Data processing method and related apparatus

HK40091011BActive Publication Date: 2026-07-17TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Patent Information

Authority / Receiving Office
HK · HK
Patent Type
Patents
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2023-09-27
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In complex network environments, especially cloud environments, existing technologies are often ineffective due to the rapid iteration of network threats, making it difficult to apply anomaly detection methods and resulting in a significant waste of computing and storage resources on terminal devices.

Method used

By working collaboratively between multiple terminal devices and anomaly detection devices, the terminal devices extract data features and upload them, while the anomaly detection devices perform centralized detection. The terminal devices do not need to maintain the rule base locally; instead, they utilize the server for anomaly detection and rule base updates.

Benefits of technology

It reduces the computational load on anomaly detection equipment and the processing pressure on terminal devices, improves the processing capacity of the network environment and the real-time performance of anomaly detection, and reduces the resource consumption of terminal devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a data processing method and related apparatus. For a network environment comprising a plurality of terminal devices, the plurality of terminal devices no longer load a rule base for detecting network threats, thereby realizing cooperative work between the terminal devices and an anomaly detection device for anomaly detection. The plurality of terminal devices extract to-be-detected data based on computing capability, thereby reducing the amount of data reported to the anomaly detection device, alleviating the receiving and processing pressure of the anomaly detection device, shortening the time delay of obtaining an anomaly detection result, and enabling the first terminal device to obtain the anomaly detection result in real time, thereby avoiding a great impact of an abnormal situation on the first terminal device. Moreover, the anomaly detection device detects anomalies of the plurality of terminal devices in the network environment, thereby ensuring that the terminal devices are not attacked by viruses, without the need for the terminal devices to maintain a corresponding rule base locally, thereby freeing the processing resources of the terminal devices and improving the processing capability of the network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and in particular to a data processing method and related apparatus. Background Technology

[0002] Anomaly detection is an important technology for protecting various types of data in terminal devices. For example, by detecting abnormal intrusion behavior, an alarm will be triggered once abnormal behavior is detected, and the terminal device can prevent abnormal behavior to ensure the security of its own communication and data.

[0003] In related technologies, anomaly detection is mainly accomplished through terminal devices, which deploy rule bases for anomaly detection and perform their own anomaly detection based on the loaded rule bases.

[0004] However, cyber threats are evolving rapidly, especially in complex network environments such as cloud environments, where cyber threats exhibit diverse patterns, making it difficult for related technologies to provide anomaly detection methods that are applicable. Summary of the Invention

[0005] To address the aforementioned technical issues, this application provides a data processing method and related apparatus that enables collaborative work between terminal devices and anomaly detection devices for anomaly detection in a network environment including multiple terminal devices. This reduces the receiving and processing pressure on the anomaly detection devices and eliminates the need for terminal devices to maintain corresponding rule bases locally, thus freeing up the processing resources of the terminal devices.

[0006] The embodiments of this application disclose the following technical solutions:

[0007] On one hand, embodiments of this application provide a data processing method, which is applied in a network environment including multiple terminal devices, the method comprising:

[0008] The data features reported by the first terminal device among the plurality of terminal devices are obtained, and the data features are extracted based on the data to be detected in the first terminal device;

[0009] Based on the rule base used for anomaly detection and the data type corresponding to the data features, corresponding anomaly detection is performed to obtain the detection results;

[0010] If the detection result is a first result that identifies an anomaly, the first result is returned to the first terminal device, and the first result is used to indicate the target data that caused the anomaly.

[0011] Acquire first raw data sent by the first terminal device, wherein the first raw data is extracted from the data to be detected based on its correlation with the target data;

[0012] The rule base is updated based on the first original data.

[0013] On the other hand, embodiments of this application provide a data processing method, which is applied in a network environment including multiple terminal devices, wherein the multiple terminal devices include a target terminal device, and the method includes:

[0014] Collect the data to be detected related to the target terminal device, and temporarily store the data to be detected locally on the target terminal device;

[0015] By performing normal data filtering on the initial data features of the data to be detected, and removing initial data features that are irrelevant to anomaly detection from the initial data features, the data features are obtained.

[0016] The data features are sent to the anomaly detection device in the network environment;

[0017] Obtain detection results for the data features from the anomaly detection device;

[0018] If the detection result is a first result that identifies an anomaly, the original target data is extracted from the locally stored data to be detected based on its correlation with the target data. The first result is used to indicate the target data that caused the anomaly.

[0019] The target raw data is sent to the anomaly detection device.

[0020] On the other hand, embodiments of this application provide a data processing apparatus, which is applied in a network environment including multiple terminal devices. The apparatus includes: an acquisition unit, an anomaly detection unit, a sending unit, and an update unit.

[0021] The acquisition unit is used to acquire data features reported by the first terminal device among the plurality of terminal devices, wherein the data features are extracted based on the data to be detected in the first terminal device;

[0022] The anomaly detection unit is used to perform corresponding anomaly detection based on the rule base for anomaly detection and the data type corresponding to the data feature, and obtain the detection result.

[0023] The sending unit is configured to return the first result to the first terminal device if the detection result is a first result that identifies an anomaly, wherein the first result is used to indicate the target data that caused the anomaly.

[0024] The acquisition unit is used to acquire first raw data sent by the first terminal device, wherein the first raw data is extracted from the data to be detected based on its correlation with the target data;

[0025] The update unit is used to update the rule base according to the first original data.

[0026] On the other hand, embodiments of this application provide a data processing apparatus, which is applied in a network environment including multiple terminal devices, the multiple terminal devices including a target terminal device, and the apparatus includes: a collection unit, a filtering unit, a sending unit, an acquisition unit, and an extraction unit;

[0027] The acquisition unit is used to acquire data to be detected related to the target terminal device and temporarily store the data to be detected locally on the target terminal device.

[0028] The screening unit is used to perform normal data screening on the initial data features of the data to be detected, and to remove initial data features that are not related to anomaly detection from the initial data features to obtain data features;

[0029] The sending unit is used to send the data features to the anomaly detection device in the network environment;

[0030] The acquisition unit is used to acquire detection results for the data features from the anomaly detection device;

[0031] The extraction unit is used to extract the target original data from the locally stored data to be detected based on its correlation with the target data if the detection result is a first result that identifies an anomaly. The first result is used to indicate the target data that caused the anomaly.

[0032] The sending unit is used to send the target raw data to the anomaly detection device.

[0033] On the other hand, embodiments of this application provide a data processing system, which includes a target terminal device and an anomaly detection device:

[0034] The target terminal device is used to collect data to be detected related to the target terminal device and temporarily store the data to be detected locally on the target terminal device; by performing normal data filtering on the initial data features of the data to be detected, the initial data features that are not related to anomaly detection are filtered out from the initial data features to obtain data features; and the data features are sent to the anomaly detection device in the network environment.

[0035] The anomaly detection device is used to acquire the data features; perform corresponding anomaly detection based on the rule base for anomaly detection and the data type corresponding to the data features, and obtain a detection result; if the detection result is a first result that identifies an anomaly, return the first result to the target terminal device, wherein the first result is used to indicate the target data that caused the anomaly;

[0036] The target terminal device is further configured to extract target original data from the locally stored data to be detected based on its correlation with the target data; and send the target original data to the anomaly detection device.

[0037] The anomaly detection device is also used to update the rule base based on the target's original data.

[0038] On the other hand, embodiments of this application provide a computer device, the device including a processor and a memory:

[0039] The memory is used to store program code and transmit the program code to the processor;

[0040] The processor is configured to execute the methods described above according to instructions in the program code.

[0041] On the other hand, embodiments of this application provide a computer-readable storage medium for storing a computer program for performing the methods described above.

[0042] On the other hand, embodiments of this application provide a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods described above.

[0043] As can be seen from the above technical solution, for network environments with multiple terminal devices, each terminal device no longer loads its own rule base for detecting network threats. Taking the first terminal device as an example, the first terminal device extracts data from the data to be detected. The resulting data features not only characterize the features of the data to be detected but also reduce the amount of data. Therefore, the anomaly detection device performs corresponding anomaly detection based on the data features reported by the first terminal device and the rule base used for anomaly detection, reducing the computational load on the anomaly detection device while ensuring accuracy. If the detection result is the first result, it indicates that there is an anomaly in the data to be detected. The first result is returned to the first terminal device so that it can determine the target data causing the anomaly based on the first result. The first original data related to the target data is extracted from the data to be detected. Thus, the anomaly detection device can update the rule base based on the first original data, enabling the rule base to be updated accordingly based on the iteration of network threats, thereby enhancing the anomaly detection capability. Therefore, collaborative work for anomaly detection between terminal devices and anomaly detection devices is achieved in the network environment. By leveraging the computing power of multiple terminal devices to extract the data to be detected, the amount of data reported to the anomaly detection device is reduced, thereby alleviating the receiving and processing pressure on the anomaly detection device, shortening the latency of obtaining anomaly detection results, and enabling the first terminal device to obtain anomaly detection results in more real-time, avoiding significant impact from anomalies on the first terminal device. Furthermore, by using anomaly detection devices to detect anomalies on multiple terminal devices in the network environment, there is no need for terminal devices to maintain corresponding rule bases locally, freeing up processing resources for terminal devices and improving the processing capacity of the network environment. Attached Figure Description

[0044] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0045] Figure 1 This is a schematic diagram illustrating an application scenario of a data processing method provided in an embodiment of this application;

[0046] Figure 2 A signaling interaction diagram of a data processing system provided in an embodiment of this application;

[0047] Figure 3 A schematic diagram of the system framework provided for an embodiment of this application;

[0048] Figure 4 A flowchart illustrating the operation of a terminal device is provided in this application embodiment;

[0049] Figure 5 A flowchart illustrating the operation of an anomaly detection device provided in this application embodiment;

[0050] Figure 6 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;

[0051] Figure 7 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;

[0052] Figure 8 This is a schematic diagram of the structure of a data processing system provided in an embodiment of this application;

[0053] Figure 9 A structural diagram of a terminal device provided in an embodiment of this application;

[0054] Figure 10 This is a structural diagram of a server provided in an embodiment of this application. Detailed Implementation

[0055] The embodiments of this application will now be described with reference to the accompanying drawings.

