Alarm noise reduction method and device based on multi-dimensional association and intelligent aggregation

By employing multi-dimensional correlation and intelligent aggregation methods, the problem of fragmented alarm information in the security operations system has been solved, enabling intelligent aggregation of alarms across devices and stages, reducing redundant alarms, and improving the analytical capabilities and efficiency of the security operations center.

CN122053112APending Publication Date: 2026-05-15BEIJING INBASIS TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING INBASIS TECH
Filing Date
2025-12-31
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In the existing security operation system, security devices are diverse and lack unified standards, resulting in fragmented alarm information. Traditional alarm noise reduction methods cannot achieve context fusion of multi-source alarms and identification of cross-stage attack behaviors, and lack self-learning and continuous optimization capabilities, resulting in too many redundant alarms and difficulty in identifying complex network attacks.

Method used

Employing a method based on multidimensional association and intelligent aggregation, the system receives alarm data for black hat detection and feature extraction, enriches assets, merges logs, fuses multiple elements, and identifies attack chains to achieve threat characterization. Combining multidimensional aggregation and self-learning optimization, it generates high-confidence security alarms and performs event tracing and scenario analysis.

Benefits of technology

It enables intelligent aggregation of alarms across devices and stages, reduces the number of redundant alarms, improves the accuracy and efficiency of security alarm processing, enhances the analytical capabilities of the security operations center, and solves the problem of "alarm fatigue".

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053112A_ABST
    Figure CN122053112A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an alarm noise reduction method and device based on multi-dimensional association and intelligent aggregation, and the method comprises the steps: receiving alarm data, carrying out the black discrimination detection of the alarm data, carrying out the feature extraction, carrying out the asset enrichment, and outputting an original alarm; log merging, multi-element fusion and attack chain identification are carried out on the original alarm, alarm enrichment is carried out, threat qualification is realized, and the enriched security alarm is output; carrying out multi-dimensional aggregation on the enriched security alarms, carrying out end network association and attack chain restoration, and carrying out artificial experience recommendation, baseline behavior abnormity recommendation and association analysis mining recommendation on a multi-dimensional aggregation result to generate high-reliability security alarms; and based on the high-reliability security alarm, performing event traceability, scene analysis, disposal entity marking and security event display.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of computer security technology, and in particular to an alarm noise reduction method and device based on multidimensional correlation and intelligent aggregation. Background Technology

[0002] In the current security operations system, the large number of security devices and their diverse detection methods, coupled with the lack of unified standards for alerts generated by different vendors and engines, lead to severe information fragmentation in the analysis process of the Security Operations Center (SOC). Taking traditional SIEM platforms as an example, their alert denoising logic largely relies on preset rules or static conditions, such as source IP, target IP, and attack type. While these methods can reduce duplicate alerts to some extent, they cannot achieve contextual fusion of multi-source alerts or automatically identify the logical relationships between multi-stage attack behaviors. As network attacks become increasingly covert and complex, static rules alone are insufficient to meet the needs of alert aggregation and denoising. Furthermore, existing systems cannot dynamically optimize models based on feedback from security analysts, lacking self-learning and continuous improvement capabilities. Therefore, traditional denoising systems often only "reduce" the number of alerts, failing to achieve "aggregation and reconstruction" at the event semantic and causal levels.

[0003] In existing security operation systems, the mainstream alarm noise reduction and aggregation solutions mainly include the following categories: The first category is a simple aggregation method based on five-tuple features. The system matches five-tuple information such as source IP, destination IP, source port, destination port, and protocol to group alarms with the same or similar characteristics into one category. This method is simple to implement, but it relies too heavily on network layer features, cannot identify semantic differences in attack behavior, and cannot adapt to complex attack scenarios that cross stages or hosts. For example, when an attacker changes the source IP or uses a proxy channel, this type of method will mistakenly identify it as multiple independent alarms and fail to complete aggregation.

[0004] The second category is classification methods based on attack type or rule templates. For example, the system classifies and statistically analyzes alerts based on predefined rules such as "worm propagation," "SQL injection," and "WebShell upload." This method has a fixed aggregation granularity, only works under known patterns, cannot discover new attack chains, and requires a large amount of manual maintenance of the rule base. Once attack methods are updated, the aggregation effect decreases significantly.

