A method and device for detecting and backtracking compromised hosts based on mass network logs

By constructing a log library and intelligence library based on a columnar storage engine, and combining the detection mechanism of full and incremental intelligence libraries, the performance bottleneck and historical record backtracking problem of the streaming processing system were solved, achieving efficient detection and backtracking of compromised hosts, reducing the false negative rate and improving the reliability of detection results.

CN122419986APending Publication Date: 2026-07-17COLASOFT

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
COLASOFT
Filing Date
2026-06-15
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies suffer from severe performance bottlenecks when dealing with extremely large files or high-throughput log data, making it impossible to meet real-time detection requirements. Furthermore, the inability to store raw data results in the inability to trace back historical records of alarm events. As the intelligence database expands, the complexity of related queries increases dramatically, making it difficult to achieve effective detection and backtracking of compromised hosts.

Method used

A log library based on a columnar storage engine is used, combined with full and incremental intelligence databases. By using time segmentation and left join queries, full and incremental intelligence databases are constructed. The replication mechanism of the columnar storage engine is used for correlation backtracking and aggregation analysis to determine the list of compromised hosts.

Benefits of technology

It improves the efficiency of writing and querying log data, reduces the false negative rate, ensures the timeliness of the intelligence database, enables timely detection of historical threat correlations, reduces false positives, and achieves high-performance multi-dimensional correlation analysis and improved security analysis efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419986A_ABST
    Figure CN122419986A_ABST
Patent Text Reader

Abstract

本发明公开了一种基于海量网络日志的失陷主机检测与回溯方法和装置,属于网络安全技术领域。所述方法包括:构建基于列式存储引擎的日志库;获取并解析网络日志数据,将解析后的网络日志数据存储至所述日志库;获取外部威胁情报数据,分别构建全量情报库和增量情报库;将待检测的日志数据按时间划分为多个分段数据,并将每个分段数据分别与全量情报库和增量情报库进行关联检测,得到情报命中结果;基于所述情报命中结果,利用列式存储引擎的副本机制,对所述日志库中的历史数据进行关联回溯,得到历史关联数据;对所述历史关联数据进行聚合分析,确定失陷主机名单。本发明通过全量与增量相结合的检测机制,从而低了漏报率。
Need to check novelty before this filing date? Find Prior Art