Security alarm automatic response processing method, device and equipment of enterprise digital system and medium

By collecting and standardizing alarm data from multiple data sources, constructing alarm relationship graphs, and using machine learning algorithms to identify attack chains, the problem of low alarm data processing efficiency in enterprise digital systems has been solved, achieving efficient automatic response and low false alarm rate.

CN121727818APending Publication Date: 2026-03-24HANGZHOU DBAPPSECURITY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-25
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In enterprise digital systems, massive amounts of security alert data lead to high false alarm rates, obscuring real threats, lack of intelligent automatic response mechanisms, and long average response times.

Method used

Alarm data is collected from multiple data sources by a pre-set data collector, standardized and contextual information is added, an alarm relationship graph is constructed, and graph clustering and machine learning algorithms are used to identify alarm data with the same source and logical relationship, generate attack chain information, and process risk levels.

Benefits of technology

It improves the efficiency of automatic alarm response, reduces false alarm rate, ensures that real threats are not overwhelmed, and reduces manual operation costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121727818A_ABST
    Figure CN121727818A_ABST
Patent Text Reader

Abstract

The invention discloses a security alarm automatic response processing method, device and equipment for an enterprise digital system and a medium, which are applied to a security operation center and relate to the technical field of network security, and the method comprises the following steps: standardizing alarm data collected by a plurality of target data sources related to the enterprise digital system, and adding corresponding context information; generating an alarm relation graph between the alarm information and the alarm object based on the obtained target alarm data, determining first alarm data having a homologous relationship from the alarm relation graph by using a graph clustering algorithm, and determining second alarm data having a logic relationship by using an HDBSCAN clustering algorithm so as to determine a target alarm event; and analyzing the target alarm event based on a machine learning model to obtain an analysis result, and performing alarm processing operation of the target risk level by using the alarm relation graph, the target alarm event, the analysis result and the attack chain information. The automatic response efficiency of the alarm is improved, and real threats are prevented from being submerged.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, equipment and medium for automatic response processing of security alarms in enterprise digital systems. Background Technology

[0002] As enterprises scale up their digitalization, their Security Operations Centers (SOCs) receive massive amounts of security alert logs from EDRs (Extended Detection and Response), IDS (Intrusion Detection System) / IPS (Intrusion Prevention System), logging systems, cloud platforms, and medical / industrial control systems. Due to the sheer volume and high repetition of these alerts, SOC personnel struggle to cope. Traditional rule-based aggregation methods have limited capabilities, failing to identify attack chains across assets and timelines, leading to high false alarm rates and obscuring real threats. Furthermore, the lack of intelligent automated response mechanisms results in long average response times.

[0003] As can be seen from the above, improving the efficiency of automatic alarm response and preventing real threats from being overwhelmed are urgent problems to be solved. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a method, apparatus, device, and medium for automatic response processing of security alarms in enterprise digital systems, which can improve the efficiency of automatic alarm response and prevent real threats from being overwhelmed. The specific solution is as follows:

[0005] Firstly, this application provides an automatic response and processing method for security alarms in an enterprise digital system, applied to a security operations center, including:

[0006] Alarm data is collected from multiple target data sources related to the enterprise's digital system using a preset data collector, and the alarm data is standardized according to a preset template to obtain standardized alarm data. Corresponding context information is added to the standardized alarm data to obtain target alarm data.

[0007] Based on the target alarm data, an alarm relationship graph between alarm information and alarm objects is generated. A graph clustering algorithm is used to determine the first alarm data with a common source relationship from the alarm relationship graph. Based on a preset time window and using the HDBSCAN clustering algorithm, a second alarm data with a logical relationship is determined. The target alarm event is determined based on the first alarm data and the second alarm data.

[0008] The target alarm events are analyzed based on a machine learning model to obtain corresponding analysis results. The corresponding attack chain information is determined using the alarm relationship graph and the target alarm events. Based on the analysis results and the attack chain information, alarm processing operations for the target risk level are performed.