[0005] The third type is aggregation methods based on statistical thresholds. The system counts similar alarms within a set time window, triggering merging when the number exceeds a threshold. This method is suitable for suppressing high-frequency alarms within a short period, but it cannot identify correlations between different stages or across devices. For example, in APT attacks, attackers may gradually advance over hours or days; traditional time-window aggregation cannot capture such slow, stealthy attack chains.

[0006] The system itself has the following limitations: (1) The aggregation factor is single and lacks multi-dimensional semantic understanding; (2) It cannot achieve cross-device and cross-stage attack behavior identification and causal association; (3) It lacks the ability to adapt to different environments and data distributions; (4) The aggregation results have poor interpretability and are difficult to support audit traceability; (5) The model is static and rigid, relies on manual rule maintenance, and is difficult to cope with rapidly changing threat situations. Summary of the Invention

[0007] The purpose of this invention is to provide an alarm noise reduction method and apparatus based on multidimensional correlation and intelligent aggregation, aiming to solve the above-mentioned problems in the prior art.

[0008] This invention provides an alarm noise reduction method based on multidimensional correlation and intelligent aggregation, comprising: Receive alarm data, perform black detection and feature extraction on the alarm data, perform asset enrichment, and output the original alarm; The original alarms are log merged, multi-element fusion is performed, attack chain identification is performed, and alarm enrichment is performed to achieve threat characterization and output the enriched security alarms. The enriched security alerts are aggregated in multiple dimensions to correlate endpoints with networks and reconstruct attack chains. The results of the multidimensional aggregation are then used for recommendations based on human experience, baseline behavior anomalies, and correlation analysis to generate high-reliability security alerts. Based on the high-reliability security alerts, the system performs event tracing, scenario analysis, and entity marking for handling, and displays the security events.

[0009] This invention provides an alarm noise reduction device based on multidimensional correlation and intelligent aggregation, comprising: The data acquisition layer is used to receive alarm data, perform black detection and feature extraction on the alarm data, enrich the assets, and output the original alarm. The feature fusion layer is used to perform log merging, multi-element fusion, attack chain identification, and alarm enrichment on the original alarms to achieve threat characterization and output the enriched security alarms. The noise reduction and aggregation layer is used to perform multi-dimensional aggregation of enriched security alarms, perform end-to-end network correlation and attack chain reconstruction, and perform human experience recommendation, baseline behavior anomaly recommendation and correlation analysis mining recommendation on the multi-dimensional aggregation results to generate high-confidence security alarms. The results display layer is used to perform event tracing, scenario analysis, and entity marking based on the high-confidence security alarms, and to display the security events.

[0010] This invention also provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the steps of the alarm noise reduction method based on multidimensional correlation and intelligent aggregation described above.

[0011] This invention also provides a computer-readable storage medium storing an information transmission implementation program, which, when executed by a processor, implements the steps of the alarm noise reduction method based on multidimensional correlation and intelligent aggregation described above.

[0012] By employing the embodiments of the present invention, unified modeling, semantic fusion, and self-learning optimization of network-side, terminal-side, and terminal-network related data are performed to achieve semantic-level aggregation and dynamic noise reduction of alarms, thereby significantly reducing the number of redundant alarms without losing key threat information. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in one or more embodiments of this specification or in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0014] Figure 1 This is a flowchart of an alarm noise reduction method based on multidimensional correlation and intelligent aggregation according to an embodiment of the present invention; Figure 2 This is a schematic diagram illustrating the principle of the alarm noise reduction method based on multidimensional correlation and intelligent aggregation according to an embodiment of the present invention. Figure 3 This is a schematic diagram illustrating the generalization capability of network-end association strength in an embodiment of the present invention; Figure 4 This is a schematic diagram of an alarm noise reduction device based on multidimensional correlation and intelligent aggregation according to an embodiment of the present invention; Figure 5 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0015] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.

