Alarm authenticity detection method and device for operation and maintenance scene, and electronic equipment
By calculating the inherent risk of alarms, baseline deviation risk, threat intelligence risk, and verification score, the problem of false alarms in the operation and maintenance system is solved, and the accuracy of alarm authenticity is improved and the efficiency of fault handling is enhanced.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING YOUTEJIE INFORMATION TECH
- Filing Date
- 2026-03-04
- Publication Date
- 2026-06-02
AI Technical Summary
Existing operation and maintenance systems are prone to generating a large number of false alarms during monitoring, making it difficult for operation and maintenance personnel to distinguish between real anomalies and false alarms, thus affecting the efficiency of fault handling.
By acquiring multiple alarms generated by the target operation and maintenance system and determining their corresponding inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score, the alarm score is calculated by combining these scores, and the authenticity of the alarm is finally determined.
Accurately determining the authenticity of alarms improves fault handling efficiency and reduces the burden of operation and maintenance.
Smart Images

Figure CN122137728A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security, and in particular to a method, apparatus, and electronic device for detecting the authenticity of alarms in operation and maintenance scenarios. Background Technology
[0002] Existing operation and maintenance systems typically trigger alarms based on preset thresholds or simple rules when monitoring applications, servers, and network devices. However, due to the complexity of the operation and maintenance environment, frequent business fluctuations, and noise in monitoring data, traditional alarm mechanisms are prone to generating a large number of false alarms, making it difficult for operation and maintenance personnel to distinguish between real anomalies and false alarms.
[0003] In order to identify whether the alarms generated by the operation and maintenance system are genuine and valid, existing technologies usually rely on the inherent risks of each alarm to determine its authenticity. This results in low accuracy in judging the authenticity of alarms, which in turn affects the efficiency of fault handling and increases the burden of operation and maintenance. Summary of the Invention
[0004] This invention provides a method, device, and electronic device for detecting the authenticity of alarms in operation and maintenance scenarios. It can accurately determine the authenticity of each alarm to be detected, thereby effectively improving the efficiency of fault handling.
[0005] In a first aspect, embodiments of the present invention provide a method for detecting the authenticity of alarms in an operation and maintenance scenario, including: Acquire multiple alarms to be detected generated by the target operation and maintenance system, and determine the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected; Based on the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm to be detected, the alarm score corresponding to each alarm to be detected is determined. The authenticity of each alarm to be detected is determined based on its alarm score.
[0006] Secondly, embodiments of the present invention also provide an alarm authenticity detection device for operation and maintenance scenarios, comprising: The scoring component determination module is used to acquire multiple alarms to be detected generated by the target operation and maintenance system, and determine the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected. The alarm scoring determination module is used to determine the alarm score corresponding to each alarm to be detected based on the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected. The alarm authenticity detection module is used to determine the authenticity of each alarm to be detected based on its alarm score.
[0007] Thirdly, embodiments of the present invention also provide an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to execute the alarm authenticity detection method for operation and maintenance scenarios provided in any embodiment of the present invention.
[0008] The technical solution of this invention determines the alarm score corresponding to each alarm to be detected by using the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm to be detected; and determines the authenticity of each alarm to be detected based on the alarm score of each alarm to be detected. This solves the problem that the existing technology has low accuracy in judging the authenticity of alarms, which affects the efficiency of fault handling. It can accurately determine the authenticity of each alarm to be detected, thereby effectively improving the efficiency of fault handling.
[0009] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a flowchart of an alarm authenticity detection method for operation and maintenance scenarios provided by Embodiment 1 of the present invention; Figure 2 This is a flowchart of another alarm authenticity detection method for operation and maintenance scenarios provided by Embodiment 2 of the present invention; Figure 3 This is a schematic diagram of an alarm authenticity detection device for operation and maintenance scenarios provided in Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation
[0012] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0013] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0014] Example 1 Figure 1 This is a flowchart of an alarm authenticity detection method for operation and maintenance scenarios according to Embodiment 1 of the present invention. This embodiment is applicable to the situation of performing authenticity detection on multiple alarms to be detected generated by a target operation and maintenance system. The method can be executed by an alarm authenticity detection device for operation and maintenance scenarios. The alarm authenticity detection device for operation and maintenance scenarios can be implemented in hardware and / or software and can be configured in electronic devices such as computers.
[0015] like Figure 1 As shown in this embodiment, an alarm authenticity detection method for operation and maintenance scenarios is disclosed, including: S110. Obtain multiple alarms to be detected generated by the target operation and maintenance system, and determine the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected.
[0016] In this embodiment, the target operation and maintenance system can be understood as a system that continuously monitors applications, servers, or network devices and automatically generates and pushes alerts to be detected when anomalies are detected. The inherent risk score can be used to characterize the inherent risk level of the alert to be detected. The baseline deviation risk score can be used to characterize the degree of deviation of the alert to be detected relative to the historical baseline. The historical baseline can be understood as the historical normal reference range of the indicator corresponding to the alert to be detected. The threat intelligence risk score can be understood as a score obtained by quantifying the threat level and credibility of the alert to be detected based on external or internal threat intelligence. The verification score can be understood as a value obtained by dynamically quantifying the threat level of the alert to be detected based on the operational feedback from operation and maintenance personnel.
[0017] In this step, specifically, for the inherent risk score, an inherent risk sub-score corresponding to each alarm to be detected can be determined, and based on the inherent risk sub-scores corresponding to each alarm to be detected, an inherent risk score corresponding to each alarm to be detected can be determined. The inherent risk sub-score can include at least one of the following: access behavior score, entity importance score, historical false alarm score, vulnerability score, risk characteristic score, and propagation timeliness score.
[0018] For baseline deviation risk scoring, the target alarm entity corresponding to each alarm to be detected can be obtained, and the baseline deviation risk score corresponding to each alarm can be determined based on the baseline deviation risk sub-score corresponding to each target alarm entity. The baseline deviation risk sub-score can include at least one of the following: alarm frequency score, behavior pattern score, alarm accuracy score, and alarm increment score.
[0019] For threat intelligence risk scoring, the threat intelligence risk score corresponding to each alert to be detected can be determined based on the threat intelligence tags and / or the relevance to the intelligence database.
[0020] For the verification score, the verification score corresponding to each alarm to be detected can be determined based on the entity effectiveness rate of the target alarm entity corresponding to each alarm to be detected, as well as the total number of historical alarms, historical false alarm rate and current false alarm rate corresponding to each alarm to be detected.
[0021] S120. Determine the alarm score corresponding to each alarm to be detected based on the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm to be detected.
[0022] In this step, specifically, for each alarm to be detected, the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to it can be multiplied to obtain an alarm score for each alarm. Alternatively, a preset weight coefficient corresponding to each alarm can be obtained, and the inherent risk score, baseline deviation risk score, threat intelligence risk score, verification score, and preset weight coefficient corresponding to each alarm can be multiplied to obtain an alarm score for each alarm. The alarm score can be used to characterize the threat level and credibility of the alarm.
