Security threat detection and analysis method and device, equipment and medium
By using correlation analysis and intelligent comprehensive analysis of multi-source alarm data, the problem of low accuracy in existing security threat detection has been solved, achieving efficient and accurate security threat detection and automated report generation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 深圳市和讯华谷信息技术有限公司
- Filing Date
- 2026-04-08
- Publication Date
- 2026-05-08
AI Technical Summary
Existing security threat detection and analysis methods have low accuracy, high false alarm rate, serious false negative rate, rely on manual analysis, are inefficient, and cannot effectively identify complex attack chains.
By analyzing the correlation of multi-source alarm data and detecting anomalies, we can identify hidden connections between attack segments, reconstruct machine attack chains, analyze user behavior timelines, conduct intelligent comprehensive analysis, and generate security threat reports.
It improves the accuracy of security threat detection, reduces false alarms, enhances analysis efficiency, and provides refined risk assessment and automated report generation.
Smart Images

Figure CN122001684A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security threat detection and analysis equipment technology, and in particular to a security threat detection and analysis method, apparatus, equipment and medium. Background Technology
[0002] With the rapid development of information technology, cybersecurity threats are becoming increasingly complex and covert. Traditional cybersecurity monitoring and analysis methods, when facing complex attacks such as advanced persistent threats (APPTs), typically rely on a single alert source or simple rule matching. This results in a large number of isolated alerts, failing to identify complete attack chains or detect complex temporal attack behaviors, leading to high false positives and serious false negatives. Furthermore, existing methods largely depend on the personal experience of security operations personnel for analysis and judgment, resulting in highly subjective and inconsistent risk assessment results. Faced with massive amounts of alert data, security operations personnel must invest significant time in manual screening, clue linking, and report writing, resulting in slow overall response times and a high risk of missing critical threats under sustained pressure. Overall, most existing security tools remain at the stage of passively displaying alert information, lacking sufficient intelligence to cope with the challenges of today's automated and large-scale cyberattacks. Therefore, the accuracy of existing security threat detection and analysis still needs improvement. Summary of the Invention
[0003] This invention provides a security threat detection and analysis method, apparatus, equipment, and medium, aiming to solve the problem of low accuracy in existing security threat detection and analysis methods.
[0004] In a first aspect, embodiments of the present invention provide a security threat detection and analysis method, including: Receive alarm data from multiple security data sources, and perform multi-source correlation analysis and abnormal behavior detection on the alarm data respectively to generate correlation analysis results; Based on the correlation analysis results, machine attack chain analysis is performed to generate attack chain analysis results; Based on the alarm data, perform time-series analysis of user behavior to generate time-series analysis results. Based on the correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results, intelligent comprehensive analysis is performed to generate intelligent analysis results. A security threat report is generated and output based on the intelligent analysis results.
[0005] Secondly, embodiments of the present invention also provide a security threat detection and analysis device, comprising: The analysis and detection unit is used to receive alarm data from multiple security data sources, and to perform multi-source correlation analysis and abnormal behavior detection on the alarm data to generate correlation analysis results. The first analysis unit is used to perform machine attack link analysis based on the correlation analysis results and generate attack link analysis results. The second analysis unit is used to perform time-series analysis of user behavior based on the alarm data and generate time-series analysis results. The third analysis unit is used to perform intelligent comprehensive analysis based on the correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results, and generate intelligent analysis results. The generation unit is used to generate and output a security threat report based on the intelligent analysis results.
[0006] Thirdly, embodiments of the present invention also provide a security threat detection and analysis device including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the above-described method.
[0007] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the above-described method.
