A computer network information security management method based on data processing
Patent Information
- Application Number
- CN202610975822.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-02
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]但是,在实际网络环境中,网络侧数据、终端侧数据、账号权限数据和资源访问数据往往来源不同,时间粒度、字段格式和采集延迟并不一致
本申请通过将网络流量数据、终端进程数据、账号认证数据、权限变更数据、资源访问数据、资产拓扑数据和业务心跳数据统一解析为标准事件数据,并进一步按照资产标识、账号标识、进程标识、会话标识、资源标识和时间窗口标识归并形成安全状态单元,达到将分散在网络侧、终端侧、账号侧和资源侧的安全信息统一到同一可追踪对象中的效果。相较于仅依据单一日志、单一IP地址或单一告警进行风险判断的方式,本申请能够在同一时间窗口内反映账号、进程、会话和资源之间的实际关联关系,减少因账号共享、地址复用、多进程并发访问或日志来源割裂造成的误判,使后续风险识别具有更明确的数据基础。
Smart Images

Figure CN122845202A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer network security technology, and specifically to a computer network information security management method based on data processing. Background Technology
[0002] With the continuous interconnection of enterprise office systems, business servers, database resources, and remote access systems, computer network information security management typically needs to simultaneously monitor network connectivity, terminal processes, account authentication, permission changes, resource access, and business operation status. Existing security management systems mostly collect relevant data through firewalls, traffic probes, terminal proxies, log auditing systems, and security management platforms, and output security events based on alarm rules or risk models.
[0003] In existing technologies, a common approach is to clean, merge, and correlate multi-source logs, then combine this with asset level, vulnerability information, access frequency, or abnormal behavior to generate a risk level, thereby triggering actions such as alerts, blocking, isolation, or access restrictions. Some solutions also chain multiple alerts together based on attack chains, knowledge graphs, or security event topologies to help determine attack paths.
[0004] However, in real-world network environments, network-side data, terminal-side data, account permission data, and resource access data often originate from different sources, and their time granularity, field formats, and collection latency are inconsistent. If correlations are based solely on a single IP address, a single session, or similar time relationships, unrelated events can easily be mistakenly linked as attack chains, or real risk paths across hosts, accounts, and processes can be missed. Furthermore, if actions are directly applied to assets, ports, or accounts without verification based on business dependencies, it may disrupt the continuous operation of critical business processes while blocking risks. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a computer network information security management method based on data processing, in order to solve the technical problems existing in the prior art.
[0006] The above-mentioned technical objective of the present invention is achieved through the following technical solution: A computer network information security management method based on data processing includes the following steps: S1: Collect network traffic data, terminal process data, account authentication data, permission change data, resource access data, asset topology data, and service heartbeat data from the target network, and parse the collected data to generate standard event data. The standard event data includes asset identifier, account identifier, process identifier, session identifier, resource identifier, event time, event type, and data source identifier. S2: Merge standard event data according to asset identifier, account identifier, process identifier, session identifier, resource identifier and time window identifier to generate security status units. Security status units include security status units corresponding to network-side events and security status units corresponding to terminal-side events. S3: Match the security state unit corresponding to the network-side event with the security state unit corresponding to the terminal-side event. When both meet at least two anchoring conditions, generate a cross-layer evidence edge. The anchoring conditions include: consistent account identifier, consistent asset identifier, consistent session identifier, consistent network connection port and process port, the time difference between process start time and network connection time is within a preset time threshold, and resource access time is later than remote access time. S4: Construct a reachability evidence graph based on security state units and cross-layer evidence edges, and extract the minimum reachability evidence chain from the reachability evidence graph that points from the entry asset to sensitive resources or high-value assets. The minimum reachability evidence chain includes remote access status or abnormal connection status, permission change status or lateral access status, and sensitive resource reach status or external transmission status. S5: Calculate the blocking benefit value and business loss value for each cross-layer evidence edge in the minimum reachable evidence chain, and select the cross-layer evidence edge whose blocking benefit value reaches the preset blocking threshold and whose business loss value is the smallest as the disposal breakpoint. S6: Generate a shadow disposal strategy based on the disposal breakpoint, and generate a business dependency graph based on asset topology data and business heartbeat data. Calculate the set of reachable business links before loading the shadow disposal strategy and the set of reachable business links after loading the shadow disposal strategy based on the business dependency graph. Generate a differential link set based on the difference between the two sets of reachable business links. S7: When the differential link set does not contain a critical business link, or when the differential link set contains a critical business link and the business heartbeat of that critical business link remains normal, the shadow handling strategy will be converted into an actual handling strategy and issued for execution. S8: After executing the actual disposal strategy, re-collect the verification data of the security status units on both sides of the disposal breakpoint, and determine whether the minimum reachable evidence chain is blocked based on the verification data; if the minimum reachable evidence chain is blocked, reduce the sampling frequency of the security status units that are not related to the minimum reachable evidence chain; if the minimum reachable evidence chain is not blocked, return to step S5 to reselect the disposal breakpoint.
[0007] Preferably, in step S1, the collected data is parsed to generate standard event data, including: The source asset identifier, destination asset identifier, network connection port, protocol type, session identifier, and connection time are obtained by parsing network traffic data. Parsing the terminal process data yields the asset identifier, process identifier, parent process identifier, process port, process start time, and process end time. The account authentication data is parsed to obtain the account identifier, authentication asset identifier, authentication result, login time, and logout time. Parsing the permission change data yields the account identifier, permission change type, permission level before change, permission level after change, and change time. The resource access data is parsed to obtain the account identifier, process identifier, resource identifier, resource type, access action, and access time; The asset topology data is parsed to obtain the asset identifier, asset type, network segment, connection relationship, and asset level; The heartbeat data is parsed to obtain the business identifier, business link identifier, heartbeat time, heartbeat status, and dependent asset identifier.
[0008] Preferably, in step S2, generating a safety state unit includes: Standard event data is merged based on the same asset identifier, the same account identifier, the same process identifier, the same session identifier, the same resource identifier, and the same time window identifier. When a process identifier is missing within the same time window, it is merged according to asset identifier, account identifier, session identifier, and resource identifier; When a session identifier is missing within the same time window, it is merged according to asset identifier, account identifier, process identifier, and resource identifier; When resource identifiers are missing within the same time window, they are merged according to asset identifiers, account identifiers, process identifiers, and session identifiers, and the resource identifiers are recorded as unassociated resource identifiers. The merged standard event data is then written into the corresponding security status unit, so that each security status unit has a corresponding asset identifier, account identifier, process identifier, session identifier, resource identifier, time window identifier, and status type.
[0009] Preferably, in step S2, the state type of the security state unit is determined according to the following rules: When the standard event data contains a successfully authenticated remote login event, the corresponding security status unit will be marked as remote access status; When the standard event data contains information indicating that there is no preset business connection relationship between the source asset and the destination asset, and the network connection event does not match the preset whitelist communication relationship, the corresponding security status unit will be marked as an abnormal connection status. When standard event data contains network connection events where both the source asset and the destination asset belong to the target network, and the destination asset is located in a network connection event that is not in the same business link, the corresponding security status unit will be marked as a lateral access status. When the standard event data contains a permission change event in which the level after the permission change is higher than the level before the permission change, the corresponding security status unit will be marked as having a permission change status. When standard event data contains access actions to sensitive resources or high-value assets, the corresponding security status unit will be marked as sensitive resource access status. Sensitive resources are resources whose resource type matches the preset sensitive resource directory, and high-value assets are assets whose asset level reaches the preset asset level threshold. When standard event data contains data transmission events from the asset containing the sensitive resource to an external network address, the corresponding security state unit is marked as an external transmission state.