[0056] Given the rapid iteration of current network threats, especially in complex network environments such as cloud environments where network threats exhibit diverse patterns, two approaches are provided in related technologies, which will be explained below.

[0057] In Method 1, all data generated by terminal devices is uploaded to the cloud as data to be detected. The cloud performs anomaly detection on the data to be detected based on a rule base used for anomaly detection. However, due to the large amount of data generated by terminal devices, the upload speed is slow, which seriously affects the real-time nature of the detection. In addition, the large number of terminal devices and the large amount of data calculation will bring a huge computing load to the cloud.

[0058] Method 2 involves the terminal device loading a large rule base for anomaly detection. After generating data, the device performs anomaly detection automatically. However, due to the rapid iteration of network threats, the rule base needs to be updated accordingly, resulting in an ever-growing size. The terminal device struggles to load such a large rule base normally. Even if it is successfully loaded, it will consume a significant amount of computing and storage resources, affecting the normal use of the terminal device. In scenarios with a large number of terminal devices deployed, this results in a serious waste of computing and storage resources.

[0059] Based on this, the embodiments of this application provide a data processing method that enables collaborative work between terminal devices and anomaly detection devices for anomaly detection in a network environment including multiple terminal devices. This reduces the receiving and processing pressure on the anomaly detection devices and eliminates the need for terminal devices to maintain corresponding rule bases locally, thus freeing up the processing resources of the terminal devices.

[0060] The data processing method provided in this application can be applied to data processing devices with data processing capabilities, such as terminal devices and servers. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal can be a smartphone, tablet computer, laptop computer, desktop computer, intelligent voice interaction device (such as a smart speaker), smart home appliance (such as a smart TV), in-vehicle terminal, smartwatch, etc., but is not limited to these. The terminal and server can be directly or indirectly connected via wired or wireless communication, which is not limited herein.

[0061] The data processing method provided in this application is based on cloud computing technology. Cloud computing refers to the delivery and usage model of IT infrastructure, which means obtaining the required resources in an on-demand and easily scalable manner through the network. In a broader sense, cloud computing refers to the delivery and usage model of services, which means obtaining the required services in an on-demand and easily scalable manner through the network. Such services can be IT and software, Internet-related, or other services. Cloud computing is a product of the development and integration of traditional computer and network technologies such as grid computing, distributed computing, parallel computing, utility computing, network storage technologies, virtualization, and load balancing.

[0062] With the development of the internet, real-time data streams, and the diversification of connected devices, as well as the demands for search services, social networks, mobile commerce, and open collaboration, cloud computing has rapidly developed. Unlike previous parallel distributed computing, cloud computing will fundamentally revolutionize the entire internet model and enterprise management model.

[0063] In this application embodiment, the main cloud computing technology involved includes cloud security. Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior detection. Through a large number of clients in a network, it monitors abnormal software behavior, obtains the latest information on Trojans and malware on the Internet, sends it to the server for automatic analysis and processing, and then distributes solutions for viruses and Trojans to each client.

[0064] The main research directions in cloud security include: 1. Cloud computing security, which mainly studies how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, and compliance auditing; 2. Cloudification of security infrastructure, which mainly studies how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security event and information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive amounts of information and improve the ability to control network-wide security events and risks; 3. Cloud security services, which mainly studies various security services provided to users based on cloud computing platforms, such as antivirus services.

[0065] In the data processing method provided in this application embodiment, cloud security is used to perform anomaly detection on the data generated by the terminal device, such as whether there are viruses, in order to ensure the network security of the terminal device.

[0066] To facilitate understanding of the technical solution of this application, the data processing method provided in the embodiments of this application will be described below using a data processing device as a server, combined with a practical application scenario. For example, see... Figure 1 The figure is a schematic diagram of an application scenario of a data processing method provided in an embodiment of this application.

[0067] exist Figure 1 The scenario shown includes terminal device 100 and terminal device 200. Both terminal device 100 and terminal device 200 will upload data features to server 300 via the network. For ease of explanation, the following description will take terminal device 100 as the first terminal device.

[0068] Terminal device 100 extracts data features from the data to be detected. While the data features can characterize the features of the data to be detected, the amount of data is reduced. Therefore, terminal device 100 reduces the amount of data reported to server 300, thereby reducing the receiving and processing pressure on server 300, shortening the latency of obtaining anomaly detection results, enabling terminal device to obtain anomaly detection results in a relatively real-time manner, and avoiding significant impact of anomalies on terminal device.

[0069] Server 300 acquires data characteristics uploaded by terminal device 100. Based on the data type corresponding to these characteristics and the rule base 400 used for anomaly detection, server 300 performs corresponding anomaly detection. This reduces computational load while maintaining accuracy. Furthermore, by using server 300 to detect anomalies in multiple terminal devices within the network environment, terminal devices do not need to maintain their own rule bases locally, freeing up their processing resources and improving the network's processing capabilities. If the detection result is the first result, it indicates an anomaly in the data being detected, and the first result is returned to terminal device 100.

[0070] Terminal device 100 determines the target data causing the anomaly based on the first result, extracts the first original data that is related to the target data from the data to be detected, and sends the first original data to server 300 so that server 300 can extract the characteristics of the anomaly from the first original data and update the rule base. This allows the rule base to be updated accordingly based on the iteration of network threats, which not only allows for rapid updates to the rule base but also further improves transmission efficiency.

[0071] Therefore, for network environments with multiple terminal devices, multiple terminal devices work collaboratively with the server to extract the data to be detected based on the computing power of multiple terminal devices. This eliminates the need for terminal devices to iteratively update the rule base based on network threats, thus avoiding the waste of computing and storage resources of terminal devices caused by the rule base. Furthermore, the server's detection capabilities are used to perform threat detection on data features with small amounts of data, eliminating the need for the server to calculate the data to be detected generated by each terminal device. This reduces the computing load while improving the real-time performance of network threat detection.

[0072] Based on the above introduction, the data processing system provided in this application will be described below. The data processing system includes multiple terminal devices and a server, wherein the server is an anomaly detection device as an example, and the multiple terminal devices are a first terminal device and a second terminal device as examples.

[0073] See Figure 2 This figure is a signaling interaction diagram of a data processing system provided in an embodiment of this application.

[0074] S201: The target terminal device collects the data to be tested related to the target terminal device and temporarily stores the data to be tested locally on the target terminal device.

[0075] In the embodiments of this application, multiple terminal devices work together with an anomaly detection device. For ease of explanation, the following description uses one of the multiple terminal devices (the target terminal device) as an example.

[0076] The target terminal device can collect data to be detected related to itself. For example, a first terminal device collects data to be detected related to itself, and a second terminal device collects data to be detected related to itself. The data to be detected can be data generated by the host or data generated through network traffic. After collecting the data, the target terminal device temporarily stores it locally (on the host) for anomaly detection. Anomaly detection is a crucial technology for protecting user data. For example, it can determine whether abnormal behavior such as virus intrusion exists. Once abnormal behavior is detected, an alarm is issued and the abnormal behavior is blocked, thereby ensuring the security of user data.

[0077] This application does not specifically limit the method by which the terminal device collects the data to be detected. For example, the data can be collected through a pre-built collection program or extracted through a gateway device. As one possible implementation, different collection methods can be used for different types of data to be detected. For example, if the data to be detected includes three types of files: real-time file data, real-time traffic data, and key data packets.

[0078] Real-time file data refers to file data downloaded from sources such as browsers, office software, and email attachments, which can be obtained through the file system. Real-time traffic data refers to the traffic data of each network interface card (NIC) on the corresponding host device, which can be obtained through each NIC. Key data packets are those from processes such as Kerbose (a computer network licensing protocol) and Server Message Block (SMB) services. Since the traffic of some important processes or services is encrypted, unencrypted data packets can be obtained from the functions of these processes through process injection.

[0079] S202: The target terminal device performs normal data filtering on the initial data features of the data to be detected, and removes the initial data features that are not related to anomaly detection from the initial data features to obtain the data features.

[0080] The target terminal device can extract features from the data to be detected to obtain initial feature data. This initial feature data not only characterizes the features of the data to be detected but also reduces the amount of data, thereby alleviating the receiving and processing pressure on the anomaly detection device.

[0081] As a possible implementation, different feature extraction methods can be used for different types of data to be detected. Let's continue to take real-time file data, real-time traffic data and key data packets as examples. First, for real-time file data, we determine the type of file and calculate features such as hash. Second, for real-time traffic data, the extracted features are divided into three categories: traffic sequence features, known application layer protocol features, and file features. Among them, (1) traffic sequence features mainly refer to timestamp, source Internet Protocol (IP), source port, destination IP, destination port, protocol, etc.; (2) known application layer protocols include File Transfer Protocol (FTP), Hyper Text Transfer Protocol (HTTP), Simple Mail Transfer Protocol (SMTP), etc. For known application layer protocols, a set of feature vector extraction methods is pre-set. The target terminal device or the client built into the target terminal device automatically extracts the application layer protocol packets in the traffic and performs feature calculation and extraction; (3) file features mainly extract files in unknown application layer protocol packets according to the known file rule list. The third approach is to extract key data packets using corresponding rules based on the specific process. For example, in the Kerbose interaction process, extract operations such as ticket requests and service accesses from the packets.

[0082] After extracting the initial data features, since normal data generally does not cause anomalies, normal data can be screened out. Initial data features that are irrelevant to anomaly detection are removed from the initial data features to obtain the data features, thereby further reducing the amount of data and the amount of data uploaded, and reducing the burden on the anomaly detection equipment for receiving and processing.