[0008] This invention provides a security threat detection and analysis method, apparatus, device, and medium. The method includes: receiving alarm data from multiple security data sources, and performing multi-source correlation analysis and abnormal behavior detection on the alarm data to generate correlation analysis results; performing machine attack chain analysis based on the correlation analysis results to generate attack chain analysis results; performing user behavior time-series analysis based on the alarm data to generate behavior time-series analysis results; performing intelligent comprehensive analysis based on the correlation analysis results, the attack chain analysis results, and the behavior time-series analysis results to generate intelligent analysis results; and generating and outputting a security threat report based on the intelligent analysis results. The technical solution of this invention identifies hidden connections between attack segments through correlation analysis and anomaly detection of multi-source alarm data; reconstructs the complete attack chain through machine attack chain analysis to restore the attacker's intent; discovers internal abnormal behaviors through user behavior time-series analysis; and performs intelligent comprehensive analysis of the multi-dimensional analysis results to output a security threat report. This solves the problems of high false positive rates and severe false negatives in traditional methods, thereby improving the accuracy of security threat detection and analysis. Attached Figure Description
[0009] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0010] Figure 1This is a flowchart illustrating a security threat detection and analysis method according to an embodiment of the present invention. Figure 2 This is a schematic diagram of a sub-process of a security threat detection and analysis method provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of another sub-process of a security threat detection and analysis method provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of another sub-process of a security threat detection and analysis method provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of another sub-process of a security threat detection and analysis method provided in an embodiment of the present invention; Figure 6 This is a schematic block diagram of a security threat detection and analysis device provided in an embodiment of the present invention; Figure 7 This is a schematic block diagram of a security threat detection and analysis device provided in an embodiment of the present invention. Detailed Implementation
[0011] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0012] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0013] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0014] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0015] As used in this specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if [described condition or event] is detected" may be interpreted, depending on the context, as "once determined," "in response to determination," "once [described condition or event] is detected," or "in response to detection of [described condition or event]."
[0016] This invention proposes a security threat detection and analysis method that addresses the low accuracy of existing security threat detection and analysis methods. In this embodiment, through correlation analysis and anomaly detection of multi-source alarm data, hidden connections between attack segments are identified; through machine attack chain analysis, the complete attack chain is reconstructed to restore the attacker's intent; through user behavior time sequence analysis, internal abnormal behaviors are discovered; and intelligent comprehensive analysis of the multi-dimensional analysis results is performed to output a security threat report. This solves the problems of high false alarm rate and serious false negative rate of traditional methods, thereby improving the accuracy of security threat detection and analysis.
[0017] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0018] Please refer to Figure 1 , Figure 1 A flowchart illustrating the security threat detection and analysis method according to an embodiment of the present invention is shown, as follows: Figure 1 As shown, the security threat detection and analysis method includes steps S110-S150.
[0019] S110. Receive alarm data from multiple security data sources, and perform multi-source correlation analysis and abnormal behavior detection on the alarm data respectively to generate correlation analysis results.
[0020] In this embodiment, alarm data from various heterogeneous security devices and software is received and aggregated in real time. This multi-source alarm data includes, but is not limited to, network firewall interception logs, intrusion detection system alerts, endpoint detection and response platform event records, cloud security group operation audits, and login anomaly information from identity authentication systems. It should be noted that the above-mentioned multi-source alarm data is collected, parsed, and standardized in real time through a unified interface, providing a complete and consistent input data source for subsequent multi-dimensional correlation analysis and intelligent threat detection. It should also be noted that the security threat detection and analysis method in this embodiment is applied to a security threat detection and analysis device, which includes a multi-source log correlation analysis engine, a machine attack link analysis module, a user behavior time-series analysis module, an intelligent analysis engine, and a report generation module. The multi-source log correlation analysis engine performs time, space, and causal correlation analysis and abnormal behavior detection on the alarm data to extract inherently related threat activity clues and abnormal patterns from isolated alarms. The machine attack link analysis module maps alarms to specific stages under a standard attack framework based on the results of the correlation analysis, calculating the target machine... The system calculates the risk score of the device and reconstructs a complete multi-stage attack chain and timeline; the user behavior time sequence analysis module analyzes user operation sequences based on alarm data to identify preset suspicious behavior patterns, calculates user suspicion scores, and supports multi-user comparison to discover internal risks; the intelligent analysis engine integrates all the above analysis results and automatically generates intelligent analysis results containing key threats, attack vectors, risk levels, and handling suggestions through artificial intelligence technology to achieve intelligent comprehensive judgment; the report generation module formats the intelligent analysis results into report files of various formats, distributes them to designated receiving terminals based on policies, and performs secure transmission and local archiving management.
[0021] Among them, such as Figure 2 As shown, step S110 includes steps S111-S113: S111. Perform multi-source correlation analysis on the alarm data to identify its correlation in time, space and logical causality, and obtain the initial correlation analysis results; S112. Perform abnormal behavior detection on the alarm data in parallel to identify preset abnormal behavior patterns; S113. Generate the association analysis results based on the initial association analysis results and the abnormal behavior patterns.