[0010] Preferably, in step S3, generating cross-layer evidence edges includes: Obtain the security status unit corresponding to the network-side event to be matched and the security status unit corresponding to the terminal-side event, respectively. The system performs a step-by-step assessment of the following criteria: consistent account identifier, consistent asset identifier, consistent session identifier, consistent network connection port and process port, time difference between process start time and network connection time within a preset time threshold, and resource access time later than remote access time. When the number of anchoring conditions satisfied is greater than or equal to two, a cross-layer evidence edge is generated between the corresponding two security state units. When the number of anchoring conditions is one, a candidate evidence edge is generated between the two corresponding security state units. The candidate evidence edge is not used as a cross-layer evidence edge in the construction of the reachability evidence graph in step S4.
[0011] Preferably, in step S4, constructing the reachability evidence graph includes: Treat the safe state unit as a node in the reachability evidence graph; Cross-layer evidence edges are used as node connection edges in the reachable evidence graph; Generate an identity transfer edge between two security state units that have the same account identifier and whose event times are consecutive; Generate process-derived edges between two security state units that have a parent process identifier and a process identifier correspondence; Generate permission change edges between security state units with different levels before and after the permission change; A resource reach edge is generated between two security state units that have the same account ID or the same process ID, and the latter security state unit contains a sensitive resource access action. An external transmission edge is generated between two security state units that enter the external transmission state after the sensitive resource access state; A reachable evidence graph is formed based on cross-layer evidence edges, identity transfer edges, process derivation edges, permission change edges, resource access edges, and external transmission edges.
[0012] Preferably, in step S4, extracting the minimum reachable evidence chain from the reachable evidence graph includes: Security state units with status types of remote access or abnormal connection are identified as candidate starting points; The state type of sensitive resource access state, external transmission state, or security state unit corresponding to high-value assets is identified as the candidate endpoint; Search for candidate evidence chains between candidate start points and candidate end points that contain permission change states or lateral access states. The evidence chain with the fewest nodes is selected from the candidate evidence chains; When there are two or more evidence chains with the same number of nodes, the evidence chain with the most cross-layer evidence edges is selected as the minimum reachable evidence chain.
[0013] Preferably, in step S5, the blocking benefit value is calculated for each cross-layer evidence edge, including: Obtain the cross-layer verification count, attack stage level, sensitive resource association marker, and permission change association marker for the corresponding cross-layer evidence edge; The cross-layer verification quantity, attack stage level, sensitive resource association marker, and permission change association marker are multiplied by their respective preset benefit weights and then summed to obtain the blocking benefit value of the cross-layer evidence edge. The attack stage levels are set in ascending order of remote access status, lateral access status, permission change status, sensitive resource access status, and external transmission status. The sensitive resource association flag is set to 1 when the security state unit connected to the corresponding cross-layer evidence edge contains the sensitive resource reach state, and otherwise is set to 0. The permission change association flag is set to 1 when the security state unit connected to the corresponding cross-layer evidence edge contains a permission change state, and otherwise it is set to 0.
[0014] Preferably, in step S5, the business loss value is calculated for each cross-layer evidence edge, including: Obtain the number of business links associated with the corresponding cross-layer evidence edge, the markers of key business links, the number of abnormal business heartbeats, and the level of dependent assets; The business loss value of the cross-layer evidence edge is obtained by multiplying the number of business links, the key business link markers, the number of abnormal business heartbeats, and the dependent asset level by their respective preset loss weights and then summing them. The key business link marker takes a value of 1 when the business link associated with the corresponding cross-layer evidence edge belongs to the preset key business link directory, and otherwise takes a value of 0. If there are two or more cross-layer evidence edges whose blocking benefit values all reach the preset blocking threshold and whose business loss values are the same, the cross-layer evidence edge located on the side closer to the candidate starting point in the minimum reachable evidence chain is selected as the disposal breakpoint.
[0015] Preferably, in steps S6 to S8, the shadow handling strategy includes a session isolation strategy, a temporary account privilege reduction strategy, a process external connection restriction strategy, a network connection port access restriction strategy, or a sensitive resource access secondary verification strategy. When the set of reachable business links after loading the shadow handling policy is reduced compared to the set of reachable business links before loading the shadow handling policy, and the reduced business links are critical business links, and the business heartbeat status of the critical business links is abnormal, the session isolation policy will be adjusted to the account temporary demotion policy, or the network connection port access restriction policy will be adjusted to the sensitive resource access secondary verification policy. After implementing the actual handling strategy, the verification data of the upstream and downstream safety status units of the handling breakpoint are collected again; When the verification data indicates that there is no cross-layer evidence edge between the upstream security status unit and the downstream security status unit of the handling breakpoint, and the heartbeat status in the business heartbeat data is normal, it is determined that the minimum reachable evidence chain is blocked. When the verification data indicates that there is still a cross-layer evidence edge between the upstream and downstream security state units of the disposal breakpoint, it is determined that the minimum reachable evidence chain has not been blocked.
[0016] In summary, the present invention has the following main beneficial effects: This application unifies network traffic data, terminal process data, account authentication data, permission change data, resource access data, asset topology data, and business heartbeat data into standard event data. Furthermore, it groups these data into security state units based on asset identifiers, account identifiers, process identifiers, session identifiers, resource identifiers, and time window identifiers. This achieves the effect of unifying security information scattered across the network, terminal, account, and resource sides into a single traceable object. Compared to risk assessment based solely on a single log, IP address, or alarm, this application reflects the actual relationships between accounts, processes, sessions, and resources within the same time window. This reduces misjudgments caused by account sharing, address reuse, concurrent access by multiple processes, or fragmented log sources, providing a clearer data foundation for subsequent risk identification.
[0017] By matching the security state units corresponding to network-side events with those corresponding to terminal-side events according to anchoring conditions such as consistent account identifier, consistent asset identifier, consistent session identifier, consistent port, time difference meeting a threshold, and resource access time sequence, and generating cross-layer evidence edges when at least two anchoring conditions are met, a reachability evidence graph is constructed based on cross-layer evidence edges, identity transfer edges, process derivation edges, permission change edges, resource reach edges, and external transmission edges. This achieves the effect of extracting the minimum reachable evidence chain with cross-verification relationships from multi-source events. Therefore, the risk path is no longer a simple stacking of loose alarms, but a continuous evidence chain jointly defined by remote access status or abnormal connection status, permission change status or lateral access status, and sensitive resource reach status or external transmission status. This improves the accuracy of identifying complex security risks such as lateral access, privilege escalation, sensitive resource reach, and abnormal external connections.