[0083] As one possible approach, a whitelist can be used to initially screen normal data. The whitelist consists of trusted information such as IP addresses, ports, and file hashes, derived from client-preset or customer-defined rules. These rules are used to filter some data, reducing the burden on the cloud.

[0084] S203: The target terminal device sends data characteristics to the anomaly detection device in the network environment.

[0085] One possible approach is to anonymize sensitive features in the data after filtering out some data. These sensitive features are related to user privacy information, such as passwords and IP addresses. Another possible approach is to set sensitive features based on client-preset and customer-defined rules, so that potentially sensitive data such as passwords and IP addresses are replaced before being reported to the anomaly detection device, thus achieving anonymization.

[0086] It is understood that in the specific implementation of this application, data such as user information, passwords, and IP addresses are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.

[0087] Therefore, the target terminal device no longer uploads all the data to be detected, but uploads data features. Data features can characterize the features of the data to be detected while reducing the amount of data. This reduces the amount of data uploaded while ensuring the content required for anomaly detection, reduces the receiving and processing burden of anomaly detection equipment, and is conducive to centralized anomaly detection by anomaly detection equipment.

[0088] S204: The anomaly detection device acquires the data characteristics reported by the first terminal device among multiple terminal devices.

[0089] In this application, the anomaly detection device performs anomaly detection on the data features reported by multiple terminal devices. For ease of explanation, the first terminal device among the multiple terminal devices will be used as an example for the following description.

[0090] The first terminal device can be used as a target terminal device to execute the aforementioned S201-S203. Specifically, the first terminal device can collect the data to be detected related to the first terminal device as in S201, extract data features from the data to be detected as in S202, and send the data features to the anomaly detection device as in S203. It should be noted that the first terminal device can also execute the steps executed by other target terminal devices.

[0091] S205: The anomaly detection device performs corresponding anomaly detection based on the rule base used for anomaly detection and the data type corresponding to the data characteristics, and obtains the detection results.

[0092] The rule base for anomaly detection can be built into the anomaly detection device or it can be independent of the anomaly detection device; this application does not specifically limit this. The rule base includes various rules for anomaly detection, such as file matching rules and protocol matching rules.

[0093] The anomaly detection device retrieves the necessary rules from the rule base, performs corresponding anomaly detection based on the data type corresponding to the data characteristics, and obtains the detection results. Thus, anomaly detection is shifted from local self-checking on individual terminal devices to centralized detection by the anomaly detection device. This eliminates the need for terminal devices to maintain or download the rule base locally, freeing up their computing and storage resources.

[0094] This application does not specifically limit the method of anomaly detection. For example, the data type corresponding to the data feature can be determined first. The following description takes at least one of the data types, such as file type, protocol feature type, or message sequence type, as an example.

[0095] The first type: file type.

[0096] If the data type corresponding to the data feature includes text, file matching rules are obtained from the rule base used for anomaly detection. Anomaly detection is performed according to the file matching rules to obtain the first sub-detection result corresponding to the file type in the detection results.

[0097] Text-type data can be further categorized into executable files, rich text files, and other files. Executable files can include binary files such as executable programs (EXE files), Component Object Model (COM) files, and Executable and Linkable Format (ELF) files, as well as script files such as Windows Scripting Host (wscript) scripts and JavaScript scripts (a type of plain text executable written in JavaScript). Rich text files can be documents such as doc, excel, ppt, and pdf, which are rendered and calculated using a rich text editor.

[0098] File matching rules correspond to the executable files, rich text files, or other file types identified by the file type. For example, for executable files and rich text files, dynamic methods such as sandbox analysis and static methods such as static detection can be used for analysis. Other files are analyzed using feature matching rules. In other words, if the data type corresponding to the data feature includes text, the required file matching rules can be obtained from the rule base based on the executable files, rich text files, or other file types identified by the text type, thereby obtaining the first sub-detection result for the corresponding file type.

[0099] As one possible approach, machine learning and other methods can be used to analyze whether other files are malicious.

[0100] The second type: protocol feature type.

[0101] If the data type corresponding to the data feature includes a protocol feature type, the protocol matching rule is determined from the rule base used for anomaly detection based on the malicious sample. Anomaly detection is performed according to the protocol matching rule to obtain the second sub-detection result corresponding to the protocol feature type in the detection result.

[0102] For data features of protocol feature types, protocol matching rules for anomaly detection can be obtained through the analysis and extraction of a large number of known malicious samples. These rules can be pre-placed in the rule base so that subsequent anomaly detection can be performed to obtain the second sub-detection result of the corresponding protocol feature type.

[0103] The third type: message sequence type.

[0104] If the data type corresponding to the data feature includes a message sequence type, anomaly detection is performed based on the time sequence to obtain the third sub-detection result corresponding to the message sequence type in the detection result.

[0105] S206: The anomaly detection device returns the detection results of data features to the first terminal device.

[0106] The detection results of data features are divided into a first result and a second result, which are explained below. The first result indicates that there is an anomaly in the data features, see S208 for details; the second result indicates that the data features are normal, see S207 for details.

[0107] S207: The first terminal device deletes the locally stored data to be tested after a preset time.

[0108] If the detection result is a normal second result, the anomaly detection device returns the second result to the first terminal device. The second result is used to instruct the first terminal device to delete the locally stored data to be detected after a preset time.

[0109] Similarly, the target terminal device temporarily stores the data to be tested locally so that it can trace the source when an anomaly is detected. This will be explained in S301-S304 later, and will not be repeated here. If the detection result is the second result indicating normality, it means that the target terminal does not have an anomaly at the moment. The locally stored data to be tested can be deleted after a preset time to avoid wasting storage resources due to storing too much normal data. At the same time, even if the second result is obtained, by continuing to temporarily store the data to be tested for a preset time, the target terminal can perform self-checks when other terminal devices detect an anomaly, and this provides a basis for tracing the source of abnormal devices.

[0110] S208: The first terminal device sends the first raw data to the anomaly detection device.

[0111] If the detection result is the first result that identifies an anomaly, the anomaly detection device returns the first result to the first terminal device. The first result is used to indicate the target data that caused the anomaly.

[0112] The following uses the target terminal device as an example to illustrate how the target terminal device sends target raw data to the anomaly detection device, thereby illustrating how the first terminal device sends first raw data to the anomaly detection device. See steps A1 and A2.

[0113] Step A1: If the detection result is the first result that indicates an anomaly, the target terminal device extracts the target original data from the locally stored data to be detected based on its correlation with the target data.

[0114] After the target terminal device sends data features to the anomaly detection device in the network environment, the anomaly detection device performs anomaly detection on the data features and returns the detection result to the target terminal device. If the detection result is the first result, it indicates that there is an anomaly in the data features. The first result is used to indicate the target data that caused the anomaly. The target terminal device extracts the target original data from the locally stored data to be detected. There is a correlation between the target original data and the target data.

[0115] Step A2: The target terminal device sends the target raw data to the anomaly detection device.

[0116] The target terminal device sends the target raw data related to the anomaly to the anomaly detection device, so that the anomaly detection device can discover more data related to the anomaly based on the target raw data and quickly update the rule base. Moreover, compared with the data to be detected, the target raw data has a smaller data volume, which can further improve the transmission efficiency.

[0117] It should be noted that when the target terminal device is the first terminal device, the target raw data is the first raw data. The first terminal device extracts the first raw data from the locally stored data to be detected based on its correlation with the target data, and sends the first raw data to the anomaly detection device.

[0118] As one possible implementation, the target terminal device desensitizes the sensitive features in the first raw data and sends the desensitized first raw data to the anomaly detection device.

[0119] As one possible implementation, the target terminal device may issue an error message based on the anomaly identified by the first result, so that the user of the target terminal can suspend the current dangerous behavior based on the error message.

[0120] S209: The anomaly detection device updates the rule base based on the first raw data.

[0121] The first raw data is extracted from the data to be detected based on its correlation with the target data. It is data related to anomalies. The anomaly detection device can update the rule base based on the first raw data. Thus, through the efficient processing capability of the anomaly detection device, it can maintain and load a massive rule base that conforms to the complexity of the current network, achieving more accurate centralized detection. Moreover, after an anomaly is detected, the rule base is updated in a timely manner based on the first raw data related to the anomaly.

[0122] As one possible implementation, the anomaly detection device archives either the anonymized first original data or the unanonymized first original data, so that the anomaly detection device can subsequently extract data features from the first original data and use them to update the rule base and feature base.

[0123] As can be seen from the above technical solution, the anomaly detection device performs corresponding anomaly detection based on the data characteristics reported by the first terminal device and the rule base used for anomaly detection. This reduces the computational load of the anomaly detection device while ensuring accuracy. If the obtained detection result is the first result, it indicates that there is an anomaly in the data to be detected. The first result is returned to the first terminal device so that the first terminal device can determine the target data causing the anomaly based on the first result. The first original data that is related to the target data is extracted from the data to be detected. Thus, the anomaly detection device can update the rule base based on the first original data, enabling the rule base to be updated accordingly based on the iteration of network threats, thereby enhancing the anomaly detection capability. Therefore, collaborative work for anomaly detection is achieved between the terminal device and the anomaly detection device in the network environment. The data to be detected is extracted based on the computing power of multiple terminal devices, reducing the amount of data reported to the anomaly detection device. This alleviates the receiving and processing pressure on the anomaly detection device, shortens the latency of obtaining anomaly detection results, and allows the first terminal device to obtain anomaly detection results in more real-time, avoiding significant impact of anomalies on the first terminal device. Furthermore, by using anomaly detection equipment to detect anomalies in multiple terminal devices in the network environment, there is no need for terminal devices to maintain corresponding rule bases locally, thus freeing up the processing resources of terminal devices and improving the processing capabilities of the network environment.