[0009] Optionally, the step of collecting alarm data from multiple target data sources related to the enterprise's digital system using a preset data collector, and standardizing the alarm data according to a preset template to obtain standardized alarm data, includes:

[0010] Alarm data is collected from multiple target data sources related to enterprise digital systems using streaming processing tools and log collectors; the streaming processing tools include a distributed streaming processing platform and a streaming data processing engine; the target data sources include intrusion detection systems, intrusion prevention coefficients, endpoint detection and response platforms, firewalls, security information management systems, cloud logs, application logs, network traffic data, vulnerability scan results, and threat intelligence;

[0011] The alarm data is standardized based on a preset template to obtain standardized alarm data. The preset template includes data source, timestamp, source IP address, target IP address, client, alarm type, alarm severity, feature identifier, original payload, and related context.

[0012] Optionally, adding corresponding context information to the standardized alarm data to obtain the target alarm data includes:

[0013] Add corresponding context information to the standardized alarm data to obtain the alarm data after addition; the context information includes IP intelligence information, domain name intelligence information, asset classification information and geographical location information;

[0014] The added alarm data is cached using a remote dictionary service to obtain the target alarm data.

[0015] Optionally, generating an alarm relationship diagram between alarm information and alarm objects based on the target alarm data includes:

[0016] The alarm objects in the target alarm data are identified as nodes, and the association between the alarm information in the target alarm data and the alarm objects is identified as edges;

[0017] Construct an alarm relationship graph between the alarm information and the alarm object based on the nodes and the edges;

[0018] The alarm objects include the source IP address, the target IP address, the user terminal, and the assets and business processes involved in the target alarm data.

[0019] Optionally, the step of using a graph clustering algorithm to determine first alarm data with a common origin from the alarm relationship graph, determining second alarm data with a logical relationship based on a preset time window and using the HDBSCAN clustering algorithm, and determining the target alarm event based on the first alarm data and the second alarm data includes:

[0020] Using graph neural networks and the Louvain algorithm, related alarm data with the same source IP address, the same asset, and the same user terminal are obtained from the alarm relationship graph, and the related alarm data is identified as the first alarm data;

[0021] Based on a preset time window and using the HDBSCAN clustering algorithm, logical alarm data with sequential logical relationships within the same time range are identified, and the logical alarm data is identified as the second alarm data.

[0022] The first alarm data and the second alarm data are aggregated to obtain the target alarm event.

[0023] Optionally, the step of analyzing the target alarm events based on a machine learning model to obtain corresponding analysis results, determining the corresponding attack chain information using the alarm relationship graph and the target alarm events, and performing alarm processing operations based on the analysis results and the attack chain information for the target risk level includes:

[0024] The target alarm data is analyzed using XGBoost and Transformer models to obtain analysis results including target threat level and threat confidence.

[0025] The alarm relationship diagram and the target alarm events are deduced to generate attack chain information in a preset order;

[0026] Based on the attack chain information and the analysis results, and using a preset strategy library, the target risk level is determined, and corresponding alarm processing operations are performed using the target risk level.

[0027] Optionally, the step of performing the corresponding alarm processing operation based on the target risk level includes:

[0028] If the target risk level is the first risk level, then collect log information related to the target alarm event;

[0029] If the target risk level is the second risk level, an alarm processing request containing the target alarm event will be sent to the relevant security personnel. After the relevant security personnel confirm the request, the corresponding alarm processing operation will be performed.

[0030] If the target risk level is the third risk level, then the corresponding alarm handling scheme is matched, and the corresponding alarm handling operation is performed based on the alarm handling scheme.

[0031] Secondly, this application provides an automatic security alarm response processing device for an enterprise digital system, applied in a security operations center, comprising:

[0032] The alarm data acquisition module is used to collect alarm data from multiple target data sources related to the enterprise's digital system using a preset data collector, and to standardize the alarm data according to a preset template to obtain standardized alarm data. Corresponding context information is added to the standardized alarm data to obtain target alarm data.

[0033] The alarm event determination module is used to generate an alarm relationship graph between alarm information and alarm objects based on the target alarm data, use a graph clustering algorithm to determine the first alarm data with a common source relationship from the alarm relationship graph, use a preset time window and HDBSCAN clustering algorithm to determine the second alarm data with a logical relationship, and determine the target alarm event based on the first alarm data and the second alarm data.

[0034] The alarm processing module is used to analyze the target alarm events based on a machine learning model to obtain corresponding analysis results, determine the corresponding attack chain information using the alarm relationship graph and the target alarm events, and perform alarm processing operations based on the analysis results and the attack chain information to assess the target risk level.