[0018] By calculating the blocking benefit value and business loss value for each cross-layer evidence edge in the minimum reachable evidence chain, the cross-layer evidence edge with the blocking benefit value reaching a preset blocking threshold and the minimum business loss value is selected as the disposal breakpoint. A shadow disposal strategy is generated before the actual disposal strategy is issued. Combined with the business dependency graph, the set of reachable business links and the set of differential links before and after the strategy are loaded are calculated. This achieves the effect of pre-verifying the impact of disposal actions on critical business links before cutting off risk paths. Furthermore, by re-collecting verification data from the security status units on both sides of the disposal breakpoint after disposal and determining whether the same minimum reachable evidence chain is still connected, the effect of same-chain retesting and confirmation of the disposal effect is achieved. This avoids unnecessary business interruptions caused by directly isolating assets, blocking ports, or restricting accounts, making the security management process both targeted in risk blocking and continuous in business operation. Attached Figure Description
[0019] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] Example 1 refer to Figure 1 A computer network information security management method based on data processing includes the following steps: S1: Collect network traffic data, terminal process data, account authentication data, permission change data, resource access data, asset topology data, and service heartbeat data from the target network, and parse the collected data to generate standard event data. The standard event data includes asset identifier, account identifier, process identifier, session identifier, resource identifier, event time, event type, and data source identifier. S2: Merge standard event data according to asset identifier, account identifier, process identifier, session identifier, resource identifier and time window identifier to generate security status units. Security status units include security status units corresponding to network-side events and security status units corresponding to terminal-side events. S3: Match the security state unit corresponding to the network-side event with the security state unit corresponding to the terminal-side event. When both meet at least two anchoring conditions, generate a cross-layer evidence edge. The anchoring conditions include: consistent account identifier, consistent asset identifier, consistent session identifier, consistent network connection port and process port, the time difference between process start time and network connection time is within a preset time threshold, and resource access time is later than remote access time. S4: Construct a reachability evidence graph based on security state units and cross-layer evidence edges, and extract the minimum reachability evidence chain from the reachability evidence graph that points from the entry asset to sensitive resources or high-value assets. The minimum reachability evidence chain includes remote access status or abnormal connection status, permission change status or lateral access status, and sensitive resource reach status or external transmission status. S5: Calculate the blocking benefit value and business loss value for each cross-layer evidence edge in the minimum reachable evidence chain, and select the cross-layer evidence edge whose blocking benefit value reaches the preset blocking threshold and whose business loss value is the smallest as the disposal breakpoint. S6: Generate a shadow disposal strategy based on the disposal breakpoint, and generate a business dependency graph based on asset topology data and business heartbeat data. Calculate the set of reachable business links before loading the shadow disposal strategy and the set of reachable business links after loading the shadow disposal strategy based on the business dependency graph. Generate a differential link set based on the difference between the two sets of reachable business links. S7: When the differential link set does not contain a critical business link, or when the differential link set contains a critical business link and the business heartbeat of that critical business link remains normal, the shadow handling strategy will be converted into an actual handling strategy and issued for execution. S8: After executing the actual disposal strategy, re-collect the verification data of the security status units on both sides of the disposal breakpoint, and determine whether the minimum reachable evidence chain is blocked based on the verification data; if the minimum reachable evidence chain is blocked, reduce the sampling frequency of the security status units that are not related to the minimum reachable evidence chain; if the minimum reachable evidence chain is not blocked, return to step S5 to reselect the disposal breakpoint.
[0022] This application applies to security monitoring and mitigation scenarios in target networks such as enterprise office networks, data center networks, government business networks, and industrial production management networks. Traffic acquisition devices, endpoint behavior acquisition agents, account authentication systems, access control systems, resource access auditing systems, asset management systems, business monitoring systems, and security policy enforcement devices can be deployed in the target network.
[0023] Among them, traffic collection devices are used to collect network traffic data; terminal behavior collection agents are used to collect terminal process data; account authentication systems are used to collect account authentication data; permission management systems are used to collect permission change data; resource access auditing systems are used to collect resource access data; asset management systems are used to provide asset topology data; business monitoring systems are used to provide business heartbeat data; and security policy execution devices are used to execute actual handling strategies such as session isolation, temporary account demotion, process external connection restrictions, network connection port access restrictions, or secondary verification of sensitive resource access.
[0024] This embodiment does not generate risk levels solely based on a single log alert, nor does it generate attack chains solely based on attack tags. Instead, it first unifies data from different sources into standard event data, and then binds assets, accounts, processes, sessions, resources, and time windows into security state units. Subsequently, it generates cross-layer evidence edges through multiple anchoring conditions between network-side events and terminal-side events, and constructs a reachability evidence graph based on these cross-layer evidence edges. Then, it extracts the minimum reachability evidence chain pointing to sensitive resources or high-value assets from the reachability evidence graph. After that, it determines the handling breakpoint in the minimum reachability evidence chain, and generates a shadow handling strategy before actually issuing the security handling strategy. The shadow handling strategy is differentially verified through a business dependency graph. After successful verification, the actual handling strategy is executed. Finally, the same minimum reachability evidence chain is retested and confirmed.
[0025] Establishing basic configuration data: Before executing the method of this embodiment, an asset topology table, a sensitive resource directory, a critical business link directory, a whitelist communication relationship table, and a policy parameter table are pre-established in the target network.
[0026] The asset topology table records the asset identifier, asset type, network segment, connection relationship, asset level, and associated business system in the target network. The asset identifier uniquely identifies a terminal, server, gateway, database server, file server, business server, or security device within the target network. The asset level is pre-configured based on the asset's role in the business system, the importance of the stored data, and business continuity requirements. For example, assets hosting core databases, identity authentication services, core file storage services, or production control services can be configured with a higher asset level.
[0027] The sensitive resource directory records resource identifiers, resource types, associated assets, resource paths, the business scope to which the resource belongs, and their sensitivity levels. Resources can be database tables, file directories, business interfaces, configuration files, key files, user information datasets, production parameter datasets, or business report datasets. Sensitive resources are those whose resource types match the sensitive resource directory.
[0028] The critical business link directory records the business identifier, business link identifier, starting asset, dependent assets, access port, protocol type, heartbeat detection method, and business level. A critical business link refers to a business communication path marked as critical in the critical business link directory.
[0029] The whitelist communication relationship table records the communication relationships between permitted source assets, destination assets, ports, protocols, accounts, processes, and service identifiers within the target network. When a network connection event matches the whitelist communication relationship table, it indicates that the connection belongs to a known service communication relationship.
[0030] The strategy parameter table is used to record preset time thresholds, preset blocking thresholds, preset asset level thresholds, preset profit weights, preset loss weights, heartbeat detection cycle, consecutive heartbeat loss thresholds, response timeout thresholds, minimum sampling frequency, and sampling frequency adjustment rules.
[0031] The above parameters are not arbitrarily set, but are configured based on the target network's asset class classification, service class classification, log collection latency, device clock synchronization error, historical security event records, historical handling records, and business continuity requirements. For newly deployed networks, in the absence of historical samples, the above parameters can be pre-configured by security administrators based on asset topology, service class, sensitive resource catalog, and security policy level; after the target network has been running for a period of time and accumulated security event and handling records, some parameters can be updated based on confirmed security event samples and handling results.
[0032] The source and determination method of preset parameters: The preset time threshold is used to determine whether the process startup time and network connection time belong to the same behavioral process. The preset time threshold is determined based on the historical synchronization of terminal agent logs, traffic collection logs, and authentication logs in the target network. Specifically, it takes into account log collection latency, clock synchronization errors between network devices and terminal devices, and the time difference distribution between process startup time and network connection time in confirmed normal connection samples.
[0033] The preset time threshold can be determined using the following formula: in, Indicates a preset time interval; Indicates the process start time; Indicates network connection time; This represents the absolute time difference between process startup time and network connection time. This represents the quantile statistics of the absolute value of the difference between process start time and network connection time in historically confirmed connection samples. This indicates the upper limit of clock synchronization error between the terminal device and the network device. The specific quantile points of the quantile statistics are configured by the policy parameter table and can be determined based on the log granularity and clock synchronization accuracy of the target network.
[0034] A preset blocking threshold is used to filter out cross-layer evidence edges with low disposal value. The preset blocking threshold is determined based on historically confirmed security events, manually reviewed attack chain samples, or security management policy levels. For target networks without historical samples, the preset blocking threshold is configured by security managers in the policy parameter table based on the sensitive resource catalog, high-value asset level, and disposal policy level. As the target network accumulates disposal records, the preset blocking threshold can be updated based on the blocking benefit value corresponding to the confirmed and effectively blocked cross-layer evidence edges.