[0023] S130. Determine the authenticity of each alarm to be detected based on the alarm score of each alarm to be detected.
[0024] In this step, specifically, the authenticity of each alarm to be detected can be determined based on its alarm score and a predefined alarm score threshold.
[0025] For example, when the alarm score of an alarm to be detected is greater than or equal to the alarm score threshold, it can be determined that the alarm to be detected has a high threat level and credibility, and is therefore a real alarm. When the alarm score of an alarm to be detected is less than the alarm score threshold, it can be determined that the alarm to be detected has a low threat level and credibility, and is therefore not a real alarm.
[0026] The technical solution of this embodiment obtains multiple alarms to be detected generated by the target operation and maintenance system, and determines the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm. Based on the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm, an alarm score corresponding to each alarm is determined. Based on the alarm score of each alarm, the authenticity of each alarm is determined. This technical means solves the problem that the existing technology has low accuracy in judging the authenticity of alarms, which affects the efficiency of fault handling. It can accurately determine the authenticity of each alarm, thereby effectively improving the efficiency of fault handling.
[0027] Example 2 Figure 2 This is a flowchart of another alarm authenticity detection method for operation and maintenance scenarios provided by Embodiment 2 of the present invention. This embodiment is a further optimization and extension based on the above embodiments and can be combined with various optional technical solutions in the above embodiments.
[0028] like Figure 2 As shown in this embodiment, an alarm authenticity detection method for operation and maintenance scenarios is disclosed, including: S210: Obtain multiple alarms to be detected generated by the target operation and maintenance system.
[0029] S220. Based on the behavior and attribute information corresponding to each alarm to be detected, determine the access behavior score, entity importance score, historical false alarm score, vulnerability score, risk characteristic score, and propagation timeliness score corresponding to each alarm to be detected.
[0030] In this embodiment, the behavior and attribute information may include access mode, access address, fault lifecycle, historical validity, entity identifier, port identifier, vulnerability, risk feature combination, alarm occurrence time, alarm propagation speed, rule historical false alarm count, and entity historical false alarm count, etc.
[0031] In this step, specifically, an access behavior score corresponding to each alarm to be detected can be determined based on the access mode, access address, fault lifecycle, and historical validity. The fault lifecycle can be occurrence, duration, or recovery. An entity importance score corresponding to each alarm to be detected can be determined based on the entity identifier and port identifier. A historical false alarm score corresponding to each alarm to be detected can be determined based on the historical false alarm count of the rule and the historical false alarm count of the entity.
[0032] Based on the vulnerabilities corresponding to each alarm to be detected, a vulnerability score is determined for each alarm. Based on the risk characteristic combinations corresponding to each alarm to be detected, a risk characteristic score is determined for each alarm to be detected. These risk characteristic combinations may include features such as alarm recurrence frequency and alarm occurrence time. Based on the alarm occurrence time and alarm propagation speed corresponding to each alarm to be detected, a propagation timeliness score is determined for each alarm to be detected.
[0033] For example, regarding access behavior scoring, an access pattern score can be determined based on the access pattern corresponding to each alarm to be detected. An access address score can be determined based on the access address corresponding to each alarm to be detected. A lifecycle score can be determined based on the fault lifecycle corresponding to each alarm to be detected. A historical validity score can be determined based on the historical validity corresponding to each alarm to be detected. After determining the access pattern score, access address score, fault lifecycle score, and historical validity score for each alarm to be detected, a weighted summation is performed on these scores to determine the access behavior score for each alarm to be detected.
[0034] For entity importance scoring, an entity importance score can be determined based on the entity identifier corresponding to each alarm to be detected, and a port risk score can be determined based on the port identifier corresponding to each alarm to be detected. Then, the port risk score is added to a preset benchmark value, and the sum is multiplied by the entity importance score to obtain the entity importance score corresponding to the alarm to be detected. The preset benchmark value can be set based on historical experience; for example, it can be set to 1.
[0035] S230. Based on the access behavior score, entity importance score, historical false alarm score, vulnerability score, risk characteristic score, and propagation timeliness score corresponding to each alarm to be detected, determine the inherent risk score corresponding to each alarm to be detected.
[0036] In this step, specifically, the inherent risk score corresponding to each alarm to be detected can be determined using the following specific calculation formula: in, Score the inherent risk. Score the visit behavior. Assess the importance of entities. Rate the vulnerabilities Score the risk characteristics. To score the timeliness of dissemination, Rate historical false alarms.
[0037] S240. Obtain the target alarm entity corresponding to each alarm to be detected, and determine the alarm frequency anomaly score, behavior pattern score, alarm accuracy score and alarm increment score corresponding to each target alarm entity.
[0038] Specifically, in this step, an alarm frequency anomaly score is determined based on the current alarm count, average alarm count, and standard deviation of the alarm count corresponding to each target alarm entity. A behavioral pattern score is determined based on the alarm occurrence time, business period, entity identifier, and alarm triggering rule corresponding to each target alarm entity. An alarm accuracy score is determined based on the alarm accuracy corresponding to each target alarm entity, as well as a predefined first accuracy range and a second accuracy range. Finally, an alarm increment score is determined based on the current alarm count and a predefined average historical alarm count corresponding to each target alarm entity.
[0039] Optionally, an alarm frequency anomaly score is determined for each target alarm entity, including: obtaining the current alarm count for each target alarm entity within the current set time period, and the historical alarm count within multiple historical time periods; determining the mean alarm count and standard deviation of the alarm count for each target alarm entity based on the current alarm count and historical alarm count; determining the alarm frequency score for each target alarm entity based on the current alarm count, mean alarm count, and standard deviation of the alarm count; and determining the alarm frequency anomaly score for each target alarm entity based on the alarm frequency score and a predefined frequency score range.
[0040] Specifically, the alarm frequency score can be calculated by subtracting the average alarm count corresponding to the target alarm entity from the current alarm count. Then, this difference can be divided by the standard deviation of the alarm count corresponding to the target alarm entity to obtain the alarm frequency score. Finally, if the alarm frequency score is lower than the lowest value of a first frequency score range, the alarm frequency anomaly score corresponding to the target alarm entity is determined as a first frequency anomaly score. If the alarm frequency score falls within the first frequency score range, it is determined as a second frequency anomaly score. If the alarm frequency score falls within the second frequency score range, it is determined as a third frequency anomaly score. If the alarm frequency score is higher than the highest value of the second frequency score range, it is determined as a fourth frequency anomaly score. Note that the highest value of the first frequency score range is lower than the lowest value of the second frequency score range. The first, second, third, and fourth frequency anomaly scores increase sequentially. The score range for each frequency can be determined based on user needs and historical experience. For example, the first frequency score range can be set to be greater than or equal to -2 and less than 0.5; the second frequency score range can be set to be greater than or equal to 0.5 and less than or equal to 2.