[0016] Method Implementation Examples According to embodiments of the present invention, an alarm noise reduction method based on multidimensional correlation and intelligent aggregation is provided. Figure 1 This is a flowchart of an alarm noise reduction method based on multidimensional correlation and intelligent aggregation according to an embodiment of the present invention, such as... Figure 1 As shown, the alarm noise reduction method based on multidimensional correlation and intelligent aggregation according to an embodiment of the present invention specifically includes: Step S101: Receive alarm data, perform black detection and feature extraction on the alarm data, enrich assets, and output the original alarm; wherein the alarm data specifically includes: proprietary telemetry data, third-party telemetry data, and third-party standard original alarms. Specifically: On the network side, based on traffic and log collection, preliminary analysis is performed using four rules: firewall, IPS, vulnerability detection, and threat intelligence. Data is then labeled and features are detected. This is combined with threat detection models in UEBA and AI for matching to quickly locate scenario threats. For irregular combined threat attack methods, detection is performed based on the entire session traffic, and a complete backtracking and correlation are conducted to ultimately locate abnormal risks. Based on the optimized algorithm model, typical threats are optimized for feature detection. Comprehensive local data is collected on the client side, and layered and aggregated locally. Valid data is then uploaded to the network side. Contextual strong correlation analysis is performed on the local data in conjunction with the user's real-world environment. Behavior detection is performed based on a multi-event complex correlation rule matching algorithm. Attack detection for known and unknown advanced threats is performed based on IOA generalized behavior rules, achieving complex behavior correlation detection. A three-level detection mechanism is employed for threat event detection. Specifically, the three-level detection mechanism includes: Level 1: Single-terminal event detection, detecting obvious attack behaviors based on a single terminal and outputting analysis; Level 2: Multi-alarm correlation detection, performing further in-depth detection based on a large amount of correlation data; Level 3: Cross-terminal multi-source detection, reproducing attack scenarios based on the correlation of data from multiple terminals and multiple sources. Cross-domain data fusion between the network and the terminal is performed. When the network side and the terminal side detect alarms of the same type, network-terminal correlation is performed. Network-terminal correlation is divided into strong correlation, logical correlation, and weak correlation according to the correlation strength. Strong correlation is the correlation of "the same thing" happening on the network and terminal, including: command execution correlation, file persistence correlation, active external connection correlation, and attack type correlation. Logical correlation is the correlation of causal relationship and attack stage relationship that occurs through the network and terminal. Weak correlation is the correlation with the strongest generalization ability.

[0017] Step S102: Perform log merging, multi-element fusion, attack chain identification, and alarm enrichment on the original alarms to achieve threat characterization and output the enriched security alarms. Step S103: Perform multi-dimensional aggregation on the enriched security alarms to correlate end-to-end networks and restore attack chains. Then, perform manual experience recommendation, baseline behavior anomaly recommendation, and correlation analysis mining recommendation on the multi-dimensional aggregation results to generate high-confidence security alarms. Step S104 involves performing event tracing, scenario analysis, and entity marking based on the high-confidence security alarm, followed by security event display. Specifically, this includes: The high-confidence security alerts are generated into a structured event set. Each event in the event set contains a complete attack context, associated host, timeline, attack stage, and original alert reference information. Each event is displayed through a visual interface in the form of an attack chain diagram, causal path, or process tree. High-confidence events are automatically pushed to the response system to trigger handling actions.

[0018] In summary, the embodiments of the present invention realize a closed-loop process of "data fusion - semantic understanding - intelligent aggregation - self-learning optimization", which can automatically identify redundant events and reconstruct attack semantic chains in a massive alarm environment, greatly reducing the pressure of manual analysis and improving the accuracy and efficiency of security alarm processing.

[0019] The technical solutions of the embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0020] This invention provides an alarm noise reduction method based on multi-dimensional correlation and intelligent aggregation. By performing unified modeling, semantic fusion, and self-learning optimization on network-side, terminal-side, and end-network correlated data, semantic-level aggregation and dynamic noise reduction of alarms are achieved, thereby significantly reducing the number of redundant alarms without losing key threat information. The entire technical solution consists of four core components: data acquisition, feature fusion, intelligent aggregation, and visualization.

[0021] like Figure 2As shown, the overall architecture includes a data acquisition layer, a feature fusion layer, a noise reduction and aggregation engine layer, and a result display layer. The data acquisition layer is responsible for accessing proprietary telemetry data, third-party telemetry data, and standard raw alarms from third parties. After detection (e.g., based on policies, IOC, AI models) and assetization / key feature extraction (i.e., data noise reduction), it outputs raw alarms. The feature fusion layer performs log merging / reduction, multi-element fusion, and attack chain identification (e.g., contextual correlation, endpoint / network correlation) on the raw alarms, while also enriching the alarms (e.g., attacker identity, host vulnerability) and achieving threat characterization, outputting enriched security alarms. The noise reduction and aggregation layer performs multi-dimensional aggregation of the enriched alarms, including endpoint / network correlation (strong correlation, logical correlation, weak signal correlation) and attack chain reconstruction (e.g., based on entities, knowledge graphs, multi-dimensional), pushing the results to human experience recommendation and correlation analysis mining, ultimately generating high-confidence security alarms after aggregation. The result display layer performs event tracing, scenario analysis, and entity labeling based on the aggregation results, ultimately forming accurate and traceable security events for display.