[0035] The preset benefit weights are configured based on the target network's security priorities regarding attack phases, access to sensitive resources, and permission changes. The preset loss weights are configured based on the target network's business continuity requirements regarding critical business links, business heartbeat status, and dependent asset levels. Both preset benefit and loss weights are non-negative. These weights are stored in the policy parameter table and associated with the corresponding version number or effective date for subsequent auditing and review.
[0036] Before calculating the blocking gains and service losses, the number of cross-layer verifications, attack phase levels, number of service links, number of abnormal service heartbeats, and dependent asset levels are mapped or normalized to ensure that all indicators are mapped to the same comparison scale. The level mapping or normalization rules are stored in the policy parameter table and are determined by the target network's asset level classification, service level classification, and security policy level.
[0037] Generation of standard event data: After collecting network traffic data, terminal process data, account authentication data, permission change data, resource access data, asset topology data, and business heartbeat data from the target network, the collected data is parsed to generate standard event data.
[0038] Network traffic data can be obtained from switch mirror ports, traffic probes, gateway devices, firewall logs, or proxy gateway logs. When parsing network traffic data, the source address, destination address, source port, destination port, protocol type, session identifier, connection start time, connection end time, and data transmission direction are extracted. Then, based on the asset topology table, the source address and destination address are mapped to source asset identifiers and destination asset identifiers, respectively. The destination port or source port is designated as the network connection port, and the connection start time is designated as the connection time.
[0039] Terminal process data can be obtained by a behavior acquisition agent deployed on a terminal or server. When parsing terminal process data, the following are extracted: asset identifier, process identifier, parent process identifier, process name, process port, process start time, process end time, and process initiating account. The process identifier is used to distinguish different processes running in parallel within the same asset, and the parent process identifier is used to determine the process hierarchy.
[0040] Account authentication data can be obtained from identity authentication systems, single sign-on systems, bastion hosts, domain controllers, VPN systems, or business system login audit records. When parsing account authentication data, the following are extracted: account identifier, authentication asset identifier, authentication result, login time, logout time, authentication method, and source asset identifier. Authentication results include successful and failed authentication.
[0041] Permission change data can be obtained from account permission management systems, operating system permission audit logs, database permission audit logs, or business system authorization records. When parsing permission change data, the following are extracted: account identifier, permission change type, permission level before change, permission level after change, change time, and the asset identifier that performed the change. Permission change types include role elevation, granting administrator privileges, expanding access permissions, and temporary authorization.
[0042] Resource access data can be obtained from database auditing systems, file access auditing systems, business interface auditing systems, or application logs. When parsing resource access data, the following are extracted: account identifier, process identifier, resource identifier, resource type, access action, access time, and associated asset identifier. Access actions include reading, writing, exporting, deleting, and retrieving.
[0043] Asset topology data can be obtained from asset management systems, configuration management databases, network topology scan results, or manual configuration tables. When parsing asset topology data, the asset identifier, asset type, network segment, connectivity, asset level, and associated business system are extracted.
[0044] Business heartbeat data can be obtained from business monitoring systems, probe services, or health check interfaces. When parsing business heartbeat data, the business identifier, business link identifier, heartbeat time, heartbeat status, and dependent asset identifier are extracted. Heartbeat status includes normal and abnormal. Heartbeat abnormalities can be determined by consecutive lost heartbeats, response timeouts, or abnormal return statuses.
[0045] The generated standard event data includes at least the following: asset identifier, account identifier, process identifier, session identifier, resource identifier, event time, event type, and data source identifier. The event type includes network connection events, remote login events, process startup events, permission change events, resource access events, data transmission events, and service heartbeat events. The data source identifier records that the standard event data originates from network traffic data, terminal process data, account authentication data, permission change data, resource access data, asset topology data, or service heartbeat data.
[0046] In cases where certain data sources lack certain fields, this embodiment does not discard the data entry but instead generates standard event data based on the parsable fields. If the network traffic data lacks an account identifier or process identifier, the account identifier or process identifier is recorded as a null value and associated with other events through asset identifier, session identifier, port, and time window during subsequent merging and matching processes. If a normal network connection event lacks a resource identifier, the resource identifier is recorded as an unassociated resource identifier.
[0047] Generation of safe state units: After generating standard event data, the standard event data is merged according to asset identifier, account identifier, process identifier, session identifier, resource identifier, and time window identifier to generate security status units.
[0048] The time window identifier is determined by the time window into which the event falls. The length of the time window is determined by the sampling granularity parameter in the strategy parameter table. Shorter time windows can be used for high-value assets or assets already on the minimum reachable chain of evidence; a basic time window can be used for ordinary assets. Different time windows are arranged in chronological order.
[0049] When the fields are complete, standard event data with the same asset identifier, account identifier, process identifier, session identifier, resource identifier, and time window identifier will be merged into the same security state unit.
[0050] When a process identifier is missing within the same time window, it is merged according to asset identifier, account identifier, session identifier, and resource identifier. When a session identifier is missing within the same time window, it is merged according to asset identifier, account identifier, process identifier, and resource identifier. When a resource identifier is missing within the same time window, it is merged according to asset identifier, account identifier, process identifier, and session identifier, and the resource identifier is recorded as an unassociated resource identifier.
[0051] Each security state unit includes at least an asset identifier, account identifier, process identifier, session identifier, resource identifier, time window identifier, state type, event list, and data source set. The event list records standard event data merged into this security state unit, and the data source set records which data sources jointly support this security state unit.
[0052] In this way, the security status unit no longer analyzes only IP addresses, log entries, or alarms, but binds assets, accounts, processes, sessions, and resources within the same time window into a single traceable object. This allows for handling situations such as multiple accounts logging in concurrently on the same asset, the same account accessing multiple assets, multiple processes on the same asset initiating network connections simultaneously, and the same session accessing different resources.
[0053] Determining the state type of a safety state unit: After generating a safety state unit, determine the corresponding state type based on the event list in the safety state unit.
[0054] When the event list in a security state cell contains a successfully authenticated remote login event, the security state cell is marked as having a remote access status. Remote login events can originate from bastion host logins, remote desktop logins, SSH logins, VPN access, or remote login records from business systems.
[0055] When the event list in a security status unit indicates that there is no preset service connection relationship between the source asset and the destination asset, and the network connection event does not match the preset whitelist communication relationship, the security status unit is marked as an abnormal connection state. The preset service connection relationship is determined by the asset topology table and the critical service link directory, and the preset whitelist communication relationship is determined by the whitelist communication relationship table.
[0056] When the event list in a security state unit contains network connection events where both the source asset and the destination asset belong to assets within the target network, and the destination asset is located on a different service link, the security state unit is marked as a lateral access state. Assets within the target network are determined by their network segment and asset identifier in the asset topology table. "Different service links" means that the source asset and the destination asset are not registered under the same service link identifier, or that there is no dependency relationship between them recorded in the critical service link directory.
[0057] When the event list in a security status unit contains a permission change event where the level after the permission change is higher than the level before the permission change, the security status unit is marked as having changed permissions. Permission levels are determined by the permission management system or a preset permission level table in the policy parameter table.
[0058] When the event list in a security status cell contains access actions to sensitive resources or high-value assets, the security status cell is marked as having reached a sensitive resource. Sensitive resources are resources whose resource type matches the sensitive resource catalog, and high-value assets are assets whose asset level reaches a preset asset level threshold.
[0059] When the event list in a security state cell contains data transmission events pointing from the asset containing the sensitive resource to an external network address, the security state cell is marked as an outbound transmission state. An external network address is a network address that does not belong to the internal network segment of the target network in the asset topology table. Data transmission events can be obtained by parsing network traffic data, or by parsing gateway logs, proxy logs, or firewall logs.