[0041] Optionally, since accessing a new target at an abnormal time and triggering a new rule is highly suspicious, and accessing a common target at a normal time and triggering a common rule is likely to result in a false alarm, determining the behavioral pattern score corresponding to each target alarm entity may include: determining a time anomaly score corresponding to each target alarm entity based on the alarm occurrence time and business period corresponding to each target alarm entity; determining an entity anomaly score corresponding to each target alarm entity based on the comparison results between each target alarm entity and each preset alarm entity; determining a rule anomaly score corresponding to each target alarm entity based on the alarm triggering rule corresponding to each target alarm entity; and determining a behavioral pattern score corresponding to each target alarm entity based on the time anomaly score, entity anomaly score, and rule anomaly score corresponding to each target alarm entity.
[0042] Specifically, when the alarm occurrence time of a target alarm entity falls within the business period, the time anomaly score of that target alarm entity is determined as the first time anomaly score. When the alarm occurrence time of a target alarm entity does not fall within the business period but falls within the first or second boundary period, the time anomaly score of that target alarm entity is determined as the second time anomaly score. When the alarm occurrence time of a target alarm entity does not fall within the business period, the first boundary period, or the second boundary period, the time anomaly score of that target alarm entity is determined as the third time anomaly score.
[0043] The first boundary period is a preset period before the business session, and the second boundary period is a preset period after the business session. For example, the first 30 minutes before the business session can be used as the first boundary period, and the last 30 minutes after the business session can be used as the second boundary period. The first, second, and third time anomaly scores increase sequentially. Each time anomaly score can be determined based on user needs and historical experience. For example, the first, second, and third time anomaly scores can be set to 0.9, 1.1, and 1.3, respectively.
[0044] When a target alarm entity matches any preset alarm entity, the entity anomaly score corresponding to that target alarm entity is determined as the first entity anomaly score. When a target alarm entity does not match any preset alarm entity, the entity anomaly score corresponding to that target alarm entity is determined as the second entity anomaly score. The second entity anomaly score is greater than the first entity anomaly score. Each entity anomaly score can be determined based on user needs and historical experience; for example, the second entity anomaly score can be set to 1.5, and the first entity anomaly score can be set to any value less than 1.5.
[0045] When the historical trigger count of an alarm trigger rule for a target alarm entity exceeds the first threshold, the rule anomaly score corresponding to that target alarm entity is determined as the first rule anomaly score. When the historical trigger count of an alarm trigger rule for a target alarm entity is less than or equal to the first threshold but greater than the second threshold, the rule anomaly score corresponding to that target alarm entity is determined as the second rule anomaly score. When the historical trigger count of an alarm trigger rule for a target alarm entity is less than or equal to the second threshold but greater than the third threshold, the rule anomaly score corresponding to that target alarm entity is determined as the third rule anomaly score. When the historical trigger count of an alarm trigger rule for a target alarm entity is less than or equal to the third threshold, the rule anomaly score corresponding to that target alarm entity is determined as the fourth rule anomaly score. The first, second, and third thresholds decrease sequentially, while the first, second, third, and fourth rule anomaly scores increase sequentially. The threshold values for each number of occurrences and the abnormal scores for each rule can be determined based on user needs and historical experience. For example, the threshold values for the first, second, and third occurrences can be set to 20, 5, and 1, respectively, and the abnormal scores for the first, second, third, and fourth rules can be set to 0.6, 0.8, 1, and 1.3, respectively.
[0046] After determining the time anomaly score, entity anomaly score, and rule anomaly score corresponding to each target alarm entity, a multiplication operation can be performed on the time anomaly score, entity anomaly score, and rule anomaly score corresponding to each target alarm entity to obtain the behavior pattern score corresponding to each target alarm entity.
[0047] Optionally, determining the alarm accuracy score corresponding to each target alarm entity may include: when the alarm accuracy of a target alarm entity is greater than the maximum value of a first accuracy range, determining the alarm accuracy score corresponding to that target alarm entity as the first alarm accuracy score; when the alarm accuracy of a target alarm entity is within the first accuracy range, determining the alarm accuracy score corresponding to that target alarm entity as the second alarm accuracy score; when the alarm accuracy of a target alarm entity is within the second accuracy range, determining the alarm accuracy score corresponding to that target alarm entity as the third alarm accuracy score; and when the alarm accuracy of a target alarm entity is less than the minimum value of the second accuracy range, determining the alarm accuracy score corresponding to that target alarm entity as the fourth alarm accuracy score. Wherein, the maximum value of the second accuracy range is less than the minimum value of the first accuracy range, and the first, second, third, and fourth alarm accuracy scores decrease sequentially. Each accuracy range and each alarm accuracy score can be determined based on user needs and historical experience. For example, the first accuracy range can be set to greater than 0.6 and less than or equal to 0.8; the second accuracy range can be set to greater than or equal to 0.4 and less than or equal to 0.6; and the first alarm accuracy score, the second alarm accuracy score, the third alarm accuracy score, and the fourth alarm accuracy score can be set to 1.4, 1.1, 0.9, and 0.5, respectively.
[0048] Optionally, since a target alarm entity that has always been quiet suddenly starts issuing alarms, requiring greater vigilance; a target alarm entity that has consistently issued frequent alarms, an additional alarm is not surprising; and a target alarm entity that suddenly experiences a surge in alarms may be under attack, the alarm increment score corresponding to each target alarm entity can be determined as follows: when the current number of alarms for a target alarm entity is greater than the historical average number of alarms by a first set multiple, the alarm increment score corresponding to that target alarm entity is determined as the first alarm increment score. When the current number of alarms for a target alarm entity is less than or equal to the historical average number of alarms by a first set multiple, and greater than the historical average number of alarms by a second set multiple, the alarm increment score corresponding to that target alarm entity is determined as the second alarm increment score.
[0049] When the current alarm count of a target alarm entity is less than or equal to the historical alarm count average of a second set multiple, and greater than the historical alarm count average of a third set multiple, the alarm increment score corresponding to that target alarm entity is determined as the third alarm increment score. When the current alarm count of a target alarm entity is less than or equal to the historical alarm count average of a third set multiple, and greater than the historical alarm count average of a fourth set multiple, the alarm increment score corresponding to that target alarm entity is determined as the fourth alarm increment score. When the current alarm count of a target alarm entity is less than or equal to the historical alarm count average of a fourth set multiple, the alarm increment score corresponding to that target alarm entity is determined as the fifth alarm increment score. The historical alarm count average can be the average of the historical alarm counts over the past few days, such as 7 days. Each set multiplier and each alarm increment score can be set according to user needs and historical experience. For example, the first set multiplier, the second set multiplier, the third set multiplier, and the fourth set multiplier can be set to 5, 2, 1.5, and 0.9, respectively; and the first alarm increment score, the second alarm increment score, the third alarm increment score, the fourth alarm increment score, and the fifth alarm increment score can be set to 1.8, 1.5, 1.2, 1, and 0.9, respectively.
[0050] S250. Based on the alarm frequency score, behavior pattern score, alarm accuracy score and alarm increment score corresponding to each target alarm entity, determine the baseline deviation risk score corresponding to each alarm to be detected.
