Security detection method and apparatus, and device and storage medium
By determining the detection priority of log features and optimizing the detection sequence in security detection, the problem of low detection efficiency caused by large amount of data in the prior art is solved, and efficient and flexible security detection processing is achieved to adapt to data changes and real-time adjustments to threat environments.
Patent Information
- Application Number
- PCT/CN2024/138806
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-02
- Filing Date
- 2024-12-12
- Publication Date
- 2025-07-10
AI Technical Summary
The existing security detection methods require detection of all fields in the security log, resulting in large amounts of data and long time-consuming, making it difficult to cope with the analysis and processing needs of massive data, affecting the efficiency of security detection.
By obtaining the log feature set of security logs, the detection priority is determined based on the degree of abnormal correlation between log features, the priority is matched in the order of priority from high to low, and the detection order and resource allocation are optimized through the preset priority update strategy to achieve flexible security detection processing.
It improves the efficiency and accuracy of security detection, can adapt to data changes and real-time adjustments of threat environments, reduces unnecessary detection of low-risk characteristics, and improves overall detection efficiency and sensitivity.
Smart Images

Figure CN2024138806_10072025_PF_FP_ABST
Abstract
Description
A security detection method, device, equipment and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on January 2, 2024, with application number 202410001976.4 and application name "A security detection method, device, equipment and storage medium", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of network and information security technology, and provides a security detection method, device, equipment and storage medium. Background Art
[0004] With the rapid development of network information technology, the information security field is facing complex and changing threats such as network attacks, malware, abnormal traffic, etc. It is crucial to detect related threatening behaviors in a timely and effective manner.
[0005] Currently, existing security detection methods require testing all fields in security logs to identify possible threat behaviors. The amount of data to be tested is large, and the security detection efficiency is low.
[0006] Therefore, how to improve the efficiency of security detection is an urgent problem to be solved. Summary of the Invention
[0007] The embodiments of the present application provide a security detection method, apparatus, device and storage medium for improving security detection efficiency.
[0008] In one aspect, a security detection method is provided, comprising:
[0009] For each security log to be tested, iteratively perform security testing until a test result for each security log is obtained. Each security testing process includes:
[0010] Obtain the log feature set of the target security log;
[0011] Determining the detection priority of each log feature based on the confidence level of the log feature; the confidence level represents the degree of abnormal correlation between the corresponding log feature and other log features in the log feature set;
[0012] Based on a preset detection data set, matching the respective log features in descending order of detection priority;
[0013] Based on the obtained matching results and the preset priority update strategy, the detection priority of each log feature is updated, and the next security log is used as the target security log for the next security detection process.
[0014] In one aspect, an embodiment of the present application provides a safety detection device, comprising:
[0015] a processing unit, configured to iteratively perform security detection processing on each security log to be detected until a detection result of each security log is obtained;
[0016] The processing unit includes an acquisition subunit, a determination subunit, and a matching subunit, wherein:
[0017] The acquisition subunit is used to acquire a log feature set of a target security log;
[0018] The determination subunit is configured to determine a detection priority of each log feature based on the confidence level of the log feature; the confidence level represents the degree of abnormal correlation between the corresponding log feature and other log features in the log feature set;
[0019] The matching subunit is configured to match the log features based on a preset detection data set in descending order of detection priority;
[0020] The updating unit is used to update the detection priority of each log feature based on the obtained matching result and the preset priority update strategy, and use the next security log as the target security log for the next security detection process.
[0021] Optionally, the acquisition subunit is specifically configured to:
[0022] Extracting features from the target security log to obtain a corresponding candidate feature set;
[0023] Based on the support of each candidate feature, log features with support greater than a preset support threshold are screened out from the candidate feature set to obtain the log feature set; the support represents the ratio of the number of abnormal records of the corresponding candidate feature to the total number of abnormal records in the target security log.
[0024] Optionally, the determining subunit is specifically configured to:
[0025] Based on a preset confidence threshold, determining a preceding feature from each log feature; the confidence of the preceding feature is greater than the confidence threshold;
[0026] Based on the confidence of the preceding feature, and in accordance with a preset weight allocation strategy, a detection weight value of each preceding feature is determined; wherein the detection weight value of each preceding feature is greater than a preset value;
[0027] Based on the relative sizes of the detection weight values, the detection priority of each log feature is obtained.