[0022] In this embodiment, the initial correlation analysis result includes the temporal correlation analysis result, the spatial correlation analysis result, and the causal correlation analysis result. Step S111 includes: performing temporal correlation analysis on the alarm data within a preset sliding time window to detect alarm clustering and generating the temporal correlation analysis result; performing spatial correlation analysis on the alarm data belonging to the same target asset to form spatial correlation clusters and generating the spatial correlation analysis result; performing causal correlation analysis on the alarm data with a temporal order based on a predefined causal relationship pattern library to identify logical causal relationships on the attack logic chain and generating the causal correlation analysis result; and using the temporal correlation analysis result, the spatial correlation analysis result, and the causal correlation analysis result as the initial correlation analysis result. It should be noted that the temporal correlation analysis specifically uses a sliding time window mechanism to dynamically scan and analyze the alarm data. This window is typically set to a configurable time interval, such as 30 minutes. Within this window, the dense occurrence of alarm events is detected in real time. If the number or frequency of alarms within a certain time period exceeds a preset threshold, it is identified as an alarm clustering phenomenon. Such clustering usually indicates organized attack activity rather than isolated, sporadic events. The system records the occurrence time, duration, alarm type distribution, and associated assets of these clustered events, forming structured temporal correlation analysis results. Spatial correlation analysis clusters alarm data belonging to the same server, network segment, or user, forming spatial correlation clusters. This method can effectively detect attackers' lateral movement within the same target environment, persistent persistence attempts, or concentrated attacks targeting specific assets. Each correlation cluster records characteristics such as the alarm events it contains, associated asset information, and consistency of attack methods, forming spatial correlation analysis results. It should also be noted that the predefined causal relationship pattern library contains the logical relationships between events in various known attack tactic chains; for example, "successful brute-force attack" often leads to "abnormal login," and "vulnerability exploitation" is usually followed by "privilege escalation." Scanning alarm events with a chronological order, when an alarm sequence matching a predefined causal pattern is found, it is identified as a potential causal relationship. These causal relationships can reveal the inherent logic between attack steps, forming causal correlation analysis results.
[0023] In one embodiment, such as this one, the multi-source log correlation analysis engine, in addition to performing multi-source correlation analysis on alarm data, also performs abnormal behavior detection on the alarm data in parallel. The multi-source log correlation analysis engine has built-in various preset abnormal behavior pattern recognition rules, such as login outside of working hours, high-frequency failed authentication, abnormal geographical login, and abnormal permission changes. By performing real-time matching and pattern recognition on alarm data, suspicious behaviors that do not conform to the normal baseline can be detected in a timely manner. These identified abnormal behavior patterns are generated independently of the initial correlation analysis results mentioned above, but they complement each other. Finally, the initial correlation analysis results and the identified abnormal behavior patterns are fused and cross-validated to form a comprehensive, multi-dimensional correlation analysis result. Understandably, this correlation analysis result not only includes traditional correlation findings based on statistics and rules, but also integrates abnormal insights based on behavioral analysis, providing more accurate and richer analytical input for subsequent machine attack chain analysis and comprehensive intelligent assessment.
[0024] S120. Based on the correlation analysis results, perform machine attack link analysis and generate attack link analysis results.
[0025] In this embodiment, as Figure 3As shown, step S120 includes steps S121-S123: S121, mapping the alarm types in the correlation analysis results to attack stages under a preset attack framework; S122, calculating the risk score of the target machine based on the number and type of the attack stages; S123, reconstructing the timeline of the attack event based on the risk score and the temporal and causal correlation information in the correlation analysis results, generating the attack chain analysis results containing multi-stage attack chains. Specifically, firstly, according to predefined mapping rules, different types of alarms (e.g., vulnerability scanning, successful brute-force attack, privilege escalation) in the correlation analysis results are intelligently classified and mapped to attack stages (e.g., reconnaissance, initial access, privilege escalation) under a standard attack framework (e.g., MITRE ATT&CK framework). Understandably, by implementing step S121, isolated alarm events can be standardized into attack stages with clear tactical intentions, thereby establishing a unified perspective for understanding the attacker's behavioral logic. Secondly, based on the number of attack stages involved in the target machine and their severity types (different stages usually have different preset risk weights), the risk score of the machine is calculated using a built-in algorithm. Understandably, the risk score provides an immediate, quantitative assessment of the severity of the threat to an asset. It's important to note that the built-in algorithm, within the machine attack chain analysis module, calculates the machine risk score based on the type and number of attack stages and preset weights, using weighted calculations or machine learning models. Finally, based on the risk score, the temporal sequence and causal logic information contained in the correlation analysis results are deeply integrated. By chronologically sorting and logically connecting this information, the complete, multi-step attack evolution process of the attacker targeting the machine can be reconstructed, ultimately generating a detailed attack chain analysis result that clearly shows the attack path and the corresponding risk status at each stage.