[0124] The following section explains the process of constructing a threat trajectory for the anomaly detection device using S210-S213 to achieve network threat tracing.

[0125] S210: The anomaly detection device determines a second terminal device that is associated with the anomaly from multiple terminal devices based on the first raw data.

[0126] The first set of raw data is data that correlates with the target data causing the anomaly. This raw data clarifies the cause of the anomaly in the first terminal device. For example, if the first terminal device receives a file containing a virus, the raw data can analyze that the file was sent to the first terminal device by a second terminal device. In other words, the anomaly detection device can identify a second terminal device related to the anomaly from multiple terminal devices in the network environment. This second terminal device is different from the first terminal device.

[0127] S211: The anomaly detection device sends a temporary detection rule determined based on the first raw data to the second terminal device.

[0128] The anomaly detection device sends a temporary detection rule determined based on the first raw data to the second terminal device.

[0129] The following section uses the target terminal device as an example to explain how the target terminal device obtains the detection results according to the temporary detection rules. See steps B1-B3.

[0130] Step B1: The target terminal device obtains temporary detection rules from the anomaly detection device.

[0131] The target terminal device is a terminal device that is associated with the target anomaly, such as the second terminal device mentioned above, and the target anomaly is the anomaly identified in the data characteristics uploaded by the first terminal device mentioned above.

[0132] Temporary detection rules are determined by the anomaly detection device based on the original target data corresponding to the detected anomaly. After calculating new rules (i.e., temporary detection rules) based on the original target data corresponding to the detected anomaly through methods such as feature extraction, the anomaly detection device, considering that the attack corresponding to the target anomaly may have already affected or will affect other terminal devices, such as secondary terminal devices, distributes the temporary detection rules to these other terminal devices. This collaboration between terminal devices further enhances protection and detects whether other terminal devices are under threat.

[0133] For example, if the anomaly detection device detects an anomaly based on the data characteristics uploaded by the first terminal device, the anomaly detection device will determine a temporary detection rule based on the first original data corresponding to the anomaly. That is, the target original data can be the first original data mentioned above. The temporary detection rule is determined based on the first original data and then sent to the second terminal device.

[0134] Step B2: The target terminal device detects the local temporary data of the target terminal device based on the temporary detection rules and obtains the detection results.

[0135] The target terminal device's local temporary data includes data to be detected. The local temporary data is detected based on temporary detection rules to obtain detection results, which include normal detection results and abnormal detection results.

[0136] One possible implementation is to generate protection policies based on temporary detection rules, and then detect the locally stored temporary data of the target terminal device according to the protection policies to obtain the detection results. This enables real-time detection and interception, and protects the security of the target terminal device through the protection policies.

[0137] As one possible implementation, the anomaly detection device generates protection rules while generating temporary detection rules, and sends the temporary detection rules and protection rules to the target terminal device. The target terminal device generates and applies protection policies according to the protection rules, and detects the locally stored data according to the temporary detection rules. If an anomaly is found, it is sent back to the anomaly detection device.

[0138] Step B3: The target terminal device returns the detection result to the anomaly detection device.

[0139] Therefore, when the target terminal device is the second terminal device, the second terminal device obtains the temporary detection rules determined based on the first original data from the anomaly detection device; the second terminal device detects the local temporary data of the target terminal device based on the temporary detection rules to obtain the detection results; and the second terminal device returns the detection results to the anomaly detection device.

[0140] S212: The second terminal device sends the anomaly detection result to the anomaly detection device.

[0141] The anomaly detection results are obtained by detecting the local temporary data of the second terminal device based on temporary detection rules.

[0142] S213: The anomaly detection device constructs a threat trajectory corresponding to the anomaly based on the anomaly detection results.

[0143] For example, anomaly detection equipment can locate a second terminal device by detecting anomalies in a first terminal device, and then a third, fourth, and so on, until the source is found, thus constructing a threat trajectory corresponding to the anomaly. In this way, the anomaly detection equipment can sense the trajectory of the threat and, by continuously tracing back the data to be detected in the terminal devices, determine the attack path of the network threat, thereby providing targeted security protection for the terminal devices along the attack path.

[0144] As one possible implementation, second raw data can be obtained from a second terminal device. The second raw data is extracted from the local temporary data of the second terminal device based on the anomaly detection results, and the second terminal device updates the rule base based on the second raw data.

[0145] Next, let's combine the following... Figures 3-5 The data processing method provided in this application embodiment will be described using the interaction between the first terminal device, the second terminal device, and the anomaly detection device as an example.

[0146] See Figure 3 The figure is a schematic diagram of the system framework provided in an embodiment of this application. The system framework includes a first terminal device, a second terminal device, and an anomaly detection device.

[0147] The first terminal device is used to perform S1 data acquisition, S2 feature extraction, S3 data initial screening, S4 data desensitization, and S5 data reporting.

[0148] The anomaly detection equipment is used to perform S6 data analysis, S7 malicious intent detection, S8 emergency response, S9 alarm generation, S10 temporary detection rule generation, and S11 temporary detection rule issuance.

[0149] The second terminal device is used to perform S12 self-test and S13 self-test result reporting.

[0150] The anomaly detection equipment is also used to perform S14 intelligence updates, S15 threat trajectory construction, and S16 rule base updates.

[0151] Specifically, a client program is installed on the first terminal device, and the data to be detected on the first terminal device is collected through the pre-installed acquisition program of the client program (S1 data acquisition). Then, after S2 feature extraction, S3 initial data screening, S4 data desensitization, and S5 data reporting, the desensitized data is uploaded to the anomaly detection device in the cloud. The anomaly detection device determines the detection result through S6 data analysis, and S7 determines whether it is malicious (i.e., whether the detection result is the primary result or the secondary result). If the detection result is the primary result, S8 emergency response, S9 generates an alarm and returns it to the client program, and then the client program performs the corresponding alarm and other operations. At the same time, if the detection result is identified as the primary result, it indicates that a new network threat has been discovered. After S8 emergency response, S10 generates a temporary detection rule, and S11 sends the temporary detection rule to the client program of the second terminal device. S12 Self-check: After receiving the issued temporary detection rules, the client program of the second terminal device activates the corresponding protection and performs a self-check to obtain the self-check result. S13 The self-check result is reported to the anomaly detection device. That is, if a new network threat is discovered according to the rule, it is reported to the anomaly detection device for further processing by the regular detection device. S14 Intelligence update by the anomaly detection device, S15 Threat trajectory construction, and S16 Update of the rule base.

[0152] The following is through Figure 4 The description will focus on the first and second terminal devices, and will be carried out in detail through... Figure 5 The description will focus on anomaly detection equipment.

[0153] See Figure 4 This figure is a flowchart illustrating the operation of a terminal device according to an embodiment of this application. The first terminal device will be described below.

[0154] S1: Data Acquisition.

[0155] The first terminal device collects the data to be tested related to the first terminal device and temporarily stores the data to be tested locally on the first terminal device.

[0156] The first terminal device has a client program installed. The client program uses a pre-installed data collection program to collect data related to the first terminal device, such as real-time file data, real-time traffic data, and key data packets, which are required for detecting network threats.

[0157] S2: Feature extraction.

[0158] The first terminal device extracts features from the data to be detected to obtain the initial data features of the data to be detected.

[0159] This application does not specifically limit the feature extraction method. For example, different feature extraction methods may be used for different types of data to be detected. Please refer to the relevant description of feature extraction in S202 above. Alternatively, features may be extracted from the data to be detected according to pre-set rules.

[0160] S3: Initial data screening.

[0161] The first terminal device performs normal data filtering on the initial data features of the data to be detected, removing initial data features that are irrelevant to anomaly detection, and thus obtains the data features.

[0162] After extracting the initial data features, data filtering can be performed. For example, a whitelist can be set up using preset rules and user-defined rules. The whitelist includes initial data features that are not related to anomaly detection. If an initial data feature is the same as an initial data feature in the whitelist, then that initial data feature is filtered out. This process removes initial data features that are not related to anomaly detection from the initial data features, thereby obtaining the data features and further reducing the amount of data, the amount of data uploaded, and the burden on the anomaly detection equipment for receiving and processing.

[0163] S4: Data anonymization.

[0164] The first terminal device de-identifies sensitive features in the data characteristics. These sensitive features are related to user privacy information and can be pre-defined using preset rules and user-defined rules. For example, after filtering out some data, the sensitive features in the data characteristics are de-identified using preset rules and user-defined rules to obtain the de-identified data characteristics.

[0165] S5: Data reporting.

[0166] The first terminal device sends data characteristics to the anomaly detection device in the network environment.

[0167] The anomaly detection device analyzes the de-identified data features using S6 to obtain detection results, and then feeds these results back to the client program of the first terminal device. The specific execution content of the first terminal device is detailed in S17-S19. In addition, the anomaly detection device can also execute S7 (malicious intent detection), S8 (emergency response), S9 (alarm generation), S10 (temporary detection rule generation), and S11 (temporary detection rule issuance). See details in [link to relevant documentation]. Figure 5 The embodiments shown are not described in detail here.

[0168] S17: Whether it was malicious.

[0169] If the first terminal device identifies the detection result, and the detection result is the first result, then there is malice in the data to be detected, and S18 is executed to issue a prompt; if the detection result is the second result, then there is no malice in the data to be detected, and the locally temporarily stored data to be detected is deleted after a preset time to avoid wasting storage resources due to storing too much normal data. At the same time, even if the second result is obtained, by continuing to temporarily store the data to be detected for a preset time, when other terminal devices discover the abnormality, the target terminal identification can perform self-checks and provide a basis for tracing the abnormal device.

[0170] It should be noted that both the first terminal device and the anomaly detection device can identify the detection results and determine whether they are malicious.

[0171] S18: Issue a prompt.