[0028] Optionally, the determining subunit is specifically configured to:
[0029] Determining a maximum confidence and a minimum confidence from the confidences of the preceding features; and determining a first weight parameter based on a difference between the maximum confidence and the minimum confidence;
[0030] For each preceding feature, determining a second weight parameter based on a difference between the confidence of the preceding feature and the minimum confidence;
[0031] Based on the ratio between the second weight parameter and the first weight parameter, a detection weight value of the preceding feature is obtained.
[0032] Optionally, after determining the preceding feature from each log feature based on a preset confidence threshold, the determining subunit is further configured to:
[0033] Determining a subsequent feature among the log features; the confidence of the subsequent feature is less than the confidence threshold;
[0034] According to the preset weight distribution strategy, the detection weight value of each subsequent feature is determined to be the preset value.
[0035] On the one hand, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned security detection method when executing the program.
[0036] On the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program that can be executed by a computer device. When the program is run on the computer device, the computer device executes the steps of the above-mentioned security detection method.
[0037] On the one hand, an embodiment of the present application provides a computer program product, which includes a computer program stored on a computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer device, the computer device executes the steps of the above-mentioned security detection method.
[0038] In an embodiment of the present application, when performing security detection processing on each security log to be detected, a log feature set of the security log is obtained. The detection priority of each log feature is determined by the degree of abnormal correlation between each log feature and other log features in the log feature set, i.e., the confidence level of the log feature, to identify the importance of each log feature in the security detection processing process. This allows for flexible adjustment of the detection order of different log features, effectively allocates computing resources, prioritizes the detection of high-risk features, reduces unnecessary detection of low-risk features, and improves overall security detection efficiency. Each log feature is matched with a preset detection data set in descending order of detection priority. When it is determined that a log feature successfully matches the detection data set, it is determined that the log feature has a potential security threat. The detection priority of each log feature is updated using a preset priority update strategy, and the security detection processing described above is performed on the next security log using the updated detection priority. This fully utilizes real-time log data information and a cyclic feedback mechanism, and optimizes the next security detection processing based on the results of each security detection, so that the security detection processing can adapt to the latest data changes and the highly changing security threat environment, thereby improving the accuracy and sensitivity of security detection.
[0039] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0041] FIG1 is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0042] FIG2 is a schematic structural diagram of a safety detection system provided in an embodiment of the present application;
[0043] FIG3 is a schematic diagram of a flow chart of a safety detection method provided in an embodiment of the present application;
[0044] FIG4 is a schematic diagram of the structure of a transaction database provided in an embodiment of the present application;
[0045] FIG5 is a flow chart of another safety detection method provided in an embodiment of the present application;
[0046] FIG6 is a schematic structural diagram of a safety detection device provided in an embodiment of the present application;
[0047] FIG7 is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0048] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. Unless there is a conflict, the embodiments in the present application and the features in the embodiments can be combined with each other in any way. In addition, although a logical order is shown in the flowchart, in some cases, the steps shown or described can be performed in an order different from that here.
[0049] The terms "first" and "second" in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of its variations are intended to cover non-exclusive protection. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. "Multiple" in this application can mean at least two, for example, two, three or more, and the embodiments of this application are not limited thereto.
[0050] The term "and / or" in the embodiments of this application is simply a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent the following three situations: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0051] In the technical solutions of this application, the collection, dissemination, and use of data are in compliance with the requirements of relevant national laws and regulations. It is understood that in the following specific implementation methods of this application, when object-related data and the collection of related data are involved, when the various embodiments of this application are applied to specific products or technologies, relevant licenses or consents need to be obtained, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0052] To facilitate understanding of the technical solutions provided in the embodiments of the present application, some key terms used in the embodiments of the present application are explained here:
[0053] Intelligence collision: A security detection method that discovers potential threats and attack activities by comparing and matching security event information in security logs with predefined information in a threat intelligence library. It includes cross-validation of information from different data sources to identify patterns or characteristics related to known threats.
[0054] Threat intelligence database: A collection of information about computer network threats, attacks, vulnerabilities, and malicious activity. This information is typically compiled and maintained by security professionals, security companies, government agencies, or other security organizations. Data in a threat intelligence database can include known attack patterns, malware fingerprints, malicious IP addresses, and more.