[0035] Thirdly, this application provides an electronic device, comprising:

[0036] Memory, used to store computer programs;

[0037] A processor is used to execute the computer program to implement the aforementioned automatic response processing method for security alarms in enterprise digital systems.

[0038] Fourthly, this application provides a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned automatic security alarm response processing method for enterprise digital systems.

[0039] This application utilizes a preset data collector to collect alarm data from multiple target data sources related to the enterprise's digital system, and standardizes the alarm data according to a preset template to obtain standardized alarm data. Corresponding context information is added to the standardized alarm data to obtain target alarm data. An alarm relationship graph between alarm information and alarm objects is generated based on the target alarm data. A graph clustering algorithm is used to determine first alarm data with a common source relationship from the alarm relationship graph. Based on a preset time window and using the HDBSCAN clustering algorithm, second alarm data with a logical relationship is determined. Target alarm events are determined based on the first and second alarm data. The target alarm events are analyzed using a machine learning model to obtain corresponding analysis results. The alarm relationship graph and the target alarm events are used to determine corresponding attack chain information. Based on the analysis results and the attack chain information, alarm processing operations are performed to determine the target risk level.

[0040] As shown above, this application collects alarm data from multiple data sources and standardizes the alarm data using a preset template to ensure a unified format for alarm data from different sources. Contextual information is added to the alarm data to form complete target alarm data. Next, an alarm relationship graph is constructed based on the internal relationships within the target alarm data, and clustering algorithms are used to identify alarm data with shared origins and logical relationships to form target alarm events. Then, machine learning algorithms are used to analyze the target alarm events, and alarm processing operations are performed based on the analysis results and corresponding attack chain information. In this way, even when faced with a large amount of alarm data, it can be organized into a smaller number of alarm events, and the accuracy of threat identification can be improved by utilizing alarm relationship graphs and machine learning algorithms, while reducing manual operation costs. Attached Figure Description

[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0042] Figure 1 This application discloses a flowchart of an automatic response and processing method for security alarms in an enterprise digital system.

[0043] Figure 2 This is a schematic diagram of the structure of an automatic security alarm response and processing device for an enterprise digital system disclosed in this application;

[0044] Figure 3 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0045] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0046] Currently, traditional rule-based aggregation capabilities are limited, making it difficult to identify attack chains across assets and time periods, easily leading to high false alarm rates and the suppression of real threats; moreover, it lacks intelligent automatic response mechanisms, resulting in long average response times. To address this, this application provides an automatic security alarm response processing method for enterprise digital systems. Even when faced with a large amount of alarm data, it can organize it into a smaller number of alarm events, and utilize alarm relationship graphs and machine learning algorithms to improve the accuracy of threat identification while reducing manual operation costs.

[0047] See Figure 1 As shown in the figure, this invention discloses an automatic response and processing method for security alarms in an enterprise digital system, applied to a security operations center, including:

[0048] Step S11: Collect alarm data from multiple target data sources related to the enterprise's digital system using a preset data collector, and standardize the alarm data according to a preset template to obtain standardized alarm data. Add corresponding context information to the standardized alarm data to obtain target alarm data.

[0049] In this embodiment, all possible security alarm data are collected from multiple target data sources related to the enterprise's digital system. During the collection process, tools such as Kafka (a distributed stream processing platform), Fluentd (a streaming data processing engine), and Logstash (a log collector) can be used to centrally collect alarm data to avoid data loss or delay. After obtaining the alarm data, the alarm data is formatted and standardized based on a unified preset template to obtain standardized alarm data. Specifically, the step of collecting alarm data from multiple target data sources related to the enterprise's digital system using a preset data collector, and standardizing the alarm data according to a preset template to obtain standardized alarm data, includes: collecting alarm data from multiple target data sources related to the enterprise's digital system using streaming processing tools and log collectors; the streaming processing tools include a distributed streaming processing platform and a streaming data processing engine; the target data sources include intrusion detection systems, intrusion prevention coefficients, endpoint detection and response platforms, firewalls, security information management systems, cloud logs, application logs, network traffic data, vulnerability scan results, and threat intelligence; standardizing the alarm data based on a preset template to obtain standardized alarm data; the preset template includes data source, timestamp, source IP address, target IP address, client, alarm type, alarm severity, feature identifier, original payload, and related context.