[0022] In specific implementation, the data noise reduction process in this embodiment of the invention includes: network-side noise reduction, terminal-side noise reduction, and terminal-network correlation noise reduction.

[0023] First, the network side performs preliminary analysis based on traffic and log collection, using four rules: firewall, IPS, vulnerability detection, and threat intelligence, to label and detect data. Then, it combines this with basic threat detection models from UEBA and AI for matching, quickly identifying scenario-specific threats such as prevalent viruses, hacker tools, brute-force attacks, scanning, and DGA. For more complex and irregular combined threat attack methods, such as successful attack identification, custom tools, zero-day vulnerability exploits, proxy forwarding tools, and covert tunnels, it performs detection based on the entire session traffic, including a complete retrospective correlation of traffic request echoes, abnormal feature correlations, abnormal behavior exploitation, and multi-stage attack exploitation, ultimately identifying abnormal risks. Finally, based on optimized algorithm models, it optimizes the detection of typical encrypted traffic and zero-day vulnerability exploit features, achieving high detection rates and low false positives.

[0024] Secondly, during the terminal-side noise reduction stage, comprehensive data is collected on the terminal side, including data on terminals, users, files, processes, and behaviors. The data is layered locally, and valid data is aggregated and uploaded to the platform. Contextual strong correlation analysis is performed based on the user's real-world environment to improve the accuracy of attack assessment. Behavior detection is based on a multi-event complex association rule matching algorithm, relying on IOA generalized behavior rules to improve the detection capability of known and unknown advanced threat attacks, filling the gap in the field of complex behavior correlation detection, constructing a behavior detection defense layer, enhancing multi-layered in-depth defense detection capabilities, and helping users effectively resist known and unknown advanced threat attacks.

[0025] Specifically, the terminal employs a three-level detection mechanism, shaped like a funnel. The first level is single-terminal event detection, which detects obvious attack behaviors on a single terminal (single-terminal single behavior, single-terminal multiple behaviors, etc.) and outputs analysis. The second level is multi-alarm correlation detection, which involves in-depth detection based on a large amount of correlation data to suppress false alarms. The third level is cross-terminal multi-source detection, which reproduces the attack scenario based on the correlation between data from multiple terminals and multiple sources.

[0026] Secondly, in the terminal-to-terminal noise reduction stage, the system achieves cross-domain data fusion between the network and the terminal. For example... Figure 3 As shown, network-end correlations are categorized by correlation strength into strong correlations, logical correlations, and weak correlations. Strong correlations address correlations where "the same thing" happens on the network and end, such as executing the same command or downloading the same file. These are mainly divided into command execution correlations, file persistence correlations, proactive external connection correlations, and attack type correlations. Logical correlations refer to correlations based on causal relationships occurring on the network and end, plus attack phase relationships. These scenarios cannot cover all correlation scenarios. For example, if an attack occurs from outside to inside and the network and end alarm types differ significantly, they cannot be linked, or data loss due to detection "breaks" prevents correlation. Causal correlations refer to correlations based on attack type without a physical entity. Alarms of the same type detected on the network and end are correlated. For example, if a WinRM alarm exists on the network and a WinRM remote command execution alarm exists on the end, then a correlation will occur. Weak correlations have the strongest generalization ability but are prone to false positives, i.e., incorrect correlations. Based on the PointNet neural network algorithm, which is derived from point cloud data, PointNet neural networks are robust to missing data and have good recognition capabilities for clues that cannot be accurately "connected".

[0027] During the output phase, the platform generates a structured "minimalist event set" from the aggregated results. Each event includes a complete attack context, associated host, timeline, attack stage, and reference information from the original alarm. Events are displayed through a visual interface in the form of attack chain diagrams, causal paths, or process trees, enabling analysts to quickly understand the nature of the event and trace its source. The system also supports policy linkage, which can automatically push high-confidence events to the response system to trigger handling actions, achieving a closed-loop process from detection to response.