[0055] Security log: Information about security events, operations, and operating status recorded by a system or network device. It contains information about user activities, system access, abnormal events, and other aspects, and is used for auditing, monitoring, and investigating security incidents.
[0056] Transactional database format: This refers to the process of organizing, cleaning, and deduplicating raw data according to specific specifications and structures, creating a database format suitable for transactional processing. In the security field, this format is often used to store cleansed security log data.
[0057] Advanced Persistent Threat (APT): A long-term, organized cyberattack targeting a specific target. APT attacks typically employ covert, persistent, and sophisticated methods to maintain a long-term presence in the target network.
[0058] Nginx: A high-performance open-source web server that can also be used as a reverse proxy server, load balancer, Hypertext Transfer Protocol (HTTP) cache, and email proxy server. Widely popular for its high performance, stability, and low resource consumption, many websites and applications use Nginx as part of their infrastructure.
[0059] Apache Flume: A distributed, reliable, and high-volume data streaming service that supports the reliable collection, aggregation, and movement of data in large-scale data streams, making the process of data moving from source to storage simple and reliable.
[0060] Apache Flink: A stream processing engine and distributed processing framework designed to handle large-scale streaming data. It provides high performance, fault tolerance, and exactly-once processing semantics, allowing users to process both unbounded and bounded data streams reliably and efficiently. Its features, including a flexible stream processing model, scalability, fault tolerance, and support for event time, make it a powerful tool for processing real-time data and widely used in both stream and batch processing scenarios.
[0061] Denial of Service / Distributed Denial of Service (Dos / DDos) traffic attack: A network attack method that uses a large number of legitimate distributed servers to send requests to the target, thereby preventing normal legitimate users from obtaining services. It mainly works by continuously sending a large number of attack packets with forged source addresses to the network service port, causing the half-open connection queue in the target server to be filled, thereby maliciously occupying the bandwidth and host resources of the target server, causing the network or system to be overloaded and paralyzed, and ceasing to provide normal network services.
[0062] The following is a brief introduction to the design concept of the embodiment of this application:
[0063] With the rapid development of network information technology, the information security field faces complex and diverse threats such as network attacks, malware, and abnormal traffic. Timely and effective detection of related threatening behaviors is crucial. However, existing security detection methods require testing all fields in security logs to identify potential threatening behaviors. For example, a global intelligence collision method is currently commonly used, matching each field in the security log with the corresponding field in the threat intelligence library until all fields are matched, obtaining the security detection result corresponding to the security log.
[0064] However, existing global intelligence collision methods require indiscriminate collision of all fields in security logs, resulting in large amounts of data to be processed. This makes it difficult to analyze and process massive amounts of data, leading to long security detection times and low security detection efficiency. Timeliness is crucial in data security. Valid information is only valuable for decision-making within a specific timeframe. For example, when dealing with network security threats, timely measures must be taken to mitigate potential damage. Delays in security decision-making can lead to serious information leaks and other consequences.
[0065] In view of the above technical problems, an embodiment of the present application proposes a security detection method. When performing security detection processing on each security log to be detected, a log feature set of the target security log is obtained, and the detection priority of each log feature is determined by the degree of abnormal correlation between each log feature and other log features in the log feature set, that is, the confidence of the log feature, to identify the importance of each log feature in the security detection processing process, thereby flexibly adjusting the detection order of different log features, effectively allocating computing resources, prioritizing key detection of high-risk features, reducing unnecessary detection of low-risk features, and improving overall security detection efficiency. In order of detection priority from high to low, each log feature is matched with the preset detection data set. When it is determined that the log feature matches the detection data set successfully, it is detected that the log feature has a potential security threat. The detection priority of each log feature is updated through the preset priority update strategy. The updated detection priority is used to perform the above-mentioned security detection processing on the next security log, so as to make full use of real-time log data information and the circular feedback mechanism, and optimize the next security detection processing with the result of each security detection, so that the security detection processing can adapt to the latest data changes and highly changing security threat environment, thereby improving the accuracy and sensitivity of security detection.
[0066] After introducing the design concepts of the embodiments of the present application, the following briefly introduces the application scenarios to which the technical solutions of the embodiments of the present application can be applied. It should be noted that the application scenarios introduced below are only used to illustrate the embodiments of the present application and are not limiting. In the specific implementation process, the technical solutions provided by the embodiments of the present application can be flexibly applied according to actual needs.