[0051] In this step, specifically, the alarm frequency score, behavior pattern score, alarm accuracy score, and alarm increment score corresponding to each target alarm entity can be multiplied to obtain the baseline deviation risk score corresponding to each alarm to be detected.
[0052] S260. Based on the alarm confidence score and intelligence database relevance score corresponding to each alarm to be detected, determine the threat intelligence risk score corresponding to each alarm to be detected.
[0053] In this step, specifically, the threat intelligence risk score corresponding to each alarm to be detected can be determined based on the alarm confidence score, intelligence database relevance score, and alarm source weight average value corresponding to each alarm to be detected.
[0054] Optionally, based on the alarm confidence score and intelligence database relevance score corresponding to each alarm to be detected, a threat intelligence risk score corresponding to each alarm to be detected is determined. This may include: determining multiple threat intelligence tags corresponding to each alarm to be detected, and tag-specific scores, tag timeliness scores, and intelligence database confidence scores corresponding to each threat intelligence tag; determining single-tag scores corresponding to each threat intelligence tag based on the tag-specific scores, tag timeliness scores, and intelligence database confidence scores corresponding to each threat intelligence tag; determining target threat intelligence tags corresponding to each alarm to be detected based on the single-tag scores of the threat intelligence tags corresponding to each alarm to be detected; determining alarm confidence scores corresponding to each alarm to be detected based on the single-tag scores of the target threat intelligence tags corresponding to each alarm to be detected; determining intelligence database relevance scores corresponding to each alarm to be detected; and determining threat intelligence risk scores corresponding to each alarm to be detected based on the alarm confidence scores and intelligence database relevance scores corresponding to each alarm to be detected.
[0055] Threat intelligence tags can be of various types, such as malware hosting server tags, botnet server tags, phishing site tags, spam source tags, brute-force source tags, port scanning source tags, and suspicious behavior tags. The inherent tag scores for malware hosting server tags, botnet server tags, phishing site tags, spam source tags, brute-force source tags, port scanning source tags, and suspicious behavior tags decrease in that order.
[0056] Specifically, the confidence score of the intelligence database corresponding to each threat intelligence tag can be determined based on the primary threat intelligence database corresponding to each threat intelligence tag. This primary threat intelligence database can be of various types, such as an internal intelligence database, a blacklist intelligence database, a market intelligence database, and an open-source intelligence database. The confidence scores of the internal intelligence database, blacklist intelligence database, market intelligence database, and open-source intelligence database decrease sequentially.
[0057] Simultaneously, based on the current time and the last appearance time corresponding to each threat intelligence tag, the dormancy time corresponding to each threat intelligence tag can be determined, and the tag validity score corresponding to each threat intelligence tag can be determined based on the dormancy time corresponding to each threat intelligence tag. For example, when the dormancy time corresponding to a threat intelligence tag is less than the minimum value of the first dormancy time range, the tag validity score corresponding to that threat intelligence tag can be determined as the first validity score. When the dormancy time corresponding to a threat intelligence tag is within the first dormancy time range, the tag validity score corresponding to that threat intelligence tag can be determined as the second validity score. When the dormancy time corresponding to a threat intelligence tag is within the second dormancy time range, the tag validity score corresponding to that threat intelligence tag can be determined as the third validity score. When the dormancy time corresponding to a threat intelligence tag is greater than the maximum value of the second dormancy time range, the tag validity score corresponding to that threat intelligence tag can be determined as the fourth validity score. The maximum value of the first dormancy time range is less than the minimum value of the first dormancy time range. The first, second, third, and fourth validity scores decrease sequentially. Each period of silence and each effective score can be set according to user needs and historical experience. For example, the first period of silence can be set to greater than or equal to 7 and less than 30; the second period of silence can be set to greater than or equal to 30 and less than or equal to 90; and the first, second, third, and fourth timeliness scores can be set to 1, 0.9, 0.7, and 0.4, respectively.
[0058] After determining the tag-specific score, tag-timeliness score, and intelligence database confidence score corresponding to each threat intelligence tag, a multiplication operation can be performed on these scores to obtain the single-tag score corresponding to each alert to be detected. Then, the single-tag scores corresponding to each alert to be detected can be sorted in descending order to obtain the sorted results. Finally, the top preset number of threat intelligence tags from each single-tag score sorted result can be used as the target threat intelligence tags corresponding to the corresponding alert to be detected. The preset number can be understood as any integer not exceeding 3, determined based on the threat intelligence tag type corresponding to each alert to be detected. For example, if the threat intelligence tags of an alert to be detected are botnet server, phishing site, and spam source, the preset number corresponding to that alert can be set to 3; if the threat intelligence tag of an alert to be detected is only a suspicious behavior tag, the preset number corresponding to that alert can be set to 1.
[0059] After determining the single-label score of the target threat intelligence label corresponding to each alarm to be detected, the average of the single-label scores of the target threat intelligence labels corresponding to each alarm to be detected can be calculated to obtain the alarm confidence score corresponding to each alarm to be detected.
[0060] In determining the alert confidence score, the source entity, target entity, file unique identifier string, and domain name corresponding to each alert to be detected can be identified. Then, based on the second threat intelligence database containing the source entity, target entity, file unique identifier string, and domain name corresponding to each alert to be detected, and the alert type of each alert to be detected, the relevance score of the intelligence database corresponding to each alert to be detected can be determined. The second threat intelligence database can be of various types, such as a malicious intelligence database, a botnet control node database, and a phishing database.
[0061] For example, when the threat intelligence databases containing the source entity, target entity, file unique identifier string, and domain name corresponding to a certain alarm to be detected are respectively a malicious intelligence database, a botnet control node database, a malicious intelligence database, and a phishing database, and the alarm type of the alarm to be detected is malicious access-external connection type, the intelligence database relevance sub-scores for the alarm to be detected in the dimensions of source entity, target entity, file unique identifier string, and domain name are determined to be a first relevance score, a second relevance score, a third relevance score, and a fourth relevance score, respectively. Then, the average of the first relevance score, the second relevance score, the third relevance score, and the fourth relevance score can be calculated to obtain the intelligence database relevance score corresponding to the alarm to be detected.
[0062] When the source entity and target entity of a certain alarm to be detected are both located in a malicious intelligence database, the file unique identifier string and domain name are not in any second threat intelligence database, and the alarm type of the alarm to be detected is local file access - inline type, the intelligence database relevance sub-scores of the alarm to be detected in the dimensions of source entity, target entity, file unique identifier string and domain name are determined to be the fifth relevance score, the sixth relevance score, the seventh relevance score and the eighth relevance score, respectively. Among them, each relevance score can be set according to user needs and historical experience. For example, the first relevance score, the second relevance score, the third relevance score, the fourth relevance score, the fifth relevance score, the sixth relevance score, the seventh relevance score and the eighth relevance score can be set to 1, 1, 0.95, 0.9, 0.3, 0.8, 0 and 0, respectively.