[0060] A single security state unit can have one or more state types. When a security state unit simultaneously satisfies multiple state determination rules, all state types are recorded together in the state type field of that security state unit. Subsequent construction of the reachability evidence graph and extraction of the minimum reachability evidence chain are then performed based on the actual state types contained within that security state unit.
[0061] Generation of cross-layer evidence edges: Security state units are divided into security state units corresponding to network-side events and security state units corresponding to terminal-side events. Security state units corresponding to network-side events are mainly generated from network traffic data, security device logs, and session connection data. Security state units corresponding to terminal-side events are mainly generated from terminal process data, account authentication data, permission change data, and resource access data.
[0062] Match the security state unit corresponding to the network-side event with the security state unit corresponding to the terminal-side event. For any network-side security state unit and a terminal-side security state unit, determine whether they satisfy the following anchoring conditions: Account identifiers are consistent; Consistent asset identification; The session identifiers are consistent; The network connection port is the same as the process port; The time difference between process startup time and network connection time is within a preset time threshold; Resource access time is later than remote access time.
[0063] When determining whether the process startup time and network connection time meet the time difference condition, the absolute time difference between the process startup time and the network connection time is used for judgment. When the absolute time difference is less than or equal to a preset time threshold, the anchoring condition is considered to be valid; when the absolute time difference is greater than the preset time threshold, the anchoring condition is considered to be invalid.
[0064] When a process startup time or network connection time is missing in a certain security state unit, the time difference anchoring condition is not used to participate in the generation of cross-layer evidence edges, but other anchoring conditions such as account identifier consistency, asset identifier consistency, session identifier consistency, network connection port and process port consistency, and resource access time being later than remote access time are still judged.
[0065] For ease of implementation, the number of cross-level verifications can be calculated as follows: ; in, Indicates the first The network-side security state unit and the first The number of anchoring conditions satisfied between each terminal-side security state unit; Indicates the first The result of the judgment of the anchoring condition, when the first anchoring condition is... The network-side security state unit and the first The terminal-side security state unit satisfies the first... When anchoring conditions are met, The value is 1 if it is set to 1, otherwise the value is 0. This indicates the sequence number of the anchoring condition, and its value range corresponds to the six anchoring conditions mentioned above.
[0066] when When the value is greater than or equal to 2, a cross-layer evidence edge is generated between the corresponding network-side security state unit and the terminal-side security state unit. When the value equals 1, a candidate evidence edge is generated between the corresponding two security state units. This candidate evidence edge is only used for subsequent manual verification or supplementary sampling and is not used as a cross-layer evidence edge for constructing the reachability evidence graph. When the value is 0, no evidence edge is generated.
[0067] The multi-anchoring matching mechanism described above avoids incorrectly associating unrelated events based solely on the same IP address, the same time window, or a single alarm. Cross-layer evidence edges must be corroborated by both network-side and terminal-side events, thus differing from processing methods that associate events based solely on log time sequence, attack tags, or session identifiers.
[0068] Construction of reachability evidence graph: After generating cross-layer evidence edges, a reachable evidence graph is constructed based on the security state units and the cross-layer evidence edges. The nodes in the reachable evidence graph are security state units, and the connection edges between nodes include cross-layer evidence edges, identity transfer edges, process derivation edges, permission change edges, resource access edges, and external transmission edges.
[0069] Cross-layer evidence edges are used as node connection edges connecting the network-side security state unit and the terminal-side security state unit.
[0070] An identity transfer edge is generated between two security state units with the same account identifier and consecutive event times. Consecutive event times means that the event time of the later security state unit is later than the event time of the earlier security state unit, and the time interval between them is within the identity transfer time range configured in the policy parameter table.
[0071] A process-derived edge is generated between two security state units that have a parent process identifier and a process identifier correspondence. For example, if the process identifier recorded in the previous security state unit is the same as the parent process identifier recorded in the next security state unit, then a process-derived edge is generated between them.
[0072] An edge representing a change in permissions is generated between security state units whose levels differ before and after the permission change. If the level after the permission change is higher than the level before the permission change, this edge representing a change in permissions is included in the subsequent extraction of the minimum reachable chain of evidence and the calculation of the blocking benefit value.
[0073] A resource reach edge is generated between two security state units that have the same account identifier or the same process identifier, and the latter security state unit contains a sensitive resource access action.
[0074] An outbound transmission edge is generated between two security state units that experience an outbound transmission state after the sensitive resource reaches the sensitive resource state. Specifically, an outbound transmission edge is generated when the latter security state unit contains a data transmission event from the asset containing the sensitive resource to an external network address, and the event time of the latter security state unit is later than the event time of the former security state unit that contains the sensitive resource reaches the sensitive resource state.
[0075] Using the edge types described above, the reachability evidence graph not only represents the temporal relationships of events, but also the connections between account transfers, process derivations, permission changes, resource access, and external transmissions. This graph structure is used to extract the minimum reachability evidence chain, rather than just to display the alarm topology.
[0076] Extraction of the minimum reachable chain of evidence: After constructing the reachability evidence graph, extract the minimum reachability evidence chain from the reachability evidence graph, pointing from the entry asset to the sensitive resource or high-value asset.
[0077] First, security state units with a status type of remote access or abnormal connection are identified as candidate starting points. Candidate starting points are used to represent access points that are externally accessed, have abnormal network connections, or do not conform to business connection relationships.
[0078] Secondly, candidate endpoints are identified as those with status types of sensitive resource access, external transmission, or security status corresponding to high-value assets. Candidate endpoints are used to indicate that risky behavior has reached sensitive resources, high-value assets, or that external transmission has occurred.
[0079] Then, candidate evidence chains are searched between the candidate starting point and the candidate ending point. Candidate evidence chains must meet the following conditions: there are cross-layer evidence edges, identity transfer edges, process derivation edges, permission change edges, resource access edges, or external transmission edges between adjacent security state units in the candidate evidence chain; the candidate evidence chain contains permission change states or lateral access states; and the event time sequence of the candidate evidence chain conforms to the chronological order from the candidate starting point to the candidate ending point.
[0080] After obtaining candidate evidence chains, the evidence chain with the fewest nodes is first selected. When there are two or more evidence chains with the same number of nodes, the evidence chain with the most cross-layer evidence edges is selected as the minimum reachable evidence chain.
[0081] For ease of implementation, the set of candidate evidence chains can be denoted as... For any candidate chain of evidence The number of its nodes is denoted as The number of cross-layer evidence edges is denoted as This embodiment follows the first sorting key. Ascending order, second sort key Determining the minimum reachable chain of evidence using descending order .in, This represents the minimum reachable chain of evidence ultimately selected.
[0082] The aforementioned minimum reachable evidence chain is neither an arbitrary attack path nor a simple log concatenation, but rather an evidence chain that satisfies the following conditions: entry point status, intermediate permission changes or lateral access status, and endpoint sensitive resource access or external transmission status. This evidence chain can characterize a risk path that can be verified and mitigated.
[0083] Calculation of blocking payoff value: After extracting the minimum reachable chain of evidence, the blocking payoff value is calculated for each cross-layer evidence edge in the chain. The blocking payoff value is used to measure the effectiveness of blocking a certain cross-layer evidence edge in breaking the minimum reachable chain of evidence.
[0084] For any cross-layer evidence edge in the minimum reachable evidence chain Its blocking benefit value Calculate using the following formula: ; in, Indicates cross-layer evidence edge The blocking benefit value; Indicates cross-layer evidence edge The corresponding number of cross-layer verifications, which is the number of anchoring conditions satisfied when generating the cross-layer evidence edge; Indicates cross-layer evidence edge Attack phase level; Indicates a sensitive resource association tag; Indicates a flag associated with permission changes; , , , These represent the preset benefit weights corresponding to the number of cross-layer verifications, attack stage level, sensitive resource association markers, and permission change association markers, respectively.