[0067] The solution provided by the embodiment of the present application can be applied to any business scenario involving security detection, including but not limited to application scenarios such as intelligence collision. As shown in Figure 1, an application scenario provided by the embodiment of the present application is schematically shown, in which a security detection device 100, a device to be detected 110, and a network 120 can be included.
[0068] Safety detection equipment 100 can be a computer device with certain processing power, such as mobile phone, personal computer (personal computer, PC), server etc. can be configured to perform any one of the method apparatus provided in the embodiment of the present application, and no longer exemplify them one by one here. For ease of description, hereinafter, the execution subject of the method is taken as an example of a server that can perform the method, and the embodiment of the method is introduced. It is understandable that the execution subject of the method is a server that is only an exemplary explanation and should not be construed as a limitation to the method. The server can be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN and the basic cloud computing services such as big data and artificial intelligence platforms, but is not limited thereto.
[0069] The device to be tested 110 is a computer device to be tested for the security detection method provided in the embodiment of the present application, such as a server, a router, a gateway device, etc. The server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms, but is not limited to this.
[0070] The security detection device 100 can obtain the log data generated by the various systems and network devices waiting for the detection device 110. The log data contains key information such as system operation status, security events and operation records, and based on the security detection method provided in the embodiment of the present application, it realizes security detection functions such as intelligence collision for the device to be detected 110.
[0071] The security detection device 100 and the device to be detected 110 can be connected through a network 120, which can be a wired network or a wireless network. For example, the wireless network can be a mobile cellular network, such as a fourth-generation mobile communication (4generation, 4G) network, a fifth-generation mobile communication (5generation, 5G) network or a new wireless (New Radio, NR) network, or a wireless fidelity (Wireless-Fidelity, WIFI) network. Of course, it can also be other possible networks, and the embodiments of the present invention are not limited to this.
[0072] In one possible implementation, in order to continuously monitor network security and provide real-time security threat intelligence, the security detection device 100 may be an intrusion detection system (IDS) and / or an intrusion prevention system (IPS). Based on the security detection method provided in the embodiment of the present application, the network traffic and network intrusion behavior recorded in the security log of the device to be detected are monitored in real time, and relevant features in the log data are analyzed to identify potential network intrusion behaviors. Security detection strategies such as intelligence collision strategies are dynamically adjusted according to the real-time analysis results to improve the efficiency and accuracy of identifying network intrusion behaviors.
[0073] In one possible implementation, the security detection device 100 can be used for abnormal traffic detection and defense. Based on the security detection method provided in the embodiment of the present application, it monitors network traffic and traffic patterns, identifies abnormal traffic behavior, and adjusts security detection strategies such as intelligence collision in real time according to normal traffic characteristics, implements traffic filtering and defense measures, and implements differentiated defense strategies for different types of network attacks to ensure network security and stability.
[0074] In one possible implementation, the security detection device 100 can be applied to malware detection and prevention. Based on the security detection method provided in the embodiment of the present application, by analyzing malicious activities and malware behaviors in log data, combined with the implementation of a threat intelligence library and a blacklist database, known malware features can be quickly and accurately detected, and security detection strategies such as intelligence collision can be dynamically adjusted to improve malware detection efficiency, timely update system defense strategies, implement malware isolation and removal, and improve the security and integrity of the network system.
[0075] In one possible implementation, the security detection device 100 can be used for real-time response and handling of network security incidents. Based on the security detection method provided in the embodiment of the present application, security logs and alarm information are monitored in real time, and security detection strategies are dynamically adjusted according to the urgency and threat level of the security incidents to optimize the incident response process and resource allocation method, thereby achieving faster handling of security incidents such as isolating affected systems, repairing vulnerabilities, and strengthening security defense measures.
[0076] In one possible implementation, the security detection device 100 can analyze security logs in real time based on the security detection method provided in the embodiment of the present application, continuously learn new network attack patterns and abnormal behaviors, and automatically adjust access control policies to ensure that only authorized users or authorized devices have access to sensitive data and critical systems.
[0077] It should be noted that what is shown in FIG1 is only an example. In fact, the number of safety detection devices and devices to be detected is not limited, and is not specifically limited in the embodiments of the present application.