[0063] After determining the alarm confidence score and intelligence database relevance score corresponding to each alarm to be detected, the average alarm source weight corresponding to each alarm can be determined based on the first threat intelligence database where the target threat intelligence tags corresponding to each alarm are located. For example, when the target threat intelligence tags corresponding to a certain alarm to be detected are internal intelligence database, blacklist intelligence database, market intelligence database, and open source intelligence database, the alarm source weights corresponding to that alarm to be detected can be determined to be 80%, 70%, 50%, and 30%, respectively, thus the average alarm source weight corresponding to that alarm to be detected can be determined to be 0.575.
[0064] After determining the average weight of the alarm source corresponding to each alarm to be detected, the threat intelligence risk score corresponding to each alarm to be detected can be determined using the following specific formula: in, To score threat intelligence risks, To score the confidence level of the alarm. Score the relevance of the intelligence database. This represents the average weight of alarm sources.
[0065] S270. Based on the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected, determine the verification score corresponding to each alarm to be detected.
[0066] In one specific implementation, the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected can be directly weighted and summed to obtain the verification score corresponding to each alarm to be detected.
[0067] Optionally, a verification score corresponding to each alarm to be detected can be determined based on the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected. This can include: determining the rule verification score corresponding to each alarm to be detected based on the current false alarm rate; determining the entity verification score corresponding to each alarm to be detected based on the entity effectiveness rate of the target alarm entity corresponding to each alarm to be detected; determining the historical verification score of each alarm to be detected based on the total number of historical alarms and the historical false alarm rate of each alarm to be detected within the target historical time period; and determining the verification score corresponding to each alarm to be detected based on the rule verification score, entity verification score, and historical verification score.
[0068] Specifically, regarding the rule validation score, the alarm rule corresponding to each alarm to be detected can be determined, and based on the current false alarm rate corresponding to each alarm rule, the rule-specific score, false alarm rate penalty score, and false alarm rate trend score corresponding to each alarm rule can be determined. Then, based on the rule-specific score, false alarm rate penalty score, and false alarm rate trend score corresponding to each alarm rule, the rule validation score corresponding to each alarm to be detected can be determined.
[0069] For example, when the current false positive rate of an alarm rule is less than 10%, the rule level corresponding to that alarm rule can be determined as high reliability, with an inherent rule score of 1.8. When the current false positive rate of an alarm rule is between 10% and 30%, the rule level corresponding to that alarm rule can be determined as medium, with an inherent rule score of 1.2. When the current false positive rate of an alarm rule is greater than 60%, the rule level corresponding to that alarm rule can be determined as low quality, with an inherent rule score of 0.4.
[0070] When the current false alarm rate of an alarm rule is less than 10%, the false alarm rate penalty score corresponding to that alarm rule can be set to 0. When the current false alarm rate of an alarm rule is greater than or equal to 10% and less than 30%, the penalty score can be set using the formula... Determine the false alarm rate penalty score corresponding to the alarm rule. The false alarm rate is penalized with points. This represents the current false alarm rate. When the current false alarm rate of a certain alarm rule is greater than or equal to 30% and less than 60%, it is determined by the formula... The false alarm rate penalty score corresponding to the alarm rule is determined. When the current false alarm rate of an alarm rule is greater than or equal to 60%, the false alarm rate penalty score corresponding to the alarm rule is determined to be -0.5.
[0071] To determine the false alarm rate trend score corresponding to each alarm rule, the false alarm rate change rate can first be determined using the following specific calculation formula: in, The rate of change of false alarm rate. The current false alarm rate, This represents the historical false alarm rate.
[0072] Then, when the rate of change of the false alarm rate is less than -0.3, it can be determined that the false alarm rate trend is significantly decreasing, and the false alarm rate trend score is set to 0.2. When the rate of change of the false alarm rate is greater than or equal to -0.3 but less than 0.3, it can be determined that the false alarm rate trend is not changing significantly, and the false alarm rate trend score is set to 0. When the rate of change of the false alarm rate is greater than 0.3, it can be determined that the false alarm rate trend is significantly increasing, and the false alarm rate trend score is set to -0.2.
[0073] After determining the rule-specific score, false alarm rate penalty score, and false alarm rate trend score corresponding to each alarm rule, the rule validation score corresponding to each alarm to be detected can be determined using the following specific formula: in, To validate scores according to the rules, To validate the weights for the rules, The false alarm rate is penalized with points. The false alarm rate trend score.
[0074] Regarding entity verification scores, the entity validity rate corresponding to each alarm to be detected can be determined based on whether the target alarm entity corresponding to each alarm is valid. The entity credibility score corresponding to each alarm to be detected can be determined based on the total number of target alarm entities corresponding to each alarm. Then, the entity verification score corresponding to each alarm to be detected can be determined based on the entity validity rate and entity credibility score of the target alarm entities corresponding to each alarm.
[0075] For example, the effectiveness rate of each entity corresponding to each alarm to be detected can be determined by the following specific calculation formula: in, For the sake of physical efficiency, The total number of entities receiving effective target alarms. This represents the total number of invalid target alarm entities.
[0076] The total number of target alarm entities corresponding to each alarm to be detected is determined by the following specific calculation formula: in, The total number of entities that trigger alarms.
[0077] Then, when the total number of target alarm entities corresponding to a certain alarm to be detected is less than 10, the credibility score of the entity corresponding to the alarm to be detected is determined to be 0.3. When the total number of target alarm entities corresponding to a certain alarm to be detected is greater than or equal to 10 and less than 50, the credibility score of the entity corresponding to the alarm to be detected is determined to be 0.6. When the total number of target alarm entities corresponding to a certain alarm to be detected is greater than or equal to 50 and less than 200, the credibility score of the entity corresponding to the alarm to be detected is determined to be 0.9. When the total number of target alarm entities corresponding to a certain alarm to be detected is greater than or equal to 200, the credibility score of the entity corresponding to the alarm to be detected is determined to be 1.
[0078] After determining the entity effectiveness rate and entity credibility score corresponding to each alarm to be detected, the entity verification score corresponding to each alarm to be detected can be determined using the following specific calculation formula: in, For entity verification scores, For the sake of physical efficiency, This represents the entity's credibility score.
[0079] Regarding historical verification scores, if an alarm to be detected is repeated 5 times in the past 24 hours and all of them are false alarms, the historical verification score corresponding to that alarm is determined to be 0.3. If an alarm to be detected is repeated 5 times in the past 24 hours and not all of them are false alarms, the historical verification score corresponding to that alarm is determined to be 0.7. If an alarm to be detected has not occurred in the past 24 hours, the historical verification score corresponding to that alarm is determined to be 1.
[0080] Furthermore, based on the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected, a verification score corresponding to each alarm to be detected is determined, including: determining a joint feedback score corresponding to each alarm to be detected based on the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected; determining a feedback timeliness score corresponding to each alarm to be detected based on the alarm occurrence time corresponding to each alarm to be detected; determining an urgency score corresponding to each alarm to be detected based on the joint feedback score corresponding to each alarm to be detected; and determining a verification score corresponding to each alarm to be detected based on the joint feedback score, feedback timeliness score, and urgency score corresponding to each alarm to be detected.