[0026] S130. Perform time-series analysis of user behavior based on the alarm data and generate behavior time-series analysis results.
[0027] In this embodiment, as Figure 4As shown, step S130 includes steps S131-S133: S131, analyzing the user's login and operation event sequence based on the alarm data to identify multiple preset suspicious behavior patterns; S132, calculating the corresponding user's suspicious score based on the number of identified suspicious behavior patterns and their preset severity levels; S133, generating the behavior time series analysis results including user risk ranking and key anomaly detection based on the user's suspicious score. Specifically, the user behavior time series analysis module first directly analyzes events such as user login time, operation object, and command sequence in the alarm data, and matches them with the built-in rule base to identify multiple preset suspicious behavior patterns such as "login during non-working hours," "high-frequency failed authentication," "abnormal permission access," and "batch download of sensitive data." This step aims to filter out abnormal segments that deviate from the baseline from a massive amount of normal operations. Secondly, all identified suspicious behavior patterns are summarized, and based on their number and the preset severity level of each pattern (such as "high risk" and "medium risk"), a quantitative suspicious score is generated for the corresponding user through weighted calculation and other methods. Understandably, this score comprehensively reflects the overall risk level of this user's behavior. Finally, based on the suspicious scores of all users, a global ranking and comparative analysis is performed to identify the user group with the highest risk. At the same time, combined with specific details of abnormal patterns, key anomaly findings are extracted (e.g., "a user attempted to access multiple core servers in the early morning"), ultimately generating time-series analysis results.
[0028] S140. Based on the correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results, perform intelligent comprehensive analysis to generate intelligent analysis results.
[0029] In this embodiment, as Figure 5 As shown, step S140 includes steps S141-S144: S141, integrate the correlation analysis results, the attack link analysis results and the behavior time sequence analysis results to generate a comprehensive analysis summary text containing multi-dimensional threat information; S142. The comprehensive analysis summary text is formatted to generate structured prompt information; S143. The structured prompt information is processed to obtain an initial evaluation result containing natural language descriptions and structured data; S144. The initial evaluation result is parsed to extract key threats, attack vectors, risk levels, and handling suggestions, generating a unified intelligent analysis result. Specifically, the intelligent analysis engine first receives outputs from the multi-source log correlation analysis engine, the machine attack chain analysis module, and the user behavior time series analysis module, and integrates them into a unified comprehensive analysis summary text. This comprehensive analysis summary text systematically encompasses key elements such as the attack's temporal aggregation characteristics, affected core assets, the reconstructed complete attack chain, key attack stages involved, high-risk users, and their abnormal behaviors. Then, the generated comprehensive analysis summary text is formatted, and system instructions are embedded and explicit answer format requirements are specified (e.g., specifying a JSON format return) according to the input specifications of the invoked artificial intelligence model (such as a large language model), thereby generating a high-quality structured prompt information. This step aims to transform the security analysis context into "task instructions" that the AI model can accurately understand and efficiently process, serving as a crucial bridge connecting domain knowledge and general intelligence. Next, the formatted, structured prompts are submitted to the AI model for processing. Based on its embedded general knowledge, logical reasoning capabilities, and understanding of the security context, the model performs in-depth analysis, summarization, and judgment of the comprehensive threat information input. Its output is an initial assessment result containing natural language descriptions and structured data fields (such as JSON), typically summarizing the entire attack event, attributing its causes, assessing its impact, and generating preliminary recommendations. Finally, the initial assessment result is automatically parsed. By extracting predefined key fields, it obtains information about the event, including "critical threats" (e.g., ransomware attacks), main "attack vectors" (e.g., exploiting unpatched vulnerabilities), "risk level" (e.g., high risk), and specific "response recommendations" (e.g., immediately isolating infected hosts, patching specific vulnerabilities). These elements are then organized into a standardized, clearly defined intelligent analysis result.
[0030] S150. Generate and output a security threat report based on the intelligent analysis results.