[0078] FIG2 is a diagram showing the system architecture of a safety detection device according to an embodiment of the present invention, wherein the safety detection device specifically includes the following modules:
[0079] Analysis module: includes a data acquisition module and a real-time calculation module. The data acquisition module obtains the security logs generated in real time by various network systems, network devices and other detection devices from the application module, and transmits the security logs to the real-time calculation module. The real-time calculation module includes sub-modules such as preprocessing, priority calculation, and detection update. The preprocessing sub-module performs preprocessing on the security logs, such as data cleaning, deduplication, and data format conversion, and extracts log features from the security logs, and transmits the log features to the priority calculation sub-module. The priority calculation sub-module calculates the corresponding detection weight value of each log feature based on the confidence of each log feature, and assigns different detection priorities to each log feature according to the relative size of the detection weight value. The detection update sub-module updates the detection weight value and detection priority of the log feature based on the security detection results of each security log, and sends the updated results to the offline test module.
[0080] Specifically, the data acquisition module can transmit security log data through Ngnix to ensure that the data can be smoothly sent to the subsequent processing module. Once the log data is transmitted to the Flume service, the Flume service will be responsible for transmitting the log data to the real-time computing module. In order to ensure that the data is processed and updated on time and on demand, and to ensure real-time requirements, the real-time computing module in the embodiment of the present application can efficiently process large-scale data streams through Flink technology, and can convert the message queue data transmitted by the Flume service into a transaction data set to ensure that the data can be effectively processed and analyzed. The detection and update submodule can use a dynamically adjusted time window to perform accurate data analysis and updates according to a preset time span, ensure that data processing is carried out within a specific time period, optimize data processing efficiency, and thus provide flexible policy adjustment functions, so that relevant personnel can adjust the size of the time window and the update frequency according to specific needs, thereby improving the adaptability and applicability of the system.
[0081] Offline test module: Uses pre-stored historical data to evaluate the update results sent by the detection and update sub-module. When the test passes, that is, the quality and accuracy of the detection weight value and detection priority of each log feature are verified, an upload file is generated based on the latest detection priority and sent to the application module to ensure that subsequent data processing and updates can be carried out in accordance with the set standards.
[0082] Application Module: This module includes the online update module and the detection module. The online update module receives uploaded files from the offline test module and updates the security detection policy. Based on the updated security detection policy, the detection module performs intelligence collision detection and other processing on the data to be detected. For example, it performs intelligence collision operations on the data to be detected against the threat intelligence library and generates new log files.
[0083] It should be noted that the components and structures of the functional module architecture diagram shown in FIG2 are merely exemplary and non-restrictive, and other components and structures may be provided as needed in actual scenarios.
[0084] The following describes the security detection method provided by the exemplary embodiment of the present application in combination with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of the present application, and the implementation methods of the present application are not limited in this respect.
[0085] 3 is a flow chart of a security detection method provided in an embodiment of the present application. Here, a security detection device is used as an example for illustration. Since the embodiment of the present application iteratively performs security detection processing on each security log and obtains the detection result of each security log, the security detection processing process of each iteration is similar. Therefore, one iteration is used as an example for description. The specific implementation process of the method is as follows:
[0086] Step 301: Obtain a log feature set of a security log.
[0087] In this embodiment, security log data generated by each device under test is obtained from each device, and relevant log features are extracted from the security log for subsequent security detection and processing. The security log records key security detection information such as security events, operating status, and operation records related to the device under test. The security log can be used to detect whether the device poses a security risk.
[0088] In one possible implementation, the process of obtaining security logs from network devices, servers, or other devices to be tested can be accomplished by screening the security logs to ensure that each obtained security log contains key security events and operation records, thereby ensuring the comprehensiveness and accuracy of subsequent security testing.
[0089] Specifically, keywords can be set in advance and security logs can be filtered through regular expressions, string matching, etc., so that only log data containing preset keywords is retained, avoiding subsequent related processing of irrelevant log data, wasting computing resources, increasing computing redundancy, and reducing security detection efficiency.
[0090] In one possible implementation, before extracting log features from the security log, the present embodiment also performs data preprocessing on the security log, including but not limited to processing missing values, outliers, and duplicate records, as well as data cleaning, to ensure data integrity and consistency. The preprocessed log data is then converted into a consistent transaction database format (this embodiment uses an abstract representation and does not represent the final specific machine processing format) to avoid format inconsistencies or non-standard formats that could affect subsequent security detection and processing of the log features.