[0081] Specifically, for the joint feedback score, a weighted sum can be calculated by combining the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected, resulting in a joint feedback sub-score for each alarm. Then, the rule verification weight, entity verification weight, and historical verification weight are added together to obtain a weighted sum. Finally, the joint feedback sub-score corresponding to each alarm to be detected is divided by the weighted sum to obtain the joint feedback score for each alarm.
[0082] For feedback timeliness scoring, the feedback timeliness score corresponding to each alarm to be detected can be determined based on the current time and the alarm occurrence time corresponding to each alarm to be detected.
[0083] For example, the feedback time difference corresponding to a specific alarm can be obtained by subtracting the alarm occurrence time from the current time. Then, if the feedback time difference is less than 7 days, the feedback timeliness score corresponding to the alarm is determined to be 1 point. If the feedback time difference is greater than or equal to 7 days and less than 30 days, the feedback timeliness score is determined to be 0.95 points. If the feedback time difference is greater than or equal to 30 days and less than 90 days, the feedback timeliness score is determined to be 0.8 points. If the feedback time difference is greater than 90 days, the feedback timeliness score is determined to be 0.5 points.
[0084] Regarding urgency scoring, the urgency score can be set as the preset feedback score threshold when the combined feedback score is greater than it. Conversely, the urgency score can be set as the combined feedback score when the combined feedback score is less than or equal to the preset feedback score threshold. The preset feedback score threshold can be determined based on user needs and historical experience; for example, it can be set to 1.
[0085] After determining the joint feedback score, feedback timeliness score, and urgency score corresponding to each alarm to be detected, a multiplication operation can be performed on the joint feedback score, feedback timeliness score, and urgency score corresponding to each alarm to be detected to obtain the verification score corresponding to each alarm to be detected.
[0086] Optionally, to ensure the credibility of alert triggering rules, entities, similar alerts, and threat intelligence, when an alert to be detected is marked as a false positive, the quality of the affected rule, the false positive count of the associated entity, similar alerts within the past 24 hours can be automatically updated, marked as requiring re-examination and re-evaluation, and the threat score of the threat intelligence can be automatically reduced. For example, when the current false positive rate of an alert triggering rule exceeds 30%, an alert rule quality deterioration warning can be triggered. When an alert to be detected is marked as a false positive, other alerts to be detected with the same triggering rule, the same source / destination address, and a similar time frame are treated as similar alerts. When an entity previously marked as malicious is frequently marked as a false positive, the threat score of the threat intelligence corresponding to that entity is automatically reduced.
[0087] S280. Determine the alarm score corresponding to each alarm to be detected based on the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm to be detected.
[0088] S290. Determine the authenticity of each alarm to be detected based on its alarm score.
[0089] The technical solution of this embodiment obtains the target alarm entities corresponding to each alarm to be detected and determines the alarm frequency anomaly score, behavior pattern score, alarm accuracy score, and alarm increment score corresponding to each target alarm entity. Based on the alarm frequency score, behavior pattern score, alarm accuracy score, and alarm increment score corresponding to each target alarm entity, a baseline deviation risk score corresponding to each alarm to be detected is determined. This technical means can accurately distinguish between abnormal alarms and routine alarms, providing a foundation for accurately determining the authenticity of alarms. Secondly, by using the alarm confidence score and intelligence database relevance score corresponding to each alarm to be detected, a threat intelligence risk score corresponding to each alarm to be detected is determined. This can integrate heterogeneous threat intelligence sources and dynamically associate alarms and intelligence, thereby accurately determining the authenticity of alarms. Finally, by using the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected, a verification score corresponding to each alarm to be detected is determined. This can more accurately determine the verification score corresponding to each alarm to be detected, thereby further improving the accuracy of the alarm authenticity determination results.
[0090] It should be noted that the above operations S220-S230, S240-S250, S260, and S270 can be executed sequentially or in parallel. That is, the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm to be detected can be determined sequentially, or the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each alarm to be detected can be determined simultaneously. This embodiment does not make specific limitations.
[0091] To illustrate the alarm authenticity detection method for operation and maintenance scenarios in this invention in detail, the following example illustrates an abnormal external connection case involving the internal network Internet Protocol (IP): The scenario is described as follows: Alarm time: 23:45 on November 15, 2025 (non-business hours); Source IP: 192.168.1.100 (internal network development machine); Destination IP: 203.0.113.45 (external network); Alarm rule: suspicious outbound connection; Rule description: an internal IP establishes an abnormal protocol connection to an unknown external IP; Alarm characteristics: suspected malicious control of communication, destination port 8443, traffic encryption, and abnormal data transmission volume.
[0092] Regarding the inherent risk scoring, since the access to an unknown external IP occurred outside of business hours, the access pattern score, access address score, fault lifecycle score, and historical validity score corresponding to this alarm can be determined to be 25, 30, 20, and 10, respectively, resulting in an access behavior score of 85 for each alarm. Because the internal network development machine is of moderate importance and port 8443 is very common, the entity importance score can be determined to be 1.5, and the port risk score to be 0.33, resulting in an entity importance score of approximately 2 for each alarm. Since the internal network development machine has a history of vulnerabilities, the vulnerability score corresponding to this alarm can be determined to be 1.2. Because an encrypted connection was established with an unknown IP outside of business hours, the risk characteristic score corresponding to this alarm can be determined to be 1.8. Since the alarm occurred in the early morning, the propagation timeliness score corresponding to this alarm can be determined to be 1.3. In summary, ignoring historical false alarm scores, the inherent risk score corresponding to this alarm to be detected can be determined to be 68 points.
[0093] Regarding the baseline deviation risk score, since the source IP suddenly alarmed very quietly, the alarm frequency score corresponding to the alarm to be detected can be set to 1.5, given that the maximum scoring threshold for alarm frequency scoring is 1.5. Since the alarm occurred outside of the business hours, the time anomaly score for the target alarm entity is determined to be 1.3. Since the destination IP is inconsistent with any common alarm entity, the entity anomaly score corresponding to the target alarm entity can be set to 1.5. Since the alarm triggering rule corresponding to the alarm to be detected is being triggered for the first time, the rule anomaly score corresponding to the target alarm entity can be set to 1.3, thus the behavior pattern score corresponding to the target alarm entity is set to 2. Since the alarm accuracy corresponding to the target alarm entity is greater than 0.6 and less than or equal to 0.8, the alarm accuracy score corresponding to the target alarm entity can be set to 1.1. Since the current number of alarms for the target alarm entity corresponding to the alarm to be detected is less than or equal to 1.5 of the historical average number of alarms, and greater than 0.9 of the historical average number of alarms, the alarm increment score corresponding to the target alarm entity can be determined to be 1. In summary, the baseline deviation risk score of the alarm to be detected can be determined to be 1.83.
