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, when implementing one or more embodiments of this disclosure, the functions of each module can be implemented in one or more software and / or hardware, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0166] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0167] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more blocks of a block diagram.
[0168] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more blocks of a block diagram.
[0169] Those skilled in the art will understand that one or more embodiments of this disclosure may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0170] One or more embodiments of this disclosure can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this disclosure can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can reside in local and remote computer storage media, including storage devices.
[0171] The same or similar parts between the various embodiments of this disclosure can be referred to mutually, and each embodiment focuses on describing the differences from other embodiments. In particular, for the apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and relevant parts can be referred to the description of the method embodiments. In the description of this disclosure, the descriptions of terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., mean that the specific feature, structure, material, or characteristic described in connection with the embodiment or example is included in at least one embodiment or example of this disclosure. In this disclosure, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this disclosure and the features of the different embodiments or examples.
[0172] Additionally, when used in this disclosure, the terms “here,” “above,” “below,” “below,” “in the following,” “overall,” and similar terms should refer to the entirety of this disclosure and not any particular part thereof. Furthermore, unless expressly stated otherwise or otherwise understood in the context in which they are used, conditional language used herein, such as “may,” “possibly,” “for example,” “like,” etc., is generally intended to express that certain embodiments include, while other embodiments do not, certain features, elements, and / or states. Therefore, such conditional language is not generally intended to imply that one or more embodiments require features, elements, and / or states in any way, or whether such features, elements, and / or states are included or performed in any particular embodiment.
[0173] The above description is merely an embodiment of one or more embodiments of this disclosure and is not intended to limit the scope of the one or more embodiments of this disclosure. Various modifications and variations can be made to the one or more embodiments of this disclosure by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of the claims.
Claims
1. A method for handling information security incidents, comprising: receiving alert information, the alert information indicating respective information security incidents; for the alert information, conducting a decision process and an execution process, wherein: the decision process comprises: inputting the alert information to each of a plurality of expert agents injected with knowledge of different subfields of the information security technology field, to generate, by the plurality of expert agents respectively, handling actions for the respective information security incidents, and inputting the handling actions generated by the plurality of expert agents to a judge chairman agent, to generate, by the judge chairman agent based on handling action dependency relationships, a handling plan indicating handling actions to be executed and an order thereof; and the execution process comprises: inputting the handling plan generated by the judge chairman agent to a chief engineer agent, to generate, by the chief engineer agent, handling tasks and assign the generated handling tasks to engineer agents of a plurality of engineer agents having different handling skills capable of executing respective handling tasks, and executing the assigned handling tasks via the engineer agents.
2. The method of claim 1, wherein, The judge chairman agent is provided with a handling action precedence table indicating the handling action dependency relationships, the handling action precedence table comprising descriptions about execution conditions of each handling action.
3. The method of claim 1, comprising: receiving a plurality of pieces of alert information; extracting, from each piece of the alert information, a time of occurrence, first information about an attacker, and second information about an attacked party; for alert information whose time of occurrence falls into a time window, grouping the alert information according to at least one of the first information and the second information and a grouping rule, each group of alert information indicating a respective series of information security incidents; and for each group of alert information, conducting the decision process and the execution process, wherein: the decision process comprises: inputting the group of alert information to each of the plurality of expert agents, to generate, by the plurality of expert agents respectively, handling actions for the respective series of information security incidents, and inputting the handling actions generated by the plurality of expert agents to the judge chairman agent, to generate, by the judge chairman agent based on handling action dependency relationships, a handling plan; and the execution process comprises: inputting the handling plan generated by the judge chairman agent to the chief engineer agent, to generate, by the chief engineer agent, handling tasks and assign the generated handling tasks to engineer agents of the plurality of engineer agents capable of executing respective handling tasks, and executing the assigned handling tasks via the engineer agents.
4. The method of claim 3, comprising: sliding the time window; for alert information whose time of occurrence falls into the time window after sliding, regrouping the alert information according to the at least one of the first information and the second information and the grouping rule; and for each group of alert information after regrouping, conducting the decision process and the execution process. A sliding step length of the time window is in a range of one fourth to three fourths of a length of the time window. The grouping rule comprises:
5. The method of claim 4, wherein, 6. The method of claim 3, wherein, one or more of the first information is the same or partially the same; and / or one or more of the second information is the same or partially the same.
7. The method of claim 6, wherein, The first information comprises at least one of an attacker identity, an attacker type, and an attack behavior type, and the second information comprises at least one of a victim identity and a victim type.
8. The method of claim 7, wherein, The victim type, the attacker type, and the attack behavior type are each encoded in a tree-like hierarchy, and in case the victim type, the attacker type, or the attack behavior type is included in a grouping rule, the grouping rule comprises the highest level or levels of classification of that type that are the same.