[0028] The beneficial effects of the embodiments of the present invention are as follows: First, from the perspective of noise reduction principles, existing technologies can only aggregate alarms based on a single dimension (such as a quintuple or attack type), and cannot identify behaviors from different stages and sources that belong to the same attack chain. However, this invention, through multi-dimensional feature fusion and semantic aggregation algorithms, can determine the semantic similarity and behavioral causal relationship in real time after alarm generation, achieving intelligent alarm aggregation across devices and stages, significantly reducing the number of alarms and improving the completeness and readability of events.

[0029] Secondly, from the perspective of analytical depth, the aggregation results of traditional systems are mostly superficial statistics and cannot reconstruct the attack chain. The embodiments of this invention introduce a source tracing and growth aggregation mechanism on the terminal side, which can automatically connect suspicious behaviors based on the process tree to form a complete attack path, truly realizing the transformation from "isolated alarms" to "semantic events", enabling security analysts to directly identify the nature of threats and take targeted responses.

[0030] Furthermore, from the perspective of system intelligence and adaptability, most existing solutions rely on fixed rules or manually maintained thresholds, making it difficult to cope with changes in attack patterns. This invention combines reinforcement learning algorithms with expert feedback mechanisms, enabling the system to continuously optimize. By dynamically adjusting aggregation weights and time parameters, the system can automatically maintain optimal noise reduction performance under different network environments, asset types, and attack modes, exhibiting self-learning and evolutionary characteristics.

[0031] Finally, the application effect of this invention truly achieves the goal of "reducing the number of alarms and revealing effective threats", solving the long-standing problem of "alarm fatigue" in security operations centers.

[0032] Device Example 1 According to embodiments of the present invention, an alarm noise reduction device based on multidimensional correlation and intelligent aggregation is provided. Figure 4 This is a schematic diagram of an alarm noise reduction device based on multidimensional correlation and intelligent aggregation according to an embodiment of the present invention, as shown below. Figure 4 As shown, the alarm noise reduction device based on multidimensional correlation and intelligent aggregation according to an embodiment of the present invention specifically includes: The data acquisition layer 40 is used to receive alarm data, perform black detection and feature extraction on the alarm data, enrich assets, and output raw alarms. The alarm data specifically includes: proprietary telemetry data, third-party telemetry data, and third-party standard raw alarms. Specifically, it is used for: Traffic and logs are collected from the network side. Preliminary analysis is performed using four rules: firewall, IPS, vulnerability detection, and threat intelligence. Data is then labeled and features are detected. The threat detection models in UEBA and AI are then matched to quickly locate scenario threats. For irregular combined threat attack methods, detection is performed based on the entire session traffic. A complete backtracking and correlation are conducted to ultimately locate abnormal risks. Based on the optimized algorithm model, typical threats are optimized for feature detection. Comprehensive local data is collected from the endpoint, layered and aggregated locally, and then uploaded to the network side. This local data is then analyzed for strong contextual correlation based on the user's real-world environment. Behavioral detection is performed using a multi-event complex association rule matching algorithm, and attack detection for known and unknown advanced threats is performed based on IOA generalized behavioral rules. This achieves complex behavioral correlation detection, and a three-level detection mechanism is employed for threat event detection. Specifically, the three-level detection mechanism includes: Level 1: Single-terminal event detection, detecting and analyzing obvious attack behaviors from a single terminal; Level 2: Multi-alarm correlation detection, performing further in-depth detection based on a large amount of correlation data; Level 3: Cross-terminal multi-source detection, reproducing attack scenarios based on the correlation of data from multiple terminals and multiple sources. Cross-domain data fusion between the network and the terminal is performed. When the network side and the terminal side detect alarms of the same type, network-terminal correlation is performed. Network-terminal correlation is divided into strong correlation, logical correlation, and weak correlation according to the correlation strength. Strong correlation is the correlation of "the same thing" happening on the network and terminal, including: command execution correlation, file persistence correlation, active external connection correlation, and attack type correlation. Logical correlation is the correlation of causal relationship and attack stage relationship that occurs through the network and terminal. Weak correlation is the correlation with the strongest generalization ability.