[0094] Regarding the threat intelligence risk scoring, since the threat intelligence tags corresponding to the alert to be detected include malware hosting server tags and botnet server tags, and neither of them are suspicious behavior tags, both malware hosting server tags and botnet server tags can be used as target threat intelligence tags corresponding to the alert to be detected. Then, with the single tag scores corresponding to malware hosting server tags and botnet server tags being 0.88 and 0.649 respectively, the alert confidence score corresponding to the alert to be detected can be determined to be 0.765.
[0095] Subsequently, since the source IP, file unique identifier string, and domain name of the alert to be detected were not found in any second threat intelligence database, and the target IP was located in a botnet control node database, and the alert type was local file access - inline, it can be determined that the intelligence database relevance sub-scores for the source IP, target IP, file unique identifier string, and domain name dimensions of the alert to be detected are 0, 1, 0, and 0, respectively, resulting in an intelligence database relevance score of 0.25 for the alert to be detected. In summary, the threat intelligence risk score corresponding to the alert to be detected can be determined to be 1.049. Furthermore, since the target IP is in the botnet control node database and has obvious characteristics, the threat intelligence risk score can be adjusted to 1.75.
[0096] For the verification score, based on the joint feedback score, feedback timeliness score, and urgency score corresponding to the alarm to be detected, the verification score corresponding to the alarm to be detected is determined to be 0.746.
[0097] After obtaining the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to the alarm to be detected, the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score can be multiplied to obtain an alarm score of 162.5 points corresponding to the alarm to be detected, thereby determining that the alarm to be detected is a real alarm and has an extremely high risk.
[0098] Example 3 Figure 3 This is a schematic diagram of an alarm authenticity detection device for operation and maintenance scenarios provided in Embodiment 3 of the present invention. This embodiment can be applied to the situation of performing authenticity detection on multiple alarms to be detected generated by the target operation and maintenance system. The alarm authenticity detection device for operation and maintenance scenarios can be implemented in hardware and / or software and can be configured in electronic devices such as computers.
[0099] like Figure 3 As shown, the alarm authenticity detection device for operation and maintenance scenarios disclosed in this embodiment includes: The scoring component determination module 31 is used to acquire multiple alarms to be detected generated by the target operation and maintenance system, and determine the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected. The alarm score determination module 32 is used to determine the alarm score corresponding to each alarm to be detected based on the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected. The alarm authenticity detection module 33 is used to determine the authenticity of each alarm to be detected based on the alarm score of each alarm to be detected.
[0100] The technical solution in this embodiment, through the cooperation of the scoring component determination module 31, the alarm scoring determination module 32, and the alarm authenticity detection module 33, solves the problem that the existing technology has low accuracy in judging the authenticity of alarms, which affects the efficiency of fault handling. It can accurately determine the authenticity of each alarm to be detected, thereby effectively improving the efficiency of fault handling.
[0101] Optionally, the scoring component determination module 31 includes: The inherent risk scoring unit is used to determine the access behavior score, entity importance score, historical false alarm score, vulnerability score, risk characteristic score, and propagation timeliness score corresponding to each alarm to be detected, based on the behavior and attribute information corresponding to each alarm to be detected; and to determine the inherent risk score corresponding to each alarm to be detected based on the access behavior score, entity importance score, historical false alarm score, vulnerability score, risk characteristic score, and propagation timeliness score corresponding to each alarm to be detected. The baseline deviation scoring determination unit is used to acquire the target alarm entity corresponding to each alarm to be detected; determine the alarm frequency anomaly score, behavior pattern score, alarm accuracy score and alarm increment score corresponding to each target alarm entity; and determine the baseline deviation risk score corresponding to each alarm to be detected based on the alarm frequency score, behavior pattern score, alarm accuracy score and alarm increment score corresponding to each target alarm entity. The threat intelligence risk scoring unit is used to determine multiple threat intelligence tags corresponding to each alarm to be detected, as well as tag-specific scores, tag timeliness scores, and intelligence database confidence scores corresponding to each threat intelligence tag; based on the tag-specific scores, tag timeliness scores, and intelligence database confidence scores corresponding to each threat intelligence tag, it determines the single tag score corresponding to each threat intelligence tag; based on the single tag scores of the threat intelligence tags corresponding to each alarm to be detected, it determines the target threat intelligence tags corresponding to each alarm to be detected; based on the single tag scores of the target threat intelligence tags corresponding to each alarm to be detected, it determines the alarm confidence score corresponding to each alarm to be detected; it determines the intelligence database relevance score corresponding to each alarm to be detected, and based on the alarm confidence score and intelligence database relevance score corresponding to each alarm to be detected, it determines the threat intelligence risk score corresponding to each alarm to be detected. The verification scoring unit is used to determine the rule verification score corresponding to each alarm to be detected based on the current false alarm rate corresponding to each alarm to be detected; to determine the entity verification score corresponding to each alarm to be detected based on the entity effectiveness rate of the target alarm entity corresponding to each alarm to be detected; to determine the historical verification score of each alarm to be detected based on the total number of historical alarms and the historical false alarm rate of each alarm to be detected within the target historical time period; and to determine the verification score corresponding to each alarm to be detected based on the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected.
[0102] Optionally, the baseline deviation scoring determination unit includes: The frequency anomaly scoring subunit is used to obtain the current alarm count of each target alarm entity within the current set time period, and the historical alarm count within multiple historical time periods; determine the mean alarm count and standard deviation of each target alarm entity based on the current alarm count and historical alarm count corresponding to each target alarm entity; determine the alarm frequency score corresponding to each target alarm entity based on the current alarm count, mean alarm count, and standard deviation of each alarm count corresponding to each target alarm entity; and determine the alarm frequency anomaly score corresponding to each target alarm entity based on the alarm frequency score corresponding to each target alarm entity and a predefined frequency score range. The behavior pattern scoring determination subunit is used to determine the time anomaly score corresponding to each target alarm entity based on the alarm occurrence time and business period corresponding to each target alarm entity; to determine the entity anomaly score corresponding to each target alarm entity based on the comparison results between each target alarm entity and each preset alarm entity; to determine the rule anomaly score corresponding to each target alarm entity based on the alarm triggering rule corresponding to each target alarm entity; and to determine the behavior pattern score corresponding to each target alarm entity based on the time anomaly score, entity anomaly score, and rule anomaly score corresponding to each target alarm entity.
[0103] Optionally, the verification scoring unit is specifically used for: determining a joint feedback score corresponding to each alarm to be detected based on the rule verification score, entity verification score, and historical verification score corresponding to each alarm to be detected; determining a feedback timeliness score corresponding to each alarm to be detected based on the alarm occurrence time corresponding to each alarm to be detected; determining an urgency score corresponding to each alarm to be detected based on the joint feedback score corresponding to each alarm to be detected; and determining a verification score corresponding to each alarm to be detected based on the joint feedback score, feedback timeliness score, and urgency score corresponding to each alarm to be detected.
[0104] The alarm authenticity detection device for operation and maintenance scenarios provided in this embodiment of the invention can execute the alarm authenticity detection method for operation and maintenance scenarios provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method execution. Content not described in detail in this embodiment can be referred to the description in any method embodiment of this application.