[0050] Understandably, relying solely on the basic information of the alarm data is insufficient; it is necessary to supplement the alarm data with contextual information capable of assessing risk, such as whether the IP address of the alarm data is a known malicious IP, or whether the domain name poses a risk. Then, Redis (Remote Dictionary Server) is used to cache this contextual information to obtain the target alarm data. Specifically, adding corresponding contextual information to the standardized alarm data to obtain the target alarm data includes: adding corresponding contextual information to the standardized alarm data to obtain the added alarm data; the contextual information includes IP intelligence information, domain name intelligence information, asset classification information, and geographical location information; and using a remote dictionary service to cache the added alarm data to obtain the target alarm data.

[0051] Step S12: Generate an alarm relationship graph between alarm information and alarm objects based on the target alarm data. Use a graph clustering algorithm to determine the first alarm data with a common source relationship from the alarm relationship graph. Based on a preset time window and using the HDBSCAN clustering algorithm, determine the second alarm data with a logical relationship. Determine the target alarm event based on the first alarm data and the second alarm data.

[0052] In this embodiment, alarm information in the target alarm data is linked to alarm objects based on an alarm relationship graph; the alarm objects include user terminals, assets, and processes. Specifically, generating an alarm relationship graph between alarm information and alarm objects based on the target alarm data includes: determining alarm objects in the target alarm data as nodes, and determining the association between alarm information in the target alarm data and alarm objects as edges; constructing an alarm relationship graph between alarm information and alarm objects based on the nodes and edges; wherein, the alarm objects include the source IP address, the target IP address, the user terminal, the assets involved in the target alarm data, and the business processes.

[0053] It is understandable that by using graph neural networks and clustering algorithms such as Louvain to find first alarm data with the same origin from the alarm relationship graph, and using the HDBSCAN clustering algorithm to find second alarm data that occurred sequentially and have logical correlation within a preset time range, and then merging multiple first alarm data and second alarm data to obtain the target alarm event, the number of alarms that need to be processed can be greatly reduced. Specifically, the step of using a graph clustering algorithm to determine first alarm data with a common source relationship from the alarm relationship graph, determining second alarm data with a logical relationship based on a preset time window and using the HDBSCAN clustering algorithm, and determining the target alarm event based on the first alarm data and the second alarm data includes: using a graph neural network and the Louvain algorithm to obtain associated alarm data with the same source IP address, the same asset, and the same user terminal from the alarm relationship graph, and determining the associated alarm data as the first alarm data; determining logical alarm data with a sequential logical relationship within the same time range based on a preset time window and using the HDBSCAN clustering algorithm, and determining the logical alarm data as the second alarm data; and aggregating the first alarm data and the second alarm data to obtain the target alarm event.

[0054] Step S13: Analyze the target alarm events based on the machine learning model to obtain the corresponding analysis results. Use the alarm relationship diagram and the target alarm events to determine the corresponding attack chain information. Perform alarm processing operations based on the analysis results and the attack chain information to determine the target risk level.

[0055] In this embodiment, an AI model is used to determine whether the target alert event poses a risk. Specifically, XGBoost (eXtreme Gradient Boosting) and the Transformer model (a deep learning model) are used to analyze the target alert data to obtain analysis results including the target threat level and threat confidence. The threat confidence represents the model's degree of confidence in the analysis results. The analysis process can be explained using SHAP (SHapley Additive ex Planations), a model interpretability tool, to facilitate review by relevant security personnel. Then, the alert relationship graph and the target alert event are deduced to reconstruct the attacker's attack steps, obtaining attack chain information. This allows relevant security personnel to understand the threat's development stage and to take targeted action based on the attack chain information.

[0056] Specifically, the step of analyzing the target alarm events based on a machine learning model to obtain corresponding analysis results, determining the corresponding attack chain information using the alarm relationship graph and the target alarm events, and performing alarm processing operations based on the analysis results and the attack chain information to determine the target risk level includes: analyzing the target alarm data using XGBoost and Transformer models to obtain analysis results including target threat level and threat confidence; deriving attack chain information in a preset order from the alarm relationship graph and the target alarm events; determining the target risk level based on the attack chain information and the analysis results using a preset policy library, and performing corresponding alarm processing operations based on the target risk level.