[0031] In this embodiment, the report generation module formats the intelligent analysis results according to a predetermined format to generate the security threat report. Specifically, the structured data (such as key threats, attack vectors, risk levels, and remediation recommendations) from the intelligent analysis results are used as input, and the content is filled and organized according to a predefined report template. This process, based on configuration requirements, simultaneously or selectively converts the same core analysis content into a report file in at least one predetermined format, such as HTML webpage, plain text, or JSON, thereby generating a complete, properly formatted security threat report that can be directly distributed or archived.
[0032] In one embodiment, such as this embodiment, after step S150, the method further includes: sending the security threat report to a designated receiving terminal based on a preset strategy; and archiving the security threat report. Specifically, the report delivery process is automatically executed according to a preset distribution strategy (such as timed triggering, event-driven, or manual immediate sending). This process ensures that the generated final security threat report file is securely and reliably pushed to a preset mailing list, SOC ticket system, or other designated receiving terminal by integrating an enterprise-level mail server and enabling an SSL / TLS encrypted transmission channel. After sending is completed, an archiving operation is immediately performed, automatically saving the security threat report to a local protected storage directory or dedicated database according to a predetermined storage strategy (such as classification by time, asset group, or threat level), and establishing a metadata index to achieve centralized and standardized management of all historical reports, meeting the compliance requirements of security auditing and post-event traceability.
[0033] It should be noted that, in this embodiment, a Web management interface is also provided, which has user interaction, configuration management and data visualization functions.
[0034] In summary, the security threat detection and analysis method in this embodiment achieves the following significant benefits through multi-source correlation analysis, attack chain reconstruction, user behavior analysis, and AI-powered intelligent comprehensive judgment: In terms of detection accuracy, multi-source correlation analysis effectively integrates isolated alarms, significantly reducing false positives and false negatives. Based on a standardized attack framework and time-series analysis, it greatly improves the accuracy of identifying complex threats and the ability to reconstruct complete attack chains. In terms of analysis efficiency, it achieves a high degree of automation in the analysis process, greatly reducing the workload of manual intervention and shortening the threat assessment and report generation cycle. In terms of risk quantification, it provides a refined risk scoring mechanism and dynamic ranking capability for both machines and users. At the intelligence level, the AI engine can automatically generate professional threat assessments, handling suggestions, and priority classifications, and supports real-time alerts. Furthermore, it possesses powerful integration and expansion capabilities, seamlessly integrating with common monitoring systems, supporting multiple data sources, and providing a complete management interface and API.
[0035] In one embodiment, a security threat detection and analysis device 200 is provided, which corresponds one-to-one with the security threat detection and analysis methods described in the above embodiments. For example... Figure 6 As shown, the security threat detection and analysis device 200 includes an analysis and detection unit 201, a first analysis unit 202, a second analysis unit 203, a third analysis unit 204, and a generation unit 205. Detailed descriptions of each functional module are as follows: The analysis and detection unit 201 is used to receive alarm data from multiple security data sources, and to perform multi-source correlation analysis and abnormal behavior detection on the alarm data respectively, and generate correlation analysis results. The first analysis unit 202 is used to perform machine attack link analysis based on the correlation analysis results and generate attack link analysis results. The second analysis unit 203 is used to perform user behavior time-series analysis based on the alarm data and generate behavior time-series analysis results. The third analysis unit 204 is used to perform intelligent comprehensive analysis based on the correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results to generate intelligent analysis results. The generation unit 205 is used to generate and output a security threat report based on the intelligent analysis results.
[0036] In one embodiment, the analysis and detection unit 201 is specifically used for: Multi-source correlation analysis is performed on the alarm data to identify its correlation in time, space and logical causality, and to obtain the initial correlation analysis results; The alarm data is subjected to abnormal behavior detection in parallel to identify preset abnormal behavior patterns; The association analysis results are generated based on the initial association analysis results and the abnormal behavior patterns.
[0037] In one embodiment, the analysis and detection unit 201 is further configured to: Within a preset sliding time window, perform time correlation analysis on the alarm data to detect alarm clustering and generate the time correlation analysis results. Spatial correlation analysis is performed on the alarm data belonging to the same target asset to form spatial correlation clusters, and the spatial correlation analysis results are generated. Based on a predefined causal relationship pattern library, causal correlation analysis is performed on the alarm data with a chronological order to identify logical causal relationships on the attack logic chain and generate the causal correlation analysis results. The temporal correlation analysis results, the spatial correlation analysis results, and the causal correlation analysis results are used as the initial correlation analysis results.