9. The method of claim 7, wherein, The attacker identity can comprise at least one of an Internet Protocol, IP, address of the attacker, a source port, an IP version, a service type, a reassembly identity, a header check, a Transmission Control Protocol, TCP, flag, a User Datagram Protocol, UDP, flag. The victim identity comprises at least one of an IP address of the victim, an end user, a terminal MAC address, a terminal asset code, and a location code.
10. The method of claim 1, wherein, The alert information is received from a plurality of data sources comprising devices having at least one of computing power, storage power, and network communication power.
11. The method of claim 1, wherein, Each of the plurality of expert agents is provided with a respective set of tools, and is configured to: determine, based on the received alert information, whether a tool needs to be used; and in response to determining that a tool needs to be used, select a tool from the set of tools and generate a handling action based on the selected tool, or in response to determining that a tool does not need to be used, not generate a handling action.
12. The method of claim 11, wherein, Each of the plurality of expert agents is provided with a respective whitelist, and is configured to determine, based on the received alert information and the whitelist, whether a tool needs to be used.
13. The method of claim 1, wherein, The decision process further comprises: generating, by the plurality of expert agents, respectively, an evaluation for the respective information security event; and inputting the evaluations generated by the plurality of expert agents together with the respective handling actions to a jury chairman agent to generate, by the jury chairman agent, a first incident report and a handling plan for the respective information security event, the first incident report indicating the evaluation of the jury chairman agent.
14. The method of claim 13, wherein, The execution process further comprises: providing, by the engineer agents, the execution results of the handling tasks they are assigned to the chief engineer agent; generating, by the chief engineer agent, a second incident report for the respective information security event, the second incident report indicating the execution results.
15. The method of claim 14, wherein, The chief engineer agent is configured to not generate the second incident report in case all the received execution results indicate no need for action.
16. The method of claim 14, wherein, In case at least one execution result indicates a failure of execution, outputting a human intervention prompt.
17. The method of claim 14, comprising: inputting the alert information and the first incident report, the handling plan, and the second incident report generated for the alert information to a report agent to generate, by the report agent, a final incident report.
18. The method of claim 1, wherein, The plurality of expert agents comprises an intrusion detection expert agent, a data security expert agent, a network security expert agent, a virus analysis expert agent, and an encryption and decryption expert agent. The plurality of engineer agents comprises a network device engineer agent, a firewall engineer agent, a Web application firewall engineer agent, a terminal engineer agent, and a server engineer agent.
19. The method of claim 3, wherein, The extraction of the occurrence time, the first information, and the second information from each piece of alarm information is performed by a large language model.
20. An electronic device, comprising: a processor; a memory storing computer-executable instructions that, when executed by the processor, cause the processor to perform the method of any one of claims 1-19.
21. A computer-readable storage medium having stored thereon computer-executable instructions that, when executed by a processor, cause the processor to perform the method of any one of claims 1-19.
22. A computer program product comprising instructions that, when executed by a processor, implement the method of any one of claims 1-19.
23. A system for handling information security events, comprising: an acquisition module configured to receive alarm information indicating respective information security events; and a handling module comprising a plurality of expert agents injected with knowledge of different subfields in the field of information security technology, a judge chairman agent, a chief engineer agent, and a plurality of engineer agents with different handling skills, the handling module being configured to, for the alarm information, perform a decision process and an execution process, wherein: the decision process comprises: inputting the alarm information into each expert agent of the plurality of expert agents to generate, by the plurality of expert agents, handling actions for respective information security events, and inputting the handling actions generated by the plurality of expert agents into the judge chairman agent to generate, by the judge chairman agent, a handling plan based on handling action dependency relationships, the handling plan indicating handling actions to be executed and an order thereof; and the execution process comprises: inputting the handling plan generated by the judge chairman agent into the chief engineer agent to generate handling tasks by the chief engineer agent and assign the generated handling tasks to engineer agents of the plurality of engineer agents capable of executing respective handling tasks, and executing the assigned handling tasks via the engineer agents.
24. The system of claim 23, wherein, The acquisition module is configured to receive a plurality of pieces of alarm information, and the system further comprises: an extraction module configured to extract, from each piece of alarm information of the plurality of pieces of alarm information, an occurrence time, first information about an attacker, and second information about an attacked party; a grouping module configured to, for alarm information with an occurrence time falling within a time window, group the alarm information according to at least one of the first information and the second information and a grouping rule, each group of alarm information indicating a respective series of information security events, The treatment module is configured to, for each set of alarm information, perform the decision process and the execution process, wherein: the decision process comprises: inputting the set of alarm information into each of the plurality of expert agents to generate, by the plurality of expert agents respectively, a treatment action for a corresponding series of information security events, and inputting the treatment actions generated by the plurality of expert agents into a jury chairman agent to generate, by the jury chairman agent, a treatment plan based on a treatment action dependency relationship; and the execution process comprises: inputting the treatment plan generated by the jury chairman agent into a chief engineer agent to generate, by the chief engineer agent, a treatment task and assign the generated treatment task to an engineer agent capable of performing the corresponding treatment task in the plurality of engineer agents, and performing the assigned treatment task via the engineer agent.