[0057] Understandably, different alarm handling operations are performed based on different risk levels. If the target risk level is low, more log information related to the target alarm event is collected and observation continues without affecting normal business operations. If the target risk level is medium, an alarm handling request is sent to relevant security personnel, and alarm handling operations are performed after approval and confirmation from the relevant security personnel, such as blocking the attacker's IP address and isolating infected devices. If the target risk level is high, the relevant security personnel confirm the alarm immediately, and an alarm handling solution is automatically matched from the Playbook (a systematic policy or operation guide). Specifically, the step of performing corresponding alarm processing operations based on the target risk level includes: if the target risk level is a first risk level, collecting log information related to the target alarm event; if the target risk level is a second risk level, sending an alarm processing request containing the target alarm event to relevant security personnel, and performing corresponding alarm processing operations after confirmation by the relevant security personnel; if the target risk level is a third risk level, matching a corresponding alarm processing scheme, and performing corresponding alarm processing operations based on the alarm processing scheme.

[0058] Furthermore, the Orchestrator tool (a distributed system management tool) can be used to call the security device's interface to automatically complete operations such as isolating hosts. Specifically, if a legitimate IP address is mistakenly blocked, a rollback mechanism can be used for recovery, and change logs can be used to record in detail the alarm handling operations corresponding to the target alarm event. After all alarm handling operations are automatically executed, a second review can be performed to avoid errors. Additionally, the alarm handling results are fed back to the machine learning model for iterative optimization.

[0059] As shown above, this application collects alarm data from multiple data sources and standardizes the alarm data using a preset template to ensure a unified format for alarm data from different sources. Contextual information is added to the alarm data to form complete target alarm data. Next, an alarm relationship graph is constructed based on the internal relationships within the target alarm data, and clustering algorithms are used to identify alarm data with shared origins and logical relationships to form target alarm events. Then, machine learning algorithms are used to analyze the target alarm events, and alarm processing operations are performed based on the analysis results and corresponding attack chain information. In this way, even when faced with a large amount of alarm data, it can be organized into a smaller number of alarm events, and the accuracy of threat identification can be improved by utilizing alarm relationship graphs and machine learning algorithms, while reducing manual operation costs.

[0060] Accordingly, see Figure 2As shown, this application also provides an automatic security alarm response processing device for an enterprise digital system, applied in a security operations center, comprising:

[0061] The alarm data acquisition module 11 is used to collect alarm data from multiple target data sources related to the enterprise digital system using a preset data collector, and to standardize the alarm data according to a preset template to obtain standardized alarm data. Corresponding context information is added to the standardized alarm data to obtain target alarm data.

[0062] The alarm event determination module 12 is used to generate an alarm relationship graph between alarm information and alarm objects based on the target alarm data, determine the first alarm data with a common source relationship from the alarm relationship graph using a graph clustering algorithm, determine the second alarm data with a logical relationship based on a preset time window and using the HDBSCAN clustering algorithm, and determine the target alarm event based on the first alarm data and the second alarm data.

[0063] The alarm processing module 13 is used to analyze the target alarm event based on a machine learning model to obtain the corresponding analysis results, determine the corresponding attack chain information using the alarm relationship graph and the target alarm event, and perform alarm processing operations for the target risk level based on the analysis results and the attack chain information.

[0064] In some specific embodiments, the alarm data acquisition module 11 may specifically include:

[0065] The alarm data acquisition unit is used to collect alarm data from multiple target data sources related to the enterprise's digital system using streaming processing tools and log collectors; the streaming processing tools include a distributed streaming processing platform and a streaming data processing engine; the target data sources include intrusion detection systems, intrusion prevention coefficients, endpoint detection and response platforms, firewalls, security information management systems, cloud logs, application logs, network traffic data, vulnerability scan results, and threat intelligence;

[0066] The data standardization unit is used to standardize the alarm data based on a preset template to obtain standardized alarm data. The preset template includes data source, timestamp, source IP address, target IP address, user terminal, alarm type, alarm severity, feature identifier, original payload, and related context.

[0067] In some specific embodiments, the alarm data acquisition module 11 may specifically include:

[0068] The data adding unit is used to add corresponding context information to the standardized alarm data to obtain the added alarm data; the context information includes IP intelligence information, domain name intelligence information, asset classification information and geographical location information;

[0069] The data caching unit is used to cache the added alarm data using a remote dictionary service to obtain the target alarm data.