[0085] The attack stage levels are set in ascending order: remote access, lateral access, permission change, sensitive resource access, and external transmission. In other words, the closer a cross-layer evidence edge is to the sensitive resource access or external transmission stage, the higher its attack stage level.
[0086] Sensitive resource association tags The value is 1 when the security state unit of the corresponding cross-layer evidence edge connection contains the sensitive resource access status; otherwise, the value is 0. Permission change association flag. The value is 1 when the security state unit connected to the corresponding cross-layer evidence edge contains the permission change state, and 0 otherwise.
[0087] The preset revenue weights are configured by the strategy parameter table. Different target networks can set weights according to their own management requirements, but the weights are all used to express the contribution of the above four types of factors to the blocking revenue value, without changing the calculation logic of this embodiment.
[0088] Calculate the service loss value for each cross-layer evidence edge in the minimum reachable evidence chain. The service loss value is used to measure the impact of blocking a certain cross-layer evidence edge on the normal service chain.
[0089] For any cross-layer evidence edge Its business loss value Calculate using the following formula: ; in, Indicates cross-layer evidence edge The business loss value; Indicates cross-layer evidence edge The number of associated business links; Indicates the identification of key business links; This indicates the number of abnormal business heartbeats; Indicates dependence on asset level; , , , These represent the number of business links, the markers of critical business links, the number of abnormal business heartbeats, and the preset loss weights corresponding to the levels of dependent assets, respectively.
[0090] Number of business links From the business dependency graph and cross-layer evidence edges The number of associated business links has been determined. Key business links have been identified. At the edge of cross-layer evidence The value is 1 if the associated business link belongs to the preset critical business link directory, and 0 otherwise. Number of abnormal business heartbeats. From cross-layer evidence edge The number of business links in the associated business chain that are in a heartbeat abnormal state has been determined. Dependency asset level. From cross-layer evidence edge The asset level of the assets involved is determined in the asset topology table.
[0091] The preset loss weights are configured by the strategy parameter table and are used to express the impact of the number of business links, critical business links, heartbeat status, and dependent asset level on the business loss value.
[0092] After calculating the blocking benefit value and business loss value, select the disposal breakpoint from each cross-layer evidence edge in the minimum reachable evidence chain.
[0093] First, cross-layer evidence edges whose blocking benefit reaches a preset blocking threshold are selected. The preset blocking threshold is configured by the strategy parameter table and is used to exclude cross-layer evidence edges with low blocking benefit and insufficient disposal value.
[0094] Secondly, among the cross-layer evidence edges whose blocking benefit value reaches the preset blocking threshold, the cross-layer evidence edge with the smallest business loss value is selected as the disposal breakpoint.
[0095] When two or more cross-layer evidence edges have blocking benefits that all reach a preset blocking threshold and have the same business loss value, the cross-layer evidence edge located closer to the candidate starting point in the least reachable evidence chain is selected as the disposal breakpoint. This can block the risk path at an earlier stage of risk propagation, while avoiding directly blocking key business links close to sensitive resources or high-value assets.
[0096] In this embodiment, the breakpoint is not determined directly based on a single risk score, but rather by comprehensively considering the blocking benefit value and business loss value within the same minimum reachable evidence chain. This avoids the business impact caused by isolating the entire asset, blocking the entire port, or imposing uniform restrictions on all users.
[0097] After identifying the action breakpoint, a shadow action policy is generated based on the breakpoint. The shadow action policy is a policy used to verify the scope of action's impact before it is actually deployed to security devices, endpoint agents, or access control systems.
[0098] Shadow handling strategies include session isolation strategies, temporary account privilege reduction strategies, process external connection restriction strategies, network connection port access restriction strategies, and sensitive resource access secondary verification strategies.
[0099] When the breakpoint corresponds to an abnormal session connection, generate a session isolation policy. When the breakpoint corresponds to an account permission change or abnormal account transfer, generate a temporary account privilege reduction policy. When the breakpoint corresponds to an abnormal process initiating an outbound connection, generate a process outbound connection restriction policy. When the breakpoint corresponds to access to a non-whitelisted port, generate a network connection port access restriction policy. When the breakpoint corresponds to a sensitive resource access status, generate a sensitive resource access secondary verification policy.
[0100] A shadow handling policy should include at least the policy type, affected asset, affected account, affected process, affected session, affected port, affected resources, policy activation conditions, and policy duration. The policy duration is configured by the policy parameter table to avoid permanent blocking that could cause continuous business disruption.
[0101] A business dependency graph is generated based on asset topology data and business heartbeat data. Nodes in the business dependency graph represent business assets, and edges represent business links. Each business link records the business identifier, business link identifier, source asset, destination asset, port, protocol, dependency relationship, and heartbeat status.
[0102] After generating the shadow handling strategy, the set of reachable business links before loading the shadow handling strategy and the set of reachable business links after loading the shadow handling strategy are calculated based on the business dependency graph.
[0103] Let the set of reachable business links before loading the shadow handling strategy be denoted as . The set of reachable business links after loading the shadow handling strategy is denoted as Differential link set Determine using the following formula: ; in, Represents a set of differential links; This represents the set of reachable business links before the shadow handling strategy is loaded; This represents the set of reachable business links after the shadow handling strategy is loaded; This represents the set difference operation, i.e., belonging to But not belonging to The business chain.
[0104] The differential link set is a set of links obtained by calculating reachability before and after policy loading based on the business dependency graph. It is used to represent business links affected by shadow handling policies in the business dependency graph structure. Business heartbeat data comes from the business monitoring system and is used to reflect the actual operating status of the corresponding business links during the verification period.
[0105] When the differential link set does not contain critical business links, it means that the shadow handling strategy will not cut off the critical business links, and the shadow handling strategy can be transformed into the actual handling strategy. When the differential link set contains critical business links, but the business heartbeat of the critical business links remains normal, it means that although the critical business links are affected by the shadow handling strategy in the business dependency graph structure, the critical business can still continue to operate through backup links, redundant services, or existing connections. Therefore, it is permissible to transform the shadow handling strategy into the actual handling strategy.
[0106] When the differential link set includes a critical business link, and the business heartbeat status of that critical business link is abnormal, it indicates that the shadow handling policy may affect the continuous operation of the critical business. In this case, the original shadow handling policy is not executed directly, but the handling intensity is reduced. Specifically, the session isolation policy can be adjusted to a temporary account privilege reduction policy, or the network connection port access restriction policy can be adjusted to a sensitive resource access secondary verification policy. The adjusted shadow handling policy is then re-verified using differential links until the execution conditions are met or confirmed by security management personnel.
[0107] The policy verification in this embodiment does not merely verify whether there are conflicts between policy rules, but rather verifies whether the shadow handling policy generated for the current handling breakpoint will sever critical business links in the current business dependency graph. This verification process is directly related to the minimum reachable evidence chain and the handling breakpoint, thus avoiding the simplistic parallel processing of attack chain identification and policy verification.
[0108] Maintaining normal business heartbeats means that, during the shadow handling strategy verification period or the retest period after actual handling, the business heartbeat data corresponding to the critical business links does not experience consecutive heartbeat loss, response timeout, or abnormal return status. The heartbeat detection period, the threshold for consecutive heartbeat loss, and the response timeout threshold are configured by the critical business link directory or strategy parameter table.
[0109] Business heartbeat data can be generated from HTTP health checks, database connection checks, interface return code checks, application probe checks, or service port probes. For the same critical business link, if the business heartbeat data meets the health check conditions of the corresponding business system within the verification period, the business heartbeat status of the critical business link is determined to be normal; if the business heartbeat data shows continuous heartbeat loss, response timeout, or abnormal return status, the business heartbeat status of the critical business link is determined to be abnormal.