[0038] In one embodiment, the first analysis unit 202 is specifically used for: Map the alarm types in the correlation analysis results to the attack stages under the preset attack framework; Calculate the risk score of the target machine based on the number and type of the attack phases; Based on the risk score and the temporal and causal correlation information in the correlation analysis results, the timeline of the attack event is reconstructed to generate the attack chain analysis results containing multi-stage attack chains.
[0039] In one embodiment, the second analysis unit 203 is specifically used for: Based on the alarm data analysis, the user's login and operation event sequence is analyzed to identify a variety of preset suspicious behavior patterns; A suspicious score is calculated for each user based on the number of identified suspicious behavior patterns and their preset severity levels. Based on the suspicious scores derived from user behavior, a time-series analysis of the behavior is generated, which includes user risk ranking and the discovery of key anomalies.
[0040] In one embodiment, the third analysis unit 204 is specifically used for: The correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results are integrated to generate a comprehensive analysis summary text containing multi-dimensional threat information. The comprehensive analysis summary text is formatted to generate structured prompt information; The structured prompt information is processed to obtain an initial evaluation result containing natural language descriptions and structured data; The initial assessment results are analyzed to extract key threats, attack vectors, risk levels, and handling recommendations, generating the intelligent analysis results in a standardized format.
[0041] In one embodiment, the generation unit 205 is specifically used for: The intelligent analysis results are formatted according to a predetermined format to generate the security threat report.
[0042] In one embodiment, the security threat detection and analysis device 200 further includes, The sending unit is used to send the security threat report to a designated receiving terminal based on a preset strategy; The storage unit is used to archive and manage the security threat reports.
[0043] The aforementioned security threat detection and analysis method can be implemented as a computer program, which can, for example... Figure 7It runs on the security threat detection and analysis equipment shown.
[0044] Please see Figure 7 , Figure 7 This is a schematic block diagram of a security threat detection and analysis device provided in an embodiment of the present invention. The security threat detection and analysis device 300 is a device capable of detecting and analyzing security threats.
[0045] See Figure 7 The security threat detection and analysis device 300 includes a processor 302, a memory, and a network interface 305 connected via a system bus 301. The memory may include a non-volatile storage medium 303 and internal memory 304.
[0046] The non-volatile storage medium 303 may store an operating system 3031 and a computer program 3032. When the computer program 3032 is executed, it causes the processor 302 to execute a security threat detection and analysis method.
[0047] The processor 302 provides computing and control capabilities to support the operation of the entire security threat detection and analysis device 300.
[0048] The internal memory 304 provides an environment for the execution of the computer program 3032 in the non-volatile storage medium 303. When the computer program 3032 is executed by the processor 302, the processor 302 can execute a security threat detection and analysis method.
[0049] This network interface 305 is used for network communication with other devices. Those skilled in the art will understand that... Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the security threat detection and analysis device 300 to which the present invention is applied. The specific security threat detection and analysis device 300 may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0050] The processor 302 is used to run a computer program 3032 stored in a memory to implement any embodiment of the security threat detection and analysis method described above.
[0051] It should be understood that, in this embodiment of the invention, the processor 302 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0052] It will be understood by those skilled in the art that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program may be stored in a storage medium, which is a computer-readable storage medium. The computer program is executed by at least one processor in the computer system to implement the process steps of the embodiments of the above methods.
[0053] Therefore, the present invention also provides a storage medium. This storage medium can be a computer-readable storage medium. The storage medium stores a computer program. When executed by a processor, the computer program causes the processor to perform any embodiment of the security threat detection and analysis method described above.
[0054] The storage medium can be any computer-readable storage medium capable of storing program code, such as a USB flash drive, portable hard drive, read-only memory (ROM), magnetic disk, or optical disk.
[0055] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0056] In the several embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of each unit is merely a logical functional division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.
[0057] The steps in the method of this invention can be adjusted, merged, or reduced in order according to actual needs. The units in the device of this invention can be merged, divided, or reduced according to actual needs. Furthermore, the functional units in the various embodiments of this invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0058] If the integrated unit example is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a security threat detection and analysis device to execute all or part of the steps of the methods described in the various embodiments of the present invention.
[0059] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0060] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Since these modifications and variations fall within the scope of the claims and their equivalents, this invention also intends to include these modifications and variations.