[0070] In some specific embodiments, the alarm event determination module 12 may specifically include:

[0071] An edge determination unit is used to determine the alarm objects in the target alarm data as nodes, and to determine the association between the alarm information in the target alarm data and the alarm objects as edges;

[0072] The relationship graph construction unit is used to construct an alarm relationship graph between the alarm information and the alarm object based on the nodes and the edges.

[0073] In some specific embodiments, the alarm event determination module 12 may specifically include:

[0074] The first alarm data determination unit is used to obtain associated alarm data with the same source IP address, the same asset, and the same user terminal from the alarm relationship graph using graph neural network and Louvain algorithm, and determine the associated alarm data as the first alarm data;

[0075] The second alarm data determination unit is used to determine logical alarm data that have a sequential logical relationship within the same time range based on a preset time window and using the HDBSCAN clustering algorithm, and to determine the logical alarm data as the second alarm data.

[0076] The data aggregation unit is used to aggregate the first alarm data and the second alarm data to obtain the target alarm event.

[0077] In some specific embodiments, the alarm processing module 13 may specifically include:

[0078] The data analysis unit is used to analyze the target alarm data using XGBoost and Transformer models to obtain analysis results including target threat level and threat confidence.

[0079] An attack chain information generation unit is used to deduce the alarm relationship diagram and the target alarm events to generate attack chain information in a preset order.

[0080] The alarm processing unit is used to determine the target risk level based on the attack chain information and the analysis results and using a preset strategy library, so as to perform corresponding alarm processing operations based on the target risk level.

[0081] In some specific embodiments, the alarm processing module 13 may specifically include:

[0082] A log information collection unit is used to collect log information related to the target alarm event if the target risk level is the first risk level.

[0083] The request sending unit is configured to send an alarm processing request containing the target alarm event to relevant security personnel if the target risk level is the second risk level, and to perform the corresponding alarm processing operation after the relevant security personnel confirm the request.

[0084] The processing scheme matching unit is used to match the corresponding alarm processing scheme if the target risk level is the third risk level, and to perform the corresponding alarm processing operation based on the alarm processing scheme.

[0085] Furthermore, embodiments of this application also disclose an electronic device, Figure 3 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the automatic security alarm response processing method for enterprise digital systems disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0086] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0087] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0088] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the automatic security alarm response processing method for an enterprise digital system executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.

[0089] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned automatic security alarm response processing method for enterprise digital systems. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0090] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0091] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0092] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0093] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0094] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for automatically responding to and processing security alarms in an enterprise digital system, characterized in that, Applied to security operations centers, including: Alarm data is collected from multiple target data sources related to the enterprise's digital system using a preset data collector, and the alarm data is standardized according to a preset template to obtain standardized alarm data. Corresponding context information is added to the standardized alarm data to obtain target alarm data. Based on the target alarm data, an alarm relationship graph between alarm information and alarm objects is generated. A graph clustering algorithm is used to determine the first alarm data with a common source relationship from the alarm relationship graph. Based on a preset time window and using the HDBSCAN clustering algorithm, a second alarm data with a logical relationship is determined. The target alarm event is determined based on the first alarm data and the second alarm data. The target alarm events are analyzed based on a machine learning model to obtain corresponding analysis results. The corresponding attack chain information is determined using the alarm relationship graph and the target alarm events. Based on the analysis results and the attack chain information, alarm processing operations for the target risk level are performed.

2. The automatic response and processing method for security alarms in an enterprise digital system according to claim 1, characterized in that, The process involves using a preset data collector to collect alarm data from multiple target data sources related to the enterprise's digital system, and standardizing the alarm data according to a preset template to obtain standardized alarm data, including: Alarm data is collected from multiple target data sources related to enterprise digital systems using streaming processing tools and log collectors; the streaming processing tools include a distributed streaming processing platform and a streaming data processing engine; the target data sources include intrusion detection systems, intrusion prevention coefficients, endpoint detection and response platforms, firewalls, security information management systems, cloud logs, application logs, network traffic data, vulnerability scan results, and threat intelligence; The alarm data is standardized based on a preset template to obtain standardized alarm data. The preset template includes data source, timestamp, source IP address, target IP address, client, alarm type, alarm severity, feature identifier, original payload, and related context.