[0172] If the detection result is the first result, then there is malicious activity in the data to be detected. The first terminal device can display a prompt that there is a network threat on the display screen, and can also issue an alarm through sound, so that the user of the first terminal device is aware that there is a network threat to the first terminal device and needs to immediately stop the current operation and perform virus scanning, etc.

[0173] S19: Data anonymization.

[0174] The first terminal device performs desensitization processing on the sensitive data in the data to be tested.

[0175] If the detection result is the first result, it indicates that there is malicious activity in the data to be detected. Threat traces can be constructed by identifying anomaly detection equipment to achieve network threat tracing. At this time, the locally stored data to be detected can be anonymized, that is, sensitive data in the data to be detected can be identified. For example, sensitive data such as passwords and IP addresses can be replaced to obtain anonymized data to be detected, so as to upload it to the anomaly detection equipment.

[0176] S12: Self-check.

[0177] The second terminal device detects the locally stored temporary data of the target terminal device based on temporary detection rules to obtain the detection results.

[0178] The second terminal device is identified by the anomaly detection device from multiple terminal devices based on the first raw data. A client program is installed on the second terminal device. This client program's pre-installed data acquisition program can not only collect data related to the second terminal device for the anomaly detection device to identify, but also receive temporary detection rules issued by the anomaly detection device and perform self-checks on locally stored data according to these rules.

[0179] S13: Report self-inspection results.

[0180] The second terminal device sends the detection results (also known as self-test results) to the anomaly detection device. It should be noted that the detection results are divided into anomaly detection results and normal detection results. As one possible implementation, the second terminal device can send anomaly detection results to the anomaly detection device; that is, if a new network threat is detected according to this rule, it is reported to the anomaly detection device for further processing.

[0181] S20: Generate protection strategy.

[0182] The second terminal device generates a protection strategy based on the protection rules.

[0183] For example, the client program of the second terminal device receives the protection rules and generates a protection policy based on the protection rules to ensure the security of the second terminal device.

[0184] After introducing the first and second terminal devices, the anomaly detection device will now be explained.

[0185] See Figure 5 The figure is a flowchart of the operation of an anomaly detection device provided in an embodiment of this application.

[0186] S6: Data analysis.

[0187] The anomaly detection device performs anomaly detection based on a rule base used for anomaly detection and the data type corresponding to the data features, and obtains the detection results. The data features are the aforementioned anonymized data features. The following explains the anomaly detection based on the data type corresponding to different data features.

[0188] The first type: file type.

[0189] If the data type corresponding to the data feature includes text, file matching rules are obtained from the rule base used for anomaly detection. Anomaly detection is performed according to the file matching rules to obtain the first sub-detection result corresponding to the file type in the detection results.

[0190] For executable files and rich text files, dynamic analysis methods such as sandbox analysis and static detection can be used. For other files, analysis is performed using feature matching rules. That is, if the data type corresponding to the data feature includes text, the required file matching rules can be obtained from the rule base based on the executable file, rich text file, or other file type identified by the text type, thereby obtaining the first sub-detection result for the corresponding file type.

[0191] The second type: protocol feature type.

[0192] If the data type corresponding to the data feature includes a protocol feature type, the protocol matching rule is determined from the rule base used for anomaly detection based on the malicious sample. Anomaly detection is performed according to the protocol matching rule to obtain the second sub-detection result corresponding to the protocol feature type in the detection result.

[0193] The third type: message sequence type.

[0194] If the data type corresponding to the data feature includes a message sequence type, anomaly detection is performed based on the time sequence to obtain the third sub-detection result corresponding to the message sequence type in the detection result.

[0195] S7: Whether it is malicious.

[0196] The anomaly detection device identifies the detection results. If the detection result is the first result, the data to be detected is malicious, and an S8 emergency response is executed. If the detection result is the second result, the data to be detected is not malicious, and the locally stored data to be detected is deleted after a preset time to avoid wasting storage resources due to storing too much normal data. At the same time, even if the second result is obtained, the data to be detected can continue to be stored temporarily for a preset time. When other terminal devices detect the anomaly, the target terminal can perform self-checks and provide a basis for tracing the source of the anomaly.

[0197] S8: Emergency Response.

[0198] If the detection result is the first result, the anomaly detection equipment will initiate an emergency response based on the first result.

[0199] S9: Generate an alarm.

[0200] The anomaly detection device generates an alarm and sends it to the first terminal device so that the first terminal device can issue an alarm notification.

[0201] S21: Save the file.

[0202] The first terminal device de-identifies the sensitive data in the data to be detected and then uploads it to the anomaly detection device. The anomaly detection device then stores the de-identified data to be detected locally.

[0203] S22: Feature extraction.

[0204] The anomaly detection equipment extracts features from the desensitized data to be detected.

[0205] S10: Generate temporary detection rules.

[0206] The anomaly detection device determines temporary detection rules based on the first set of raw data. This first set of raw data is extracted from the data to be detected based on its correlation with target data, which is used to indicate data that caused the anomaly.

[0207] S11: Issue temporary detection rules.

[0208] Considering that the attack may have already affected or will affect other terminal devices, the anomaly detection device needs to construct a threat trajectory to find the source of the anomaly. Based on this, the anomaly detection device issues temporary detection rules to the second terminal device, so that the second terminal device can obtain anomaly detection results according to the temporary detection rules. The anomaly detection results are obtained by detecting the locally stored temporary data of the second terminal device based on the temporary detection rules. Specifically, the second terminal device anomaly detection device identifies the terminal devices associated with the anomaly from multiple terminal devices based on the first original data.

[0209] S14: Intelligence Update.

[0210] The anomaly detection device receives the self-test results reported by the second terminal device (see...). Figure 4 (S13) Update the temporary detection rules based on the detection results, continue to identify terminal devices that are related to the second terminal device, treat them as new second terminal devices, issue temporary detection rules, and continue until the source of the abnormality of the terminal device is found.

[0211] S15: Construct a threat trajectory.

[0212] Anomaly detection equipment constructs threat trails based on continuously updated intelligence. For example, if terminal device A is affected by terminal device B, and terminal device B is affected by terminal device C, then terminal device C is the source of the anomaly, thus generating a threat trail.

[0213] S16: Update the rule base.

[0214] The anomaly detection equipment updates its rule base based on the continuously uploaded detection results and the anonymized data to be detected, thereby improving the accuracy of anomaly detection through continuous rule base updates.

[0215] In addition to the data processing methods provided in the above embodiments, this application also provides a data processing apparatus.

[0216] See Figure 6 , Figure 6 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 6 As shown, the data processing device 600 is applied in a network environment including multiple terminal devices, and includes: an acquisition unit 601, an anomaly detection unit 602, a sending unit 603, and an update unit 604;

[0217] The acquisition unit 601 is used to acquire data features reported by the first terminal device among the plurality of terminal devices, wherein the data features are extracted based on the data to be detected in the first terminal device;

[0218] The anomaly detection unit 602 is used to perform corresponding anomaly detection based on the rule base for anomaly detection and the data type corresponding to the data feature, and obtain the detection result.

[0219] The sending unit 603 is configured to return the first result to the first terminal device if the detection result is a first result that identifies an anomaly, wherein the first result is used to indicate the target data that caused the anomaly.

[0220] The acquisition unit 601 is used to acquire first raw data sent by the first terminal device, wherein the first raw data is extracted from the data to be detected based on its correlation with the target data;

[0221] The update unit 604 is used to update the rule base according to the first original data.

[0222] As one possible implementation, the data processing device 600 further includes a deletion unit, which is used to return the second result to the first terminal device if the detection result is a second result indicating normality. The second result is used to instruct the first terminal device to delete the locally stored data to be detected after a preset time.

[0223] As one possible implementation, the data processing device 600 further includes a threat trajectory construction unit, used for:

[0224] Based on the first raw data, a second terminal device that is associated with the anomaly is determined from the plurality of terminal devices;

[0225] Send a temporary detection rule determined based on the first raw data to the second terminal device;

[0226] Obtain an anomaly detection result from the second terminal device, wherein the anomaly detection result is obtained by detecting the local temporary data of the second terminal device based on the temporary detection rule;

[0227] Based on the anomaly detection results, a threat trajectory corresponding to the anomaly is constructed.

[0228] As one possible implementation, the update unit 604 is further configured to:

[0229] The second raw data is obtained from the second terminal device, which is extracted from the local temporary data of the second terminal device based on the anomaly detection result;

[0230] The rule base is updated based on the second original data.

[0231] As one possible implementation, the anomaly detection unit 602 is further configured to:

[0232] Determine the data type corresponding to the data feature, wherein the data type includes at least one of file type, protocol feature type, or message sequence type;

[0233] If the data type corresponding to the data feature includes the text type, file matching rules are obtained from the rule base for anomaly detection, and anomaly detection is performed according to the file matching rules to obtain the first sub-detection result corresponding to the file type in the detection result. The file matching rules have a corresponding relationship with the executable file, rich text file or other file identified by the file type.

[0234] If the data type corresponding to the data feature includes the protocol feature type, the protocol matching rule is determined from the rule base for anomaly detection based on the malicious sample, and anomaly detection is performed according to the protocol matching rule to obtain the second sub-detection result corresponding to the protocol feature type in the detection result;

[0235] If the data type corresponding to the data feature includes the message sequence type, anomaly detection is performed based on the time sequence to obtain a third sub-detection result corresponding to the message sequence type in the detection result.