[0061] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for detecting and analyzing security threats, characterized in that, include: Receive alarm data from multiple security data sources, and perform multi-source correlation analysis and abnormal behavior detection on the alarm data respectively to generate correlation analysis results; Based on the correlation analysis results, machine attack chain analysis is performed to generate attack chain analysis results; Based on the alarm data, perform time-series analysis of user behavior to generate time-series analysis results. Based on the correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results, intelligent comprehensive analysis is performed to generate intelligent analysis results. A security threat report is generated and output based on the intelligent analysis results.
2. The method according to claim 1, characterized in that, The steps of performing multi-source correlation analysis and abnormal behavior detection on the alarm data to generate correlation analysis results include: Multi-source correlation analysis is performed on the alarm data to identify its correlation in time, space and logical causality, and to obtain the initial correlation analysis results; The alarm data is subjected to abnormal behavior detection in parallel to identify preset abnormal behavior patterns; The association analysis results are generated based on the initial association analysis results and the abnormal behavior patterns.
3. The method according to claim 2, characterized in that, The initial correlation analysis results include the temporal correlation analysis results, the spatial correlation analysis results, and the causal correlation analysis results. The step of performing multi-source correlation analysis on the alarm data to identify its temporal, spatial, and logical causal correlations and obtaining the initial correlation analysis results includes: Within a preset sliding time window, perform time correlation analysis on the alarm data to detect alarm clustering and generate the time correlation analysis results. Spatial correlation analysis is performed on the alarm data belonging to the same target asset to form spatial correlation clusters, and the spatial correlation analysis results are generated. Based on a predefined causal relationship pattern library, causal correlation analysis is performed on the alarm data with a chronological order to identify logical causal relationships on the attack logic chain and generate the causal correlation analysis results. The temporal correlation analysis results, the spatial correlation analysis results, and the causal correlation analysis results are used as the initial correlation analysis results.
4. The method according to claim 1, characterized in that, The step of performing machine attack link analysis based on the correlation analysis results and generating attack link analysis results includes: Map the alarm types in the correlation analysis results to the attack stages under the preset attack framework; Calculate the risk score of the target machine based on the number and type of the attack phases; Based on the risk score and the temporal and causal correlation information in the correlation analysis results, the timeline of the attack event is reconstructed to generate the attack chain analysis results containing multi-stage attack chains.
5. The method according to claim 1, characterized in that, The step of performing time-series analysis of user behavior based on the alarm data and generating time-series analysis results includes: Based on the alarm data analysis, the user's login and operation event sequence is analyzed to identify a variety of preset suspicious behavior patterns; A suspicious score is calculated for each user based on the number of identified suspicious behavior patterns and their preset severity levels. Based on the suspicious scores derived from user behavior, a time-series analysis of the behavior is generated, which includes user risk ranking and the discovery of key anomalies.
6. The method according to claim 1, characterized in that, The step of performing intelligent comprehensive analysis based on the correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results to generate intelligent analysis results includes: The correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results are integrated to generate a comprehensive analysis summary text containing multi-dimensional threat information. The comprehensive analysis summary text is formatted to generate structured prompt information; The structured prompt information is processed to obtain an initial evaluation result containing natural language descriptions and structured data; The initial assessment results are analyzed to extract key threats, attack vectors, risk levels, and handling recommendations, generating the intelligent analysis results in a standardized format.
7. The method according to any one of claims 1-6, characterized in that, The step of generating and outputting a security threat report based on the intelligent analysis results includes: The intelligent analysis results are formatted according to a predetermined format to generate the security threat report; Following the step of generating and outputting a security threat report based on the intelligent analysis results, the method further includes: The security threat report is sent to the designated receiving terminal based on a preset policy. The security threat reports will be archived and managed.
8. A security threat detection and analysis device, characterized in that, include: The analysis and detection unit is used to receive alarm data from multiple security data sources, and to perform multi-source correlation analysis and abnormal behavior detection on the alarm data to generate correlation analysis results. The first analysis unit is used to perform machine attack link analysis based on the correlation analysis results and generate attack link analysis results. The second analysis unit is used to perform time-series analysis of user behavior based on the alarm data and generate time-series analysis results. The third analysis unit is used to perform intelligent comprehensive analysis based on the correlation analysis results, the attack link analysis results, and the behavior time sequence analysis results, and generate intelligent analysis results. The generation unit is used to generate and output a security threat report based on the intelligent analysis results.
9. A security threat detection and analysis device, characterized in that, The security threat detection and analysis device includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program that, when executed by a processor, can implement the method as described in any one of claims 1-7.