3. The automatic response and processing method for security alarms in an enterprise digital system according to claim 1, characterized in that, Adding corresponding context information to the standardized alarm data to obtain the target alarm data includes: Add corresponding context information to the standardized alarm data to obtain the alarm data after addition; the context information includes IP intelligence information, domain name intelligence information, asset classification information and geographical location information; The added alarm data is cached using a remote dictionary service to obtain the target alarm data.

4. The automatic response and processing method for security alarms in an enterprise digital system according to claim 2, characterized in that, The step of generating an alarm relationship diagram between alarm information and alarm objects based on the target alarm data includes: The alarm objects in the target alarm data are identified as nodes, and the association between the alarm information in the target alarm data and the alarm objects is identified as edges; Construct an alarm relationship graph between the alarm information and the alarm object based on the nodes and the edges; The alarm objects include the source IP address, the target IP address, the user terminal, and the assets and business processes involved in the target alarm data.

5. The automatic response and processing method for security alarms in an enterprise digital system according to claim 4, characterized in that, The process of determining first alarm data with a common origin from the alarm relationship graph using a graph clustering algorithm, determining second alarm data with a logical relationship based on a preset time window and using the HDBSCAN clustering algorithm, and determining the target alarm event based on the first alarm data and the second alarm data includes: Using graph neural networks and the Louvain algorithm, related alarm data with the same source IP address, the same asset, and the same user terminal are obtained from the alarm relationship graph, and the related alarm data is identified as the first alarm data; Based on a preset time window and using the HDBSCAN clustering algorithm, logical alarm data with sequential logical relationships within the same time range are identified, and the logical alarm data is identified as the second alarm data. The first alarm data and the second alarm data are aggregated to obtain the target alarm event.

6. The automatic response processing method for security alarms in an enterprise digital system according to any one of claims 1 to 5, characterized in that, The process of analyzing the target alarm events based on a machine learning model to obtain corresponding analysis results, determining the corresponding attack chain information using the alarm relationship graph and the target alarm events, and performing alarm processing operations based on the analysis results and the attack chain information to assess the target risk level includes: The target alarm data is analyzed using XGBoost and Transformer models to obtain analysis results including target threat level and threat confidence. The alarm relationship diagram and the target alarm events are deduced to generate attack chain information in a preset order; Based on the attack chain information and the analysis results, and using a preset strategy library, the target risk level is determined, and corresponding alarm processing operations are performed using the target risk level.

7. The automatic response and processing method for security alarms in an enterprise digital system according to claim 6, characterized in that, The step of performing corresponding alarm processing operations based on the target risk level includes: If the target risk level is the first risk level, then collect log information related to the target alarm event; If the target risk level is the second risk level, an alarm processing request containing the target alarm event will be sent to the relevant security personnel. After the relevant security personnel confirm the request, the corresponding alarm processing operation will be performed. If the target risk level is the third risk level, then the corresponding alarm handling scheme is matched, and the corresponding alarm handling operation is performed based on the alarm handling scheme.

8. An automatic security alarm response and processing device for an enterprise digital system, characterized in that, Applied to security operations centers, including: The alarm data acquisition module is used to collect alarm data from multiple target data sources related to the enterprise's digital system using a preset data collector, and to standardize the alarm data according to a preset template to obtain standardized alarm data. Corresponding context information is added to the standardized alarm data to obtain target alarm data. The alarm event determination module is used to generate an alarm relationship graph between alarm information and alarm objects based on the target alarm data, use a graph clustering algorithm to determine the first alarm data with a common source relationship from the alarm relationship graph, use a preset time window and HDBSCAN clustering algorithm to determine the second alarm data with a logical relationship, and determine the target alarm event based on the first alarm data and the second alarm data. The alarm processing module is used to analyze the target alarm events based on a machine learning model to obtain corresponding analysis results, determine the corresponding attack chain information using the alarm relationship graph and the target alarm events, and perform alarm processing operations based on the analysis results and the attack chain information to assess the target risk level.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor is configured to execute the computer program to implement the automatic security alarm response processing method for an enterprise digital system as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store computer programs, wherein the computer programs, when executed by a processor, implement the automatic security alarm response processing method for an enterprise digital system as described in any one of claims 1 to 7.