[0033] The feature fusion layer 42 is used to perform log merging, multi-element fusion, attack chain identification, and alarm enrichment on the original alarms to achieve threat characterization and output the enriched security alarms. The noise reduction and aggregation layer 44 is used to perform multi-dimensional aggregation of the enriched security alarms, perform end-to-end network correlation and attack chain reconstruction, and perform human experience recommendation, baseline behavior anomaly recommendation and correlation analysis mining recommendation on the multi-dimensional aggregation results to generate high-confidence security alarms. The results display layer 46 is used for event tracing, scenario analysis, and entity tagging based on the high-confidence security alarms, and for displaying security events. Specifically, it is used for: The high-confidence security alerts are generated into a structured event set. Each event in the event set contains a complete attack context, associated host, timeline, attack stage, and original alert reference information. Each event is displayed through a visual interface in the form of an attack chain diagram, causal path, or process tree. High-confidence events are automatically pushed to the response system to trigger handling actions.

[0034] The embodiments of the present invention are device embodiments corresponding to the above method embodiments. The specific operation of each module can be understood with reference to the description of the method embodiments, and will not be repeated here.

[0035] Device Example 2 This invention provides an electronic device, such as... Figure 5As shown, it includes: a memory 50, a processor 52, and a computer program stored in the memory 50 and executable on the processor 52, wherein the computer program, when executed by the processor 52, performs the steps as described in the method embodiment.

[0036] Device Example 3 This invention provides a computer-readable storage medium storing an information transmission implementation program, which, when executed by a processor 52, performs the steps described in the method embodiment.

[0037] The computer-readable storage media described in this embodiment include, but are not limited to, ROM, RAM, disk, or optical disk.

[0038] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. An alarm noise reduction method based on multidimensional correlation and intelligent aggregation, characterized in that, include: Receive alarm data, perform black detection and feature extraction on the alarm data, perform asset enrichment, and output the original alarm; The original alarms are log merged, multi-element fusion is performed, attack chain identification is performed, and alarm enrichment is performed to achieve threat characterization and output the enriched security alarms. The enriched security alerts are aggregated in multiple dimensions to correlate endpoints with networks and reconstruct attack chains. The results of the multidimensional aggregation are then used for recommendations based on human experience, baseline behavior anomalies, and correlation analysis to generate high-reliability security alerts. Based on the high-reliability security alerts, the system performs event tracing, scenario analysis, and entity marking for handling, and displays the security events.

2. The method according to claim 1, characterized in that, The alarm data specifically includes: proprietary telemetry data, third-party telemetry data, and third-party standard original alarms.

3. The method according to claim 1, characterized in that, Receiving alarm data, performing black detection and feature extraction on the alarm data, enriching assets, and outputting the original alarm specifically includes: On the network side, based on traffic and log collection, preliminary analysis is performed using four rules: firewall, IPS, vulnerability detection, and threat intelligence. Data is then labeled and features are detected. This is combined with threat detection models in UEBA and AI for matching to quickly locate scenario threats. For irregular combined threat attack methods, detection is performed based on the entire session traffic, and a complete backtracking and correlation are conducted to ultimately locate abnormal risks. Based on the optimized algorithm model, typical threats are optimized for feature detection. Comprehensive local data is collected on the client side, and layered and aggregated locally. Valid data is then uploaded to the network side. Contextual strong correlation analysis is performed on the local data in conjunction with the user's real-world environment. Behavior detection is performed based on a multi-event complex correlation rule matching algorithm. Attack detection for known and unknown advanced threats is performed based on IOA generalized behavior rules, achieving complex behavior correlation detection. A three-level detection mechanism is employed for threat event detection. Specifically, the three-level detection mechanism includes: Level 1: Single-terminal event detection, detecting obvious attack behaviors based on a single terminal and outputting analysis; Level 2: Multi-alarm correlation detection, performing further in-depth detection based on a large amount of correlation data; Level 3: Cross-terminal multi-source detection, reproducing attack scenarios based on the correlation of data from multiple terminals and multiple sources. Cross-domain data fusion between the network and the terminal is performed. When the network side and the terminal side detect alarms of the same type, network-terminal correlation is performed. Network-terminal correlation is divided into strong correlation, logical correlation, and weak correlation according to the correlation strength. Strong correlation is the correlation in which "the same thing" happens on the network and terminal, including command execution correlation, file landing correlation, active external connection correlation, and attack type correlation. Logical correlation is the correlation in which causal relationship and attack stage relationship occur through the network and terminal. Weak correlation is the correlation with the strongest generalization ability.