[0105] Example 4 Figure 4 A schematic diagram of the structure of an electronic device 10 that can be used to implement embodiments of the present invention is shown. For example... Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0106] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0107] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, central processing unit (CPU), graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as alarm authenticity detection methods for operational scenarios.
[0108] In some embodiments, the alarm authenticity detection method for operation and maintenance scenarios can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the alarm authenticity detection method for operation and maintenance scenarios described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the alarm authenticity detection method for operation and maintenance scenarios by any other suitable means (e.g., by means of firmware).
[0109] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0110] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0111] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0112] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0113] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0114] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0115] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0116] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for detecting the authenticity of alarms in operation and maintenance scenarios, characterized in that, The method includes: Acquire multiple alarms to be detected generated by the target operation and maintenance system, and determine the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected; Based on the inherent risk score, baseline deviation risk score, threat intelligence risk score, and verification score corresponding to each of the aforementioned alarms to be detected, the alarm score corresponding to each of the aforementioned alarms to be detected is determined. The authenticity of each alarm to be detected is determined based on its alarm score.
2. The method according to claim 1, characterized in that, Determine the inherent risk score corresponding to each of the aforementioned alarms to be detected, including: Based on the behavior and attribute information corresponding to each of the aforementioned alarms to be detected, determine the access behavior score, entity importance score, historical false alarm score, vulnerability score, risk characteristic score, and propagation timeliness score corresponding to each of the aforementioned alarms to be detected. Based on the access behavior score, entity importance score, historical false alarm score, vulnerability score, risk characteristic score, and propagation timeliness score corresponding to each of the aforementioned alarms to be detected, the inherent risk score corresponding to each of the aforementioned alarms to be detected is determined.
3. The method according to claim 1, characterized in that, Determine the baseline deviation risk score corresponding to each of the aforementioned alarms to be detected, including: Obtain the target alarm entity corresponding to each of the alarms to be detected; Determine the alarm frequency anomaly score, behavior pattern score, alarm accuracy score, and alarm increment score corresponding to each of the target alarm entities; Based on the alarm frequency score, behavior pattern score, alarm accuracy score, and alarm increment score corresponding to each of the target alarm entities, a baseline deviation risk score corresponding to each of the alarms to be detected is determined.
4. The method according to claim 3, characterized in that, Determine the alarm frequency anomaly score corresponding to each of the target alarm entities, including: Obtain the current alarm count of each target alarm entity within the current set time period, and the historical alarm count within multiple historical time periods; Based on the current alarm count and historical alarm count corresponding to each of the target alarm entities, determine the mean alarm count and standard deviation of the alarm count corresponding to each of the target alarm entities. Based on the current number of alarms, the average number of alarms, and the standard deviation of the number of alarms corresponding to each of the target alarm entities, determine the alarm frequency score corresponding to each of the target alarm entities; Based on the alarm frequency score corresponding to each of the target alarm entities and the predefined frequency score range, an alarm frequency anomaly score is determined for each of the target alarm entities.
5. The method according to claim 3, characterized in that, Determine the behavioral pattern score corresponding to each of the aforementioned target alarm entities, including: Based on the alarm occurrence time and service period corresponding to each of the target alarm entities, determine the time anomaly score corresponding to each of the target alarm entities; Based on the comparison results between each target alarm entity and each preset alarm entity, determine the entity anomaly score corresponding to each target alarm entity; Based on the alarm triggering rules corresponding to each of the target alarm entities, determine the rule anomaly score corresponding to each of the target alarm entities; Based on the time anomaly score, entity anomaly score, and rule anomaly score corresponding to each of the target alarm entities, a behavioral pattern score corresponding to each of the target alarm entities is determined.
6. The method according to claim 1, characterized in that, Determine the threat intelligence risk score corresponding to each of the aforementioned alarms to be detected, including: Determine multiple threat intelligence tags corresponding to each of the aforementioned alarms to be detected, as well as tag-specific scores, tag timeliness scores, and intelligence database confidence scores corresponding to each of the aforementioned threat intelligence tags; Based on the tag-inherent score, tag timeliness score, and intelligence database confidence score corresponding to each of the aforementioned threat intelligence tags, determine the single tag score corresponding to each of the aforementioned threat intelligence tags; Based on the single-tag score of the threat intelligence tag corresponding to each of the aforementioned alarms to be detected, the target threat intelligence tag corresponding to each of the aforementioned alarms to be detected is determined; Based on the single-label score of the target threat intelligence label corresponding to each of the aforementioned alarms to be detected, the alarm confidence score corresponding to each of the aforementioned alarms to be detected is determined. Determine the intelligence database relevance score corresponding to each of the aforementioned alarms to be detected, and determine the threat intelligence risk score corresponding to each of the aforementioned alarms to be detected based on the alarm confidence score and the intelligence database relevance score.
7. The method according to claim 1, characterized in that, Determine the verification score corresponding to each of the aforementioned alarms to be detected, including: Based on the current false alarm rate corresponding to each of the aforementioned alarms to be detected, determine the rule verification score corresponding to each of the aforementioned alarms to be detected; Based on the entity effectiveness rate of the target alarm entity corresponding to each of the alarms to be detected, determine the entity verification score corresponding to each of the alarms to be detected. Based on the total number of historical alarms and the historical false alarm rate of each alarm to be detected within the target historical time period, the historical verification score of each alarm to be detected is determined. Based on the rule verification score, entity verification score, and historical verification score corresponding to each of the aforementioned alarms to be detected, a verification score is determined for each of the aforementioned alarms to be detected.
8. The method according to claim 7, characterized in that, Based on the rule verification score, entity verification score, and historical verification score corresponding to each of the aforementioned alarms to be detected, a verification score corresponding to each of the aforementioned alarms to be detected is determined, including: Based on the rule verification score, entity verification score, and historical verification score corresponding to each of the aforementioned alarms to be detected, a joint feedback score corresponding to each of the aforementioned alarms to be detected is determined. Based on the alarm occurrence time corresponding to each of the aforementioned alarms to be detected, a feedback timeliness score is determined for each of the aforementioned alarms to be detected. Based on the joint feedback score corresponding to each of the aforementioned alarms to be detected, determine the urgency score corresponding to each of the aforementioned alarms to be detected; Based on the joint feedback score, feedback timeliness score, and urgency score corresponding to each of the aforementioned alarms to be detected, a verification score is determined for each of the aforementioned alarms to be detected.
9. An alarm authenticity detection device for operation and maintenance scenarios, characterized in that, The device includes: The scoring component determination module is used to acquire multiple alarms to be detected generated by the target operation and maintenance system, and determine the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each alarm to be detected. The alarm scoring determination module is used to determine the alarm score corresponding to each of the alarms to be detected based on the inherent risk score, baseline deviation risk score, threat intelligence risk score and verification score corresponding to each of the alarms to be detected. The alarm authenticity detection module is used to determine the authenticity of each alarm to be detected based on the alarm score of each alarm to be detected.
10. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to execute the alarm authenticity detection method for operation and maintenance scenarios as described in any one of claims 1-8.