[0236] As can be seen from the above technical solution, for network environments with multiple terminal devices, each terminal device no longer loads its own rule base for detecting network threats. Taking the first terminal device as an example, the first terminal device extracts data from the data to be detected. The resulting data features not only characterize the features of the data to be detected but also reduce the amount of data. Therefore, the anomaly detection device performs corresponding anomaly detection based on the data features reported by the first terminal device and the rule base used for anomaly detection, reducing the computational load on the anomaly detection device while ensuring accuracy. If the detection result is the first result, it indicates that there is an anomaly in the data to be detected. The first result is returned to the first terminal device so that it can determine the target data causing the anomaly based on the first result. The first original data related to the target data is extracted from the data to be detected. Thus, the anomaly detection device can update the rule base based on the first original data, enabling the rule base to be updated accordingly based on the iteration of network threats, thereby enhancing the anomaly detection capability. Therefore, collaborative work for anomaly detection between terminal devices and anomaly detection devices is achieved in the network environment. By leveraging the computing power of multiple terminal devices to extract the data to be detected, the amount of data reported to the anomaly detection device is reduced, thereby alleviating the receiving and processing pressure on the anomaly detection device, shortening the latency of obtaining anomaly detection results, and enabling the first terminal device to obtain anomaly detection results in more real-time, avoiding significant impact from anomalies on the first terminal device. Furthermore, by using anomaly detection devices to detect anomalies on multiple terminal devices in the network environment, there is no need for terminal devices to maintain corresponding rule bases locally, freeing up processing resources for terminal devices and improving the processing capacity of the network environment.

[0237] In addition to the data processing methods provided in the above embodiments, this application also provides a data processing apparatus.

[0238] See Figure 7 , Figure 7 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 7 As shown, the data processing device 700 is applied in a network environment including multiple terminal devices, the multiple terminal devices including target terminal devices, including: a collection unit 701, a filtering unit 702, a sending unit 703, an acquisition unit 704 and an extraction unit 705;

[0239] The acquisition unit 701 is used to acquire data to be detected related to the target terminal device and temporarily store the data to be detected locally on the target terminal device.

[0240] The screening unit 702 is used to perform normal data screening on the initial data features of the data to be detected, and to remove initial data features that are not related to anomaly detection from the initial data features to obtain data features;

[0241] The sending unit 703 is used to send the data features to the anomaly detection device in the network environment;

[0242] The acquisition unit 704 is used to acquire detection results for the data features from the anomaly detection device;

[0243] The extraction unit 705 is used to extract the target original data from the locally stored data to be detected based on its correlation with the target data if the detection result is a first result that identifies an anomaly. The first result is used to indicate the target data that caused the anomaly.

[0244] The sending unit 703 is used to send the target raw data to the anomaly detection device.

[0245] As one possible implementation, the data processing device 700 further includes a prompting unit for prompting an anomaly on the target terminal device based on the anomaly identified by the first result.

[0246] As one possible implementation, the data processing device 700 further includes a desensitization unit, used to desensitize sensitive features in the data features before sending the data features to the anomaly detection device in the network environment, the sensitive features being related to user privacy information.

[0247] As one possible implementation, the data processing device 700 further includes a deletion unit, used to delete the locally stored data to be detected after a preset time if the detection result is a second result indicating normality.

[0248] As one possible implementation, the data processing device 700 further includes a detection unit for:

[0249] Temporary detection rules are obtained from the anomaly detection device. These temporary detection rules are determined by the anomaly detection device based on the target original data corresponding to the detected target anomaly. The target terminal device is a terminal device that is associated with the target anomaly.

[0250] The detection results are obtained by detecting the local temporary data of the target terminal device based on the temporary detection rules, wherein the local temporary data includes the data to be detected;

[0251] The detection result is returned to the anomaly detection device.

[0252] As one possible implementation, the detection unit is used for:

[0253] A protection strategy is generated based on the aforementioned temporary detection rules;

[0254] The detection results are obtained by detecting the local temporary data of the target terminal device according to the protection strategy.

[0255] As can be seen from the above technical solution, for network environments with multiple terminal devices, each terminal device no longer loads its own rule base for detecting network threats. Taking the first terminal device as an example, the first terminal device extracts data from the data to be detected. The resulting data features not only characterize the features of the data to be detected but also reduce the amount of data. Therefore, the anomaly detection device performs corresponding anomaly detection based on the data features reported by the first terminal device and the rule base used for anomaly detection, reducing the computational load on the anomaly detection device while ensuring accuracy. If the detection result is the first result, it indicates that there is an anomaly in the data to be detected. The first result is returned to the first terminal device so that it can determine the target data causing the anomaly based on the first result. The first original data related to the target data is extracted from the data to be detected. Thus, the anomaly detection device can update the rule base based on the first original data, enabling the rule base to be updated accordingly based on the iteration of network threats, thereby enhancing the anomaly detection capability. Therefore, collaborative work for anomaly detection between terminal devices and anomaly detection devices is achieved in the network environment. By leveraging the computing power of multiple terminal devices to extract the data to be detected, the amount of data reported to the anomaly detection device is reduced, thereby alleviating the receiving and processing pressure on the anomaly detection device, shortening the latency of obtaining anomaly detection results, and enabling the first terminal device to obtain anomaly detection results in more real-time, avoiding significant impact from anomalies on the first terminal device. Furthermore, by using anomaly detection devices to detect anomalies on multiple terminal devices in the network environment, there is no need for terminal devices to maintain corresponding rule bases locally, freeing up processing resources for terminal devices and improving the processing capacity of the network environment.

[0256] In addition to the data processing methods provided in the above embodiments, this application also provides a data processing system.

[0257] See Figure 8 The figure is a schematic diagram of the structure of a data processing system provided in an embodiment of this application. The data processing system 800 includes a target terminal device 801 and an anomaly detection device 802.

[0258] The target terminal device 801 is used to collect data to be detected related to the target terminal device and temporarily store the data to be detected locally on the target terminal device; by performing normal data filtering on the initial data features of the data to be detected, the initial data features that are not related to anomaly detection are filtered out from the initial data features to obtain data features; and the data features are sent to the anomaly detection device in the network environment.

[0259] The anomaly detection device 802 is used to acquire the data features; perform corresponding anomaly detection according to the rule base for anomaly detection and the data type corresponding to the data features, and obtain a detection result; if the detection result is a first result that identifies an anomaly, return the first result to the target terminal device, wherein the first result is used to indicate the target data that caused the anomaly;

[0260] The target terminal device 801 is further configured to extract target original data from the locally stored data to be detected based on its correlation with the target data; and send the target original data to the anomaly detection device.

[0261] The anomaly detection device 802 is also used to update the rule base based on the target raw data.

[0262] As one possible implementation, the anomaly detection device 802 is further configured to return the second result to the target terminal device 801 if the detection result is a second result indicating normality, wherein the second result is used to instruct the target terminal device 801 to delete the locally stored data to be detected after a preset time.

[0263] As one possible implementation, if the target terminal device 801 is a first terminal device, the anomaly detection device 802 is further configured to:

[0264] Based on the first raw data, a second terminal device that is associated with the anomaly is determined from the plurality of terminal devices;

[0265] Send a temporary detection rule determined based on the first raw data to the second terminal device;

[0266] Obtain an anomaly detection result from the second terminal device, wherein the anomaly detection result is obtained by detecting the local temporary data of the second terminal device based on the temporary detection rule;

[0267] Based on the anomaly detection results, a threat trajectory corresponding to the anomaly is constructed.

[0268] Furthermore, the anomaly detection device 802 is also used for:

[0269] The second raw data is obtained from the second terminal device, which is extracted from the local temporary data of the second terminal device based on the anomaly detection result;

[0270] The rule base is updated based on the second original data.

[0271] As one possible implementation, the anomaly detection device 802 is used for:

[0272] Determine the data type corresponding to the data feature, wherein the data type includes at least one of file type, protocol feature type, or message sequence type;

[0273] If the data type corresponding to the data feature includes the text type, file matching rules are obtained from the rule base for anomaly detection, and anomaly detection is performed according to the file matching rules to obtain the first sub-detection result corresponding to the file type in the detection result. The file matching rules have a corresponding relationship with the executable file, rich text file or other file identified by the file type.

[0274] If the data type corresponding to the data feature includes the protocol feature type, the protocol matching rule is determined from the rule base for anomaly detection based on the malicious sample, and anomaly detection is performed according to the protocol matching rule to obtain the second sub-detection result corresponding to the protocol feature type in the detection result;

[0275] If the data type corresponding to the data feature includes the message sequence type, anomaly detection is performed based on the time sequence to obtain a third sub-detection result corresponding to the message sequence type in the detection result.

[0276] As one possible implementation, the target terminal device 801 is also configured to provide an error message to the target terminal device based on the anomaly identified by the first result.

[0277] As one possible implementation, the target terminal device 801 is further configured to de-identify sensitive features in the data features before sending the data features to the anomaly detection device in the network environment, the sensitive features being related to user privacy information.

[0278] As one possible implementation, the target terminal device 801 is further configured to delete the locally stored data to be detected after a preset time if the detection result is a second result indicating normality.

[0279] As one possible implementation, the target terminal device 801 is further configured to:

[0280] Temporary detection rules are obtained from the anomaly detection device. These temporary detection rules are determined by the anomaly detection device based on the target original data corresponding to the detected target anomaly. The target terminal device is a terminal device that is associated with the target anomaly.

[0281] The detection results are obtained by detecting the local temporary data of the target terminal device based on the temporary detection rules, wherein the local temporary data includes the data to be detected;

[0282] The detection result is returned to the anomaly detection device.

[0283] As one possible implementation, the target terminal device 801 is used for:

[0284] A protection strategy is generated based on the aforementioned temporary detection rules;

[0285] The detection results are obtained by detecting the local temporary data of the target terminal device according to the protection strategy.