[0110] When a critical business link enters the differential link set but the business heartbeat remains normal, it indicates that the shadow handling strategy has changed the reachability of the business link in the business dependency graph, but has not caused the actual operation of the critical business link to be abnormal during the verification period. When a critical business link enters the differential link set and the business heartbeat status is abnormal, it indicates that the shadow handling strategy may affect the operation of the critical business, and it is necessary to reduce the handling intensity or reselect the handling breakpoint.
[0111] Once the shadow disposal strategy meets the execution conditions, it will be transformed into an actual disposal strategy and issued for execution.
[0112] Actual handling strategies can be distributed to firewalls, gateways, endpoint behavior control agents, account permission management systems, resource access control systems, or business system access control modules.
[0113] For session isolation policies, the execution targets are the session identifier and asset identifier corresponding to the breakpoint, and the action is to block the session or add the session to the isolation queue. For temporary account privilege reduction policies, the execution target is the account identifier corresponding to the breakpoint, and the action is to restore the account's privileges to the level before the privilege change or reduce them to the temporary privilege level specified in the policy parameter table. For process outbound connection restriction policies, the execution target is the process identifier corresponding to the breakpoint, and the action is to restrict the process from initiating connections to external network addresses. For network connection port access restriction policies, the execution targets are the port and asset corresponding to the breakpoint, and the action is to restrict access to the port by non-whitelisted communication relationships. For sensitive resource access secondary verification policies, the execution targets are the resource identifier, account identifier, or process identifier corresponding to the breakpoint, and the action is to trigger secondary authentication, approval, or temporary access token verification before accessing sensitive resources.
[0114] After executing the actual handling strategy, record the strategy execution time, the target, the execution result, and the strategy rollback conditions. If the execution fails, write the reason for the failure into the handling record and return to the handling breakpoint selection step to reselect the handling breakpoint.
[0115] After implementing the actual disposal strategy, verification data for the safety state units on both sides of the disposal breakpoint are re-collected. The safety state units on both sides of the disposal breakpoint include the upstream safety state unit and the downstream safety state unit. The upstream safety state unit refers to the safety state unit in the minimum reachable evidence chain located before the disposal breakpoint, and the downstream safety state unit refers to the safety state unit in the minimum reachable evidence chain located after the disposal breakpoint.
[0116] Verification data includes post-processing network traffic data, terminal process data, account authentication data, permission change data, resource access data, and service heartbeat data. Security state units on both sides of the processing breakpoint are regenerated, and it is determined again whether at least two anchoring conditions are still met between them.
[0117] When the verification data shows that there is no cross-layer evidence edge between the upstream and downstream security status units of the handling breakpoint, and the heartbeat status in the business heartbeat data is normal, it is determined that the minimum reachable evidence chain is blocked.
[0118] When the verification data shows that there is still a cross-layer evidence edge between the upstream and downstream security state units of the disposal breakpoint, it is determined that the minimum reachable evidence chain has not been blocked, and the process returns to the disposal breakpoint selection step. The blocking benefit value and business loss value of each cross-layer evidence edge in the minimum reachable evidence chain are recalculated, and the disposal breakpoint is reselected.
[0119] The aforementioned retesting is not a complete network scan, nor is it merely a confirmation of whether alarms have disappeared. Instead, it verifies the handling breakpoints around the same minimum reachable chain of evidence. This confirms whether the handling actions have severed the originally identified risk path.
[0120] When the minimum reachable evidence chain is determined to be blocked, the sampling frequency of security state units unrelated to that minimum reachable evidence chain is reduced. Security state units unrelated to that minimum reachable evidence chain refer to security state units that are not located in that minimum reachable evidence chain and are not one-hop or two-hop adjacent nodes of nodes on that minimum reachable evidence chain.
[0121] When reducing the sampling frequency, it should not be lower than the minimum sampling frequency configured in the policy parameter table. The minimum sampling frequency is used to ensure that ordinary security state units in the target network can still be periodically collected and monitored.
[0122] For secure state units located in the minimum reachable evidence chain, secure state units on either side of the disposal breakpoint, and secure state units that are adjacent to the minimum reachable evidence chain by one or two hops, no reduction in sampling frequency is performed. These secure state units maintain their base sampling frequency or increase their sampling frequency until consecutive retest results indicate that the corresponding minimum reachable evidence chain has been blocked.
[0123] When the retest results show that the minimum reachable chain of evidence is not blocked, the sampling frequency of the chain of evidence and its adjacent nodes is not reduced, but the sampling frequency is maintained or increased, and the process returns to the breakpoint selection step.
[0124] The sampling frequency adjustment rules are configured by the strategy parameter table. The sampling frequency can be determined based on the security status unit's position in the evidence chain, asset level, business link level, and retest results.
[0125] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A computer network information security management method based on data processing, characterized in that, Includes the following steps: S1: Collect network traffic data, terminal process data, account authentication data, permission change data, resource access data, asset topology data, and service heartbeat data from the target network, and parse the collected data to generate standard event data. The standard event data includes asset identifier, account identifier, process identifier, session identifier, resource identifier, event time, event type, and data source identifier. S2: Merge standard event data according to asset identifier, account identifier, process identifier, session identifier, resource identifier and time window identifier to generate security status units. Security status units include security status units corresponding to network-side events and security status units corresponding to terminal-side events. S3: Match the security state unit corresponding to the network-side event with the security state unit corresponding to the terminal-side event. When both meet at least two anchoring conditions, generate a cross-layer evidence edge. The anchoring conditions include: consistent account identifier, consistent asset identifier, consistent session identifier, consistent network connection port and process port, the time difference between process start time and network connection time is within a preset time threshold, and resource access time is later than remote access time. S4: Construct a reachability evidence graph based on security state units and cross-layer evidence edges, and extract the minimum reachability evidence chain from the reachability evidence graph that points from the entry asset to sensitive resources or high-value assets. The minimum reachability evidence chain includes remote access status or abnormal connection status, permission change status or lateral access status, and sensitive resource reach status or external transmission status. S5: Calculate the blocking benefit value and business loss value for each cross-layer evidence edge in the minimum reachable evidence chain, and select the cross-layer evidence edge whose blocking benefit value reaches the preset blocking threshold and whose business loss value is the smallest as the disposal breakpoint. S6: Generate a shadow disposal strategy based on the disposal breakpoint, and generate a business dependency graph based on asset topology data and business heartbeat data. Calculate the set of reachable business links before loading the shadow disposal strategy and the set of reachable business links after loading the shadow disposal strategy based on the business dependency graph. Generate a differential link set based on the difference between the two sets of reachable business links. S7: When the differential link set does not contain a critical business link, or when the differential link set contains a critical business link and the business heartbeat of that critical business link remains normal, the shadow handling strategy will be converted into an actual handling strategy and issued for execution. S8: After executing the actual disposal strategy, re-collect the verification data of the security status units on both sides of the disposal breakpoint, and determine whether the minimum reachable evidence chain is blocked based on the verification data; if the minimum reachable evidence chain is blocked, reduce the sampling frequency of the security status units that are not related to the minimum reachable evidence chain; if the minimum reachable evidence chain is not blocked, return to step S5 to reselect the disposal breakpoint.
