A method and device for detecting and backtracking compromised hosts based on mass network logs
By constructing a log library and intelligence library based on a columnar storage engine, and combining the detection mechanism of full and incremental intelligence libraries, the performance bottleneck and historical record backtracking problem of the streaming processing system were solved, achieving efficient detection and backtracking of compromised hosts, reducing the false negative rate and improving the reliability of detection results.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- COLASOFT
- Filing Date
- 2026-06-15
- Publication Date
- 2026-07-17
AI Technical Summary
Existing technologies suffer from severe performance bottlenecks when dealing with extremely large files or high-throughput log data, making it impossible to meet real-time detection requirements. Furthermore, the inability to store raw data results in the inability to trace back historical records of alarm events. As the intelligence database expands, the complexity of related queries increases dramatically, making it difficult to achieve effective detection and backtracking of compromised hosts.
A log library based on a columnar storage engine is used, combined with full and incremental intelligence databases. By using time segmentation and left join queries, full and incremental intelligence databases are constructed. The replication mechanism of the columnar storage engine is used for correlation backtracking and aggregation analysis to determine the list of compromised hosts.
It improves the efficiency of writing and querying log data, reduces the false negative rate, ensures the timeliness of the intelligence database, enables timely detection of historical threat correlations, reduces false positives, and achieves high-performance multi-dimensional correlation analysis and improved security analysis efficiency.
Smart Images

Figure CN122419986A_ABST