[0286] As can be seen from the above technical solution, for network environments with multiple terminal devices, each terminal device no longer loads its own rule base for detecting network threats. Taking the first terminal device as an example, the first terminal device extracts data from the data to be detected. The resulting data features not only characterize the features of the data to be detected but also reduce the amount of data. Therefore, the anomaly detection device performs corresponding anomaly detection based on the data features reported by the first terminal device and the rule base used for anomaly detection, reducing the computational load on the anomaly detection device while ensuring accuracy. If the detection result is the first result, it indicates that there is an anomaly in the data to be detected. The first result is returned to the first terminal device so that it can determine the target data causing the anomaly based on the first result. The first original data related to the target data is extracted from the data to be detected. Thus, the anomaly detection device can update the rule base based on the first original data, enabling the rule base to be updated accordingly based on the iteration of network threats, thereby enhancing the anomaly detection capability. Therefore, collaborative work for anomaly detection between terminal devices and anomaly detection devices is achieved in the network environment. By leveraging the computing power of multiple terminal devices to extract the data to be detected, the amount of data reported to the anomaly detection device is reduced, thereby alleviating the receiving and processing pressure on the anomaly detection device, shortening the latency of obtaining anomaly detection results, and enabling the first terminal device to obtain anomaly detection results in more real-time, avoiding significant impact from anomalies on the first terminal device. Furthermore, by using anomaly detection devices to detect anomalies on multiple terminal devices in the network environment, there is no need for terminal devices to maintain corresponding rule bases locally, freeing up processing resources for terminal devices and improving the processing capacity of the network environment.

[0287] This application also provides a computer device, which is the computer device described above. This computer device can be a server or a terminal device, and the aforementioned data processing device can be built into the server or terminal device. The computer device provided in this application will be described below from the perspective of hardware implementation. Among them, Figure 9 The diagram shown is a schematic of the server's structure. Figure 10 The diagram shown is a structural schematic of the terminal device.

[0288] See Figure 9 This figure is a schematic diagram of a server structure provided in an embodiment of this application. The server 1400 can vary considerably due to different configurations or performance, and may include one or more Central Processing Units (CPUs) 1422 and memory 1432, and one or more application programs 1442 or data storage media 1430 (e.g., one or more mass storage devices). The memory 1432 and storage media 1430 can be temporary or persistent storage. The program stored in the storage media 1430 may include one or more modules (not shown in the figure), each module may include a series of instruction operations on the server. Furthermore, the CPU 1422 may be configured to communicate with the storage media 1430 and execute the series of instruction operations in the storage media 1430 on the server 1400.

[0289] Server 1400 may also include one or more power supplies 1426, one or more wired or wireless network interfaces 1450, one or more input / output interfaces 1458, and / or one or more operating systems 1441, such as Windows Server. TM Mac OS X TM Unix TM Linux TM FreeBSD TM etc.

[0290] The steps performed by the server in the above embodiments can be based on this Figure 9 The server structure shown.

[0291] CPU 1422 is used to perform the following steps:

[0292] The data features reported by the first terminal device among the plurality of terminal devices are obtained, and the data features are extracted based on the data to be detected in the first terminal device;

[0293] Based on the rule base used for anomaly detection and the data type corresponding to the data features, corresponding anomaly detection is performed to obtain the detection results;

[0294] If the detection result is a first result that identifies an anomaly, the first result is returned to the first terminal device, and the first result is used to indicate the target data that caused the anomaly.

[0295] Acquire first raw data sent by the first terminal device, wherein the first raw data is extracted from the data to be detected based on its correlation with the target data;

[0296] The rule base is updated based on the first original data.

[0297] Optionally, the CPU 1422 may also execute method steps of any specific implementation of the data processing method in the embodiments of this application.

[0298] See Figure 10 The figure is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. Figure 10 This diagram illustrates a partial structure of a smartphone related to the terminal device provided in this embodiment. The smartphone includes components such as a radio frequency (RF) circuit 1510, a memory 1520, an input unit 1530, a display unit 1540, a sensor 1550, an audio circuit 1560, a Wi-Fi module 1570, a processor 1580, and a power supply 1590. Those skilled in the art will understand that... Figure 10 The smartphone structure shown does not constitute a limitation on smartphones and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0299] The following is combined Figure 10 A detailed introduction to the various components of a smartphone:

[0300] The RF circuit 1510 can be used to receive and transmit signals during information transmission or calls. In particular, it receives downlink information from the base station and processes it with the processor 1580; in addition, it transmits uplink data to the base station.

[0301] The memory 1520 can be used to store software programs and modules, and the processor 1580 runs the software programs and modules stored in the memory 1520 to realize various functions and data processing of the smartphone.

[0302] Input unit 1530 can be used to receive input numeric or character information and generate key signal inputs related to user settings and function control of the smartphone. Specifically, input unit 1530 may include touch panel 1531 and other input devices 1532. Touch panel 1531, also known as a touch screen, can collect touch operations on or near the user and drive corresponding connected devices according to a pre-set program. In addition to touch panel 1531, input unit 1530 may also include other input devices 1532. Specifically, other input devices 1532 may include, but are not limited to, one or more of the following: physical keyboard, function keys (such as volume control buttons, power buttons, etc.), trackball, mouse, joystick, etc.

[0303] The display unit 1540 can be used to display information input by the user or information provided to the user, as well as various menus of the smartphone. The display unit 1540 may include a display panel 1541, which may optionally be configured as a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.

[0304] Smartphones may also include at least one sensor 1550, such as a light sensor, a motion sensor, and other sensors. Other sensors that smartphones may also be equipped with, such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, will not be detailed here.

[0305] Audio circuit 1560, speaker 1561, and microphone 1562 provide an audio interface between the user and the smartphone. Audio circuit 1560 converts received audio data into electrical signals and transmits them to speaker 1561, where speaker 1561 converts them into sound signals for output. On the other hand, microphone 1562 converts collected sound signals into electrical signals, which are received by audio circuit 1560, converted into audio data, and then processed by processor 1580 before being transmitted via RF circuit 1510 to, for example, another smartphone, or the audio data can be output to memory 1520 for further processing.

[0306] The processor 1580 is the control center of the smartphone, connecting various parts of the smartphone through various interfaces and lines. It performs various functions and processes data by running or executing software programs and / or modules stored in the memory 1520, and by calling data stored in the memory 1520. Optionally, the processor 1580 may include one or more processing units.

[0307] The processor 1580 is used to perform the following steps:

[0308] Collect the data to be detected related to the target terminal device, and temporarily store the data to be detected locally on the target terminal device;

[0309] By performing normal data filtering on the initial data features of the data to be detected, and removing initial data features that are irrelevant to anomaly detection from the initial data features, the data features are obtained.

[0310] The data features are sent to the anomaly detection device in the network environment;

[0311] Obtain detection results for the data features from the anomaly detection device;

[0312] If the detection result is a first result that identifies an anomaly, the original target data is extracted from the locally stored data to be detected based on its correlation with the target data. The first result is used to indicate the target data that caused the anomaly.

[0313] The target raw data is sent to the anomaly detection device.

[0314] Optionally, the processor 1580 may also execute method steps of any specific implementation of the data processing method in the embodiments of this application.

[0315] The smartphone also includes a power supply 1590 (such as a battery) that supplies power to various components. Preferably, the power supply can be logically connected to the processor 1580 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system.

[0316] Although not shown, smartphones may also include a camera, Bluetooth module, etc., which will not be described in detail here.

[0317] In this embodiment of the application, the memory 1520 included in the smartphone can store program code and transmit the program code to the processor.

[0318] This application also provides a computer-readable storage medium for storing a computer program that executes the data processing method provided in the above embodiments.

[0319] This application also provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the data processing methods provided in the various optional implementations of the above aspects.

[0320] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium can be at least one of the following media: read-only memory (ROM), RAM, magnetic disk, or optical disk, etc., and other media capable of storing program code.

[0321] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The device and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0322] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A data processing method, characterized in that, The method is applied in a network environment including multiple terminal devices, and the method includes: The data features reported by the first terminal device among the plurality of terminal devices are obtained. The data features are obtained by normal data filtering of the initial data features of the data to be detected temporarily stored locally in the first terminal device, and filtering out the initial data features that are not related to the anomaly. The data type of the data features includes at least one of file type, protocol feature type or message sequence type. Based on the rule base used for anomaly detection and the data type corresponding to the data features, corresponding anomaly detection is performed to obtain the detection results; If the detection result is a first result that identifies an anomaly, the first result is returned to the first terminal device, and the first result is used to indicate the target data that caused the anomaly. Acquire first raw data sent by the first terminal device, wherein the first raw data is extracted from the data to be detected based on its correlation with the target data; Update the rule base according to the first original data; Based on the first raw data, a second terminal device that is associated with the anomaly is determined from the plurality of terminal devices; Send a temporary detection rule determined based on the first raw data to the second terminal device; Obtain an anomaly detection result from the second terminal device, wherein the anomaly detection result is obtained by detecting the local temporary data of the second terminal device based on the temporary detection rule; Based on the anomaly detection results, a threat trajectory corresponding to the anomaly is constructed.

2. The method according to claim 1, characterized in that, The method further includes: If the detection result is a second result indicating normality, the second result is returned to the first terminal device. The second result is used to instruct the first terminal device to delete the locally stored data to be detected after a preset time.

3. The method according to claim 1, characterized in that, The method further includes: The second raw data is obtained from the second terminal device, which is extracted from the local temporary data of the second terminal device based on the anomaly detection result; The rule base is updated based on the second original data.

4. The method according to any one of claims 1-2, characterized in that, The step of performing anomaly detection based on the rule base used for anomaly detection and the data type corresponding to the data features, and obtaining the detection result, includes: Determine the data type corresponding to the data feature; If the data type corresponding to the data feature includes the file type, file matching rules are obtained from the rule base for anomaly detection, and anomaly detection is performed according to the file matching rules to obtain the first sub-detection result corresponding to the file type in the detection result. The file matching rules have a corresponding relationship with the executable file, rich text file or other file identified by the file type. If the data type corresponding to the data feature includes the protocol feature type, the protocol matching rule is determined from the rule base for anomaly detection based on the malicious sample, and anomaly detection is performed according to the protocol matching rule to obtain the second sub-detection result corresponding to the protocol feature type in the detection result; If the data type corresponding to the data feature includes the message sequence type, anomaly detection is performed based on the time sequence to obtain a third sub-detection result corresponding to the message sequence type in the detection result.