4. The method according to claim 1, characterized in that, Based on the high-reliability security alerts, event tracing, scenario analysis, and entity marking for handling are performed, and security event display is presented, specifically including: The high-confidence security alerts are generated into a structured event set. Each event in the event set contains a complete attack context, associated host, timeline, attack stage, and original alert reference information. Each event is displayed through a visual interface in the form of an attack chain diagram, causal path, or process tree. High-confidence events are automatically pushed to the response system to trigger handling actions.

5. An alarm noise reduction device based on multidimensional correlation and intelligent aggregation, characterized in that, include: The data acquisition layer is used to receive alarm data, perform black detection and feature extraction on the alarm data, enrich the assets, and output the original alarm. The feature fusion layer is used to perform log merging, multi-element fusion, attack chain identification, and alarm enrichment on the original alarms to achieve threat characterization and output the enriched security alarms. The noise reduction and aggregation layer is used to perform multi-dimensional aggregation of enriched security alarms, perform end-to-end network correlation and attack chain reconstruction, and perform human experience recommendation, baseline behavior anomaly recommendation and correlation analysis mining recommendation on the multi-dimensional aggregation results to generate high-confidence security alarms. The results display layer is used to perform event tracing, scenario analysis, and entity marking based on the high-confidence security alarms, and to display the security events.

6. The apparatus according to claim 5, characterized in that, The alarm data specifically includes: proprietary telemetry data, third-party telemetry data, and third-party standard original alarms.

7. The apparatus according to claim 5, characterized in that, The data acquisition layer is specifically used for: Traffic and logs are collected from the network side. Preliminary analysis is performed using four rules: firewall, IPS, vulnerability detection, and threat intelligence. Data is then labeled and features are detected. The threat detection models in UEBA and AI are then matched to quickly locate scenario threats. For irregular combined threat attack methods, detection is performed based on the entire session traffic. A complete backtracking and correlation are conducted to ultimately locate abnormal risks. Based on the optimized algorithm model, typical threats are optimized for feature detection. Comprehensive local data is collected from the endpoint, layered and aggregated locally, and then uploaded to the network side. This local data is then analyzed for strong contextual correlation based on the user's real-world environment. Behavioral detection is performed using a multi-event complex association rule matching algorithm, and attack detection for known and unknown advanced threats is performed based on IOA generalized behavioral rules. This achieves complex behavioral correlation detection, and a three-level detection mechanism is employed for threat event detection. Specifically, the three-level detection mechanism includes: Level 1: Single-terminal event detection, detecting and analyzing obvious attack behaviors from a single terminal; Level 2: Multi-alarm correlation detection, performing further in-depth detection based on a large amount of correlation data; Level 3: Cross-terminal multi-source detection, reproducing attack scenarios based on the correlation of data from multiple terminals and multiple sources. Cross-domain data fusion between the network and the terminal is performed. When the network side and the terminal side detect alarms of the same type, network-terminal correlation is performed. Network-terminal correlation is divided into strong correlation, logical correlation, and weak correlation according to the correlation strength. Strong correlation is the correlation in which "the same thing" happens on the network and terminal, including command execution correlation, file landing correlation, active external connection correlation, and attack type correlation. Logical correlation is the correlation in which causal relationship and attack stage relationship occur through the network and terminal. Weak correlation is the correlation with the strongest generalization ability.

8. The apparatus according to claim 5, characterized in that, The results display layer is specifically used for: The high-confidence security alerts are generated into a structured event set. Each event in the event set contains a complete attack context, associated host, timeline, attack stage, and original alert reference information. Each event is displayed through a visual interface in the form of an attack chain diagram, causal path, or process tree. High-confidence events are automatically pushed to the response system to trigger handling actions.

9. An electronic device, characterized in that, include: The memory, the processor, and the computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the alarm noise reduction method based on multidimensional correlation and intelligent aggregation as described in any one of claims 1 to 4.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores an information transmission implementation program, which, when executed by a processor, implements the steps of the alarm noise reduction method based on multidimensional correlation and intelligent aggregation as described in any one of claims 1 to 4.