2. The computer network information security management method based on data processing according to claim 1, characterized in that, In step S1, the collected data is parsed to generate standard event data, including: The source asset identifier, destination asset identifier, network connection port, protocol type, session identifier, and connection time are obtained by parsing network traffic data. Parsing the terminal process data yields the asset identifier, process identifier, parent process identifier, process port, process start time, and process end time. The account authentication data is parsed to obtain the account identifier, authentication asset identifier, authentication result, login time, and logout time. Parsing the permission change data yields the account identifier, permission change type, permission level before change, permission level after change, and change time. The resource access data is parsed to obtain the account identifier, process identifier, resource identifier, resource type, access action, and access time; The asset topology data is parsed to obtain the asset identifier, asset type, network segment, connection relationship, and asset level; The heartbeat data is parsed to obtain the business identifier, business link identifier, heartbeat time, heartbeat status, and dependent asset identifier.
3. The computer network information security management method based on data processing according to claim 2, characterized in that, In step S2, a safe state unit is generated, including: Standard event data is merged according to the same asset identifier, the same account identifier, the same process identifier, the same session identifier, the same resource identifier, and the same time window identifier. When a process identifier is missing within the same time window, it is merged according to asset identifier, account identifier, session identifier, and resource identifier; When a session identifier is missing within the same time window, it is merged according to asset identifier, account identifier, process identifier, and resource identifier; When resource identifiers are missing within the same time window, they are merged according to asset identifiers, account identifiers, process identifiers, and session identifiers, and the resource identifiers are recorded as unassociated resource identifiers. The merged standard event data is then written into the corresponding security status unit, so that each security status unit has a corresponding asset identifier, account identifier, process identifier, session identifier, resource identifier, time window identifier, and status type.
4. The computer network information security management method based on data processing according to claim 3, characterized in that, In step S2, the state type of the security state unit is determined according to the following rules: When the standard event data contains a successfully authenticated remote login event, the corresponding security status unit will be marked as remote access status; When the standard event data contains information indicating that there is no preset business connection relationship between the source asset and the destination asset, and the network connection event does not match the preset whitelist communication relationship, the corresponding security status unit will be marked as an abnormal connection status. When standard event data contains network connection events where both the source asset and the destination asset belong to the target network, and the destination asset is located in a network connection event that is not in the same business link, the corresponding security status unit will be marked as a lateral access status. When the standard event data contains a permission change event in which the level after the permission change is higher than the level before the permission change, the corresponding security status unit will be marked as having a permission change status. When standard event data contains access actions to sensitive resources or high-value assets, the corresponding security status unit will be marked as sensitive resource access status. Sensitive resources are resources whose resource type matches the preset sensitive resource directory, and high-value assets are assets whose asset level reaches the preset asset level threshold. When standard event data contains data transmission events from the asset containing the sensitive resource to an external network address, the corresponding security state unit is marked as an external transmission state.
5. A computer network information security management method based on data processing according to claim 4, characterized in that, In step S3, cross-layer evidence edges are generated, including: Obtain the security status unit corresponding to the network-side event to be matched and the security status unit corresponding to the terminal-side event, respectively. The system performs a step-by-step assessment of the following criteria: consistent account identifier, consistent asset identifier, consistent session identifier, consistent network connection port and process port, time difference between process start time and network connection time within a preset time threshold, and resource access time later than remote access time. When the number of anchoring conditions satisfied is greater than or equal to two, a cross-layer evidence edge is generated between the corresponding two security state units. When the number of anchoring conditions is one, a candidate evidence edge is generated between the two corresponding security state units. The candidate evidence edge is not used as a cross-layer evidence edge in the construction of the reachability evidence graph in step S4.
6. The computer network information security management method based on data processing according to claim 5, characterized in that, In step S4, a reachability evidence graph is constructed, including: Treat the safe state unit as a node in the reachability evidence graph; Cross-layer evidence edges are used as node connection edges in the reachable evidence graph; Generate an identity transfer edge between two security state units that have the same account identifier and whose event times are consecutive; Generate process-derived edges between two security state units that have a parent process identifier and a process identifier correspondence; Generate permission change edges between security state units with different levels before and after the permission change; A resource reach edge is generated between two security state units that have the same account ID or the same process ID, and the latter security state unit contains a sensitive resource access action. An external transmission edge is generated between two security state units that enter the external transmission state after the sensitive resource access state; A reachable evidence graph is formed based on cross-layer evidence edges, identity transfer edges, process derivation edges, permission change edges, resource access edges, and external transmission edges.
7. A computer network information security management method based on data processing according to claim 6, characterized in that, In step S4, the minimum reachable evidence chain is extracted from the reachable evidence graph, including: Security state units with status types of remote access or abnormal connection are identified as candidate starting points; The state type of sensitive resource access state, external transmission state, or security state unit corresponding to high-value assets is identified as the candidate endpoint; Search for candidate evidence chains between candidate start points and candidate end points that contain permission change states or lateral access states. The evidence chain with the fewest nodes is selected from the candidate evidence chains; When there are two or more evidence chains with the same number of nodes, the evidence chain with the most cross-layer evidence edges is selected as the minimum reachable evidence chain.
8. A computer network information security management method based on data processing according to claim 7, characterized in that, In step S5, the blocking payoff value is calculated for each cross-layer evidence edge, including: Obtain the cross-layer verification count, attack stage level, sensitive resource association marker, and permission change association marker for the corresponding cross-layer evidence edge; The cross-layer verification quantity, attack stage level, sensitive resource association marker, and permission change association marker are multiplied by their respective preset benefit weights and then summed to obtain the blocking benefit value of the cross-layer evidence edge. The attack stage levels are set in ascending order of remote access status, lateral access status, permission change status, sensitive resource access status, and external transmission status. The sensitive resource association flag is set to 1 when the security state unit connected to the corresponding cross-layer evidence edge contains the sensitive resource reach state, and otherwise is set to 0. The permission change association flag is set to 1 when the security state unit connected to the corresponding cross-layer evidence edge contains a permission change state, and otherwise it is set to 0.
9. A computer network information security management method based on data processing according to claim 8, characterized in that, In step S5, the business loss value is calculated for each cross-layer evidence edge, including: Obtain the number of business links associated with the corresponding cross-layer evidence edge, the markers of key business links, the number of abnormal business heartbeats, and the level of dependent assets; The business loss value of the cross-layer evidence edge is obtained by multiplying the number of business links, the key business link markers, the number of abnormal business heartbeats, and the dependent asset level by their respective preset loss weights and then summing them. The key business link marker takes a value of 1 when the business link associated with the corresponding cross-layer evidence edge belongs to the preset key business link directory, and otherwise takes a value of 0. If there are two or more cross-layer evidence edges whose blocking benefit values all reach the preset blocking threshold and whose business loss values are the same, the cross-layer evidence edge located on the side closer to the candidate starting point in the minimum reachable evidence chain is selected as the disposal breakpoint.
10. A computer network information security management method based on data processing according to claim 9, characterized in that, In steps S6 to S8, the shadow handling strategy includes session isolation strategy, temporary account privilege reduction strategy, process external connection restriction strategy, network connection port access restriction strategy, or sensitive resource access secondary verification strategy. When the set of reachable business links after loading the shadow handling policy is reduced compared to the set of reachable business links before loading the shadow handling policy, and the reduced business links are critical business links, and the business heartbeat status of the critical business links is abnormal, the session isolation policy will be adjusted to the account temporary demotion policy, or the network connection port access restriction policy will be adjusted to the sensitive resource access secondary verification policy. After implementing the actual handling strategy, the verification data of the upstream and downstream safety status units of the handling breakpoint are collected again; When the verification data indicates that there is no cross-layer evidence edge between the upstream security status unit and the downstream security status unit of the handling breakpoint, and the heartbeat status in the business heartbeat data is normal, it is determined that the minimum reachable evidence chain is blocked. When the verification data indicates that there is still a cross-layer evidence edge between the upstream and downstream security state units of the disposal breakpoint, it is determined that the minimum reachable evidence chain has not been blocked.