5. A data processing method, characterized in that, The method is applied in a network environment including multiple terminal devices, wherein the multiple terminal devices include a target terminal device, and the method includes: Collect the data to be detected related to the target terminal device, and temporarily store the data to be detected locally on the target terminal device; By performing normal data filtering on the initial data features of the data to be detected, and filtering out initial data features that are not related to anomaly detection from the initial data features, data features are obtained. The data type of the data features includes at least one of file type, protocol feature type or message sequence type. Send the data features to an anomaly detection device in the network environment; obtain the detection results for the data features from the anomaly detection device; If the detection result is a first result that identifies an anomaly, the original target data is extracted from the locally stored data to be detected based on its correlation with the target data. The first result is used to indicate the target data that caused the anomaly. Send the target raw data to the anomaly detection device; Temporary detection rules are obtained from the anomaly detection device. These temporary detection rules are determined by the anomaly detection device based on the target original data corresponding to the detected target anomaly. The target terminal device is a terminal device that is associated with the target anomaly. The detection results are obtained by detecting the local temporary data of the target terminal device based on the temporary detection rules, wherein the local temporary data includes the data to be detected; The detection result is returned to the anomaly detection device so that the anomaly detection device can construct the corresponding threat trajectory of the anomaly.

6. The method according to claim 5, characterized in that, The method further includes: An error message is displayed on the target terminal device based on the anomaly identified by the first result.

7. The method according to claim 5, characterized in that, Before sending the data features to the anomaly detection device in the network environment, the method further includes: Sensitive features in the data characteristics are anonymized, and these sensitive features are related to user privacy information.

8. The method according to claim 5, characterized in that, The method further includes: If the detection result is a normal second result, the locally stored data to be detected will be deleted after a preset time.

9. The method according to claim 8, characterized in that, The step of detecting the locally stored temporary data of the target terminal device based on the temporary detection rules to obtain the detection result includes: A protection strategy is generated based on the aforementioned temporary detection rules; The detection results are obtained by detecting the local temporary data of the target terminal device according to the protection strategy.

10. A data processing apparatus, characterized in that, The device is applied in a network environment including multiple terminal devices, and the device includes: an acquisition unit, an anomaly detection unit, a sending unit, and an update unit; The acquisition unit is used to acquire data features reported by the first terminal device among the plurality of terminal devices. The data features are obtained by normal data filtering of the initial data features extracted from the locally temporarily stored data to be detected in the first terminal device, and filtering out the initial data features that are not related to the anomaly. The data type of the data features includes at least one of file type, protocol feature type or message sequence type. The anomaly detection unit is used to perform corresponding anomaly detection based on the rule base for anomaly detection and the data type corresponding to the data feature, and obtain the detection result. The sending unit is configured to return the first result to the first terminal device if the detection result is a first result that identifies an anomaly, wherein the first result is used to indicate the target data that caused the anomaly. The acquisition unit is used to acquire first raw data sent by the first terminal device, wherein the first raw data is extracted from the data to be detected based on its correlation with the target data; The update unit is used to update the rule base according to the first original data; The data processing device further includes a threat trajectory construction unit, used for: Based on the first raw data, a second terminal device that is associated with the anomaly is determined from the plurality of terminal devices; Send a temporary detection rule determined based on the first raw data to the second terminal device; Anomaly detection results are obtained from the second terminal device, which are obtained by detecting the local temporary data of the second terminal device based on the temporary detection rules.

11. The apparatus according to claim 10, characterized in that, The data processing device further includes a deletion unit, which constructs a threat trajectory corresponding to the anomaly based on the anomaly detection result. If the detection result is a second result indicating normality, the deletion unit returns the second result to the first terminal device. The second result is used to instruct the first terminal device to delete the locally stored data to be detected after a preset time.

12. The apparatus according to claim 10, characterized in that, The update unit is further configured to: The second raw data is obtained from the second terminal device, which is extracted from the local temporary data of the second terminal device based on the anomaly detection result; The rule base is updated based on the second original data.

13. The apparatus according to any one of claims 10-11, characterized in that, The anomaly detection unit is also used for: Determine the data type corresponding to the data feature; If the data type corresponding to the data feature includes the file type, file matching rules are obtained from the rule base for anomaly detection, and anomaly detection is performed according to the file matching rules to obtain the first sub-detection result corresponding to the file type in the detection result. The file matching rules have a corresponding relationship with the executable file, rich text file or other file identified by the file type. If the data type corresponding to the data feature includes the protocol feature type, the protocol matching rule is determined from the rule base for anomaly detection based on the malicious sample, and anomaly detection is performed according to the protocol matching rule to obtain the second sub-detection result corresponding to the protocol feature type in the detection result; If the data type corresponding to the data feature includes the message sequence type, anomaly detection is performed based on the time sequence to obtain a third sub-detection result corresponding to the message sequence type in the detection result.

14. A data processing apparatus, characterized in that, The device is applied in a network environment including multiple terminal devices, the multiple terminal devices including target terminal devices, and the device includes: a collection unit, a filtering unit, a sending unit, an acquisition unit, and an extraction unit; The acquisition unit is used to acquire data to be detected related to the target terminal device and temporarily store the data to be detected locally on the target terminal device. The screening unit is used to perform normal data screening on the initial data features of the data to be detected, and to remove initial data features that are not related to anomaly detection from the initial data features to obtain data features. The data type of the data features includes at least one of file type, protocol feature type or message sequence type. The sending unit is used to send the data features to the anomaly detection device in the network environment; the acquiring unit is used to acquire the detection result for the data features from the anomaly detection device; the extraction unit is used to extract the target original data from the locally stored data to be detected based on the correlation with the target data if the detection result is a first result that identifies an anomaly, wherein the first result is used to indicate the target data that caused the anomaly. The sending unit is used to send the target raw data to the anomaly detection device; The data processing device further includes a detection unit for: Temporary detection rules are obtained from the anomaly detection device. These temporary detection rules are determined by the anomaly detection device based on the target original data corresponding to the detected target anomaly. The target terminal device is a terminal device that is associated with the target anomaly. The detection results are obtained by detecting the local temporary data of the target terminal device based on the temporary detection rules, wherein the local temporary data includes the data to be detected; The detection result is returned to the anomaly detection device so that the anomaly detection device can construct the corresponding threat trajectory of the anomaly.

15. The apparatus according to claim 14, characterized in that, The data processing device further includes a prompting unit, used to provide an error prompt to the target terminal device based on the anomaly identified by the first result.

16. The apparatus according to claim 14, characterized in that, The data processing device further includes a desensitization unit, used to desensitize sensitive features in the data features before sending the data features to the anomaly detection device in the network environment. The sensitive features are related to user privacy information.

17. The apparatus according to claim 14, characterized in that, The data processing device further includes a deletion unit, which is used to delete the locally stored data to be detected after a preset time if the detection result is a second result indicating normality.

18. The apparatus according to claim 17, characterized in that, The detection unit is used for: A protection strategy is generated based on the aforementioned temporary detection rules; The detection results are obtained by detecting the local temporary data of the target terminal device according to the protection strategy.

19. A data processing system, characterized in that, The data processing system includes target terminal equipment and anomaly detection equipment: The target terminal device is used to collect data to be detected related to the target terminal device and temporarily store the data to be detected locally on the target terminal device; by performing normal data filtering on the initial data features of the data to be detected, the initial data features that are not related to anomaly detection are filtered out from the initial data features to obtain data features, the data type of the data features including at least one of file type, protocol feature type or message sequence type; and the data features are sent to anomaly detection devices in the network environment. The detection results for the data features are obtained from the anomaly detection device; if the detection result is a first result that identifies an anomaly, the target original data is extracted from the locally stored data to be detected based on its correlation with the target data, and the first result is used to indicate the target data that caused the anomaly. Send the target raw data to the anomaly detection device; Temporary detection rules are obtained from the anomaly detection device. These temporary detection rules are determined by the anomaly detection device based on the target original data corresponding to the detected target anomaly. The target terminal device is a terminal device that is associated with the target anomaly. The detection results are obtained by detecting the local temporary data of the target terminal device based on the temporary detection rules, wherein the local temporary data includes the data to be detected; The detection result is returned to the anomaly detection device so that the anomaly detection device can construct the corresponding threat trajectory of the anomaly; The anomaly detection device is used to acquire data features reported by a first terminal device among multiple terminal devices. These data features are obtained by filtering initial data features of the data to be detected temporarily stored locally in the first terminal device, removing initial data features unrelated to anomalies. The data type of these data features includes at least one of file type, protocol feature type, or message sequence type. Anomaly detection is performed according to a rule base for anomaly detection and the data type corresponding to the data features to obtain a detection result. If the detection result is a first result identifying an anomaly, the first result is returned to the first terminal device, whereby the first result indicates the target data causing the anomaly. The process involves: acquiring first raw data sent by the first terminal device, wherein the first raw data is extracted from the data to be detected based on its correlation with the target data; updating the rule base based on the first raw data; and determining a second terminal device from the plurality of terminal devices that is associated with the anomaly based on the first raw data. Send a temporary detection rule determined based on the first raw data to the second terminal device; Obtain an anomaly detection result from the second terminal device, wherein the anomaly detection result is obtained by detecting the local temporary data of the second terminal device based on the temporary detection rule; Based on the anomaly detection results, a threat trajectory corresponding to the anomaly is constructed.

20. A computer device, characterized in that, The computer device includes a processor and memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to execute the method described in any one of claims 1-4, or to execute the method described in any one of claims 5-9, according to instructions in the program code.

21. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program for performing the method according to any one of claims 1-4, or for performing the method according to any one of claims 5-9.

22. A computer program product comprising instructions that, when run on a computer, cause the computer to perform the method of any one of claims 1-4, or the method of any one of claims 5-9.