[0091] Specifically, the transaction database format stores preprocessed log data in a table format. Each table corresponds to a security log. A table contains multiple rows, each row corresponding to a security event or behavior record, and is divided into multiple columns, each representing field information of a different data type. As shown in Figure 4, each row in a security log table corresponds to a security event record and contains multiple columns such as a timestamp, event type, source Internet Protocol (IP) address, destination IP address, and event description. This transaction database structure provides a highly structured data storage method and supports complex data retrieval and processing operations using query languages such as Structured Query Language (SQL), facilitating query, association, and analysis.
[0092] In one possible implementation, in order to further improve the efficiency of security detection, the embodiment of the present application can initially extract candidate features from the security log, and further screen out log features with support greater than a preset support threshold through the support of each candidate feature, for subsequent security detection processing. The support represents the ratio of the number of abnormal records of the corresponding candidate feature to the total number of abnormal records in the log data. Therefore, the candidate feature with support less than the preset support threshold represents that it is not often abnormal, and may be noise data or a feature that is not often abnormal. Screening out such features helps reduce computational complexity and improve the efficiency and accuracy of security detection.
[0093] Specifically, the candidate feature set extracted from a security log is {x1, x2, ..., x n}, x i Taking the i-th candidate feature as an example, i is a positive integer greater than 0 and less than n, and n is the total number of log features contained in the log feature set. The support of each candidate feature is calculated using the preset support calculation formula, and log features with a support threshold greater than this value are filtered out. The support calculation formula is as follows:
[0094] Among them, S i Represents the i-th candidate feature x iThe corresponding support;
[0095] N represents the total number of abnormal records in the security log;
[0096] num i Represents the i-th candidate feature x i The number of corresponding abnormal records.
[0097] In one possible implementation, in order to avoid duplication of candidate features in a candidate feature set and to ensure that the candidate feature set contains all the data information of the security log, the embodiment of the present application will scan the security log data to identify frequently occurring single features, obtain a single feature set, and generate possible dual feature sets by combining the single feature sets. Through pruning operations, dual feature sets containing infrequent features are removed, and then N feature sets are generated from the dual feature sets and pruned until no N feature sets can be generated. The resulting N feature sets are then combined to obtain a candidate feature set.
[0098] Specifically, taking a simplified security log as an example, the security log contains the following records: {User A, operation: login, file access: file 1}, {User B, operation: logout, file access: file 2}, {User A, operation: logout, file access: file 1}, {User C, operation: login, file access: file 3}.
[0099] Step 1: Scan the security log to identify the single features that appear frequently in the entire security log: {User A}, {User B}, {User C}, {Operation: Login}, {Operation: Logout}, {File Access: File 1}, {File Access: File 2}, {File Access: File 3}.
[0100] Step 2: Generate possible dual-item feature sets based on the above single-item features. Here, we take user features as an example, including: {User A, User B}, {User A, User C}, {User B, User C}, {User A, Operation: Login}, {User A, Operation: Logout}, {User A, File Access: File 1}, {User B, Operation: Login}, {User B, Operation: Logout}, {User B, File Access: File 2}, {User C, Operation: Login}, {User C, Operation: Logout}, {User C, File Access: File 3}, {Operation: Login, Operation: Logout}, {Operation: Login, File Access: File 1}, {Operation: Logout, File Access: File 1}, {File Access: File 1, File Access: File 2}, {File Access: File 1, File Access: File 3}, {File Access: File 2, File Access: File 3}.
[0101] Step 3: Remove binary feature sets containing infrequent features through pruning. This can be accomplished by querying individual features. For example, if the subset {UserB} in the binary feature set {UserA, UserB} is not a frequently occurring feature, it can be determined that {UserA, UserB} is a binary feature set containing infrequent features and removed to ensure the completeness of the candidate feature set.
[0102] Step 4: Repeat the process of generating possible three-item feature sets using two-item features, and repeat the process of generating new N-item feature sets using (N-1) feature sets. Prune the feature sets containing infrequent features until no more N-item feature sets can be generated. For example, the three-item feature sets generated using two-item feature sets include {A,B}, {A,C}, {B,C}. The possible three-item feature sets generated are {A,B,C}, {A,B,D}, {A,C,D}, {B,C,D}. Check whether each subset of the three-item feature set is a frequent feature. After pruning, the following three-item feature sets {A,B,C}, {A,C,D} are retained.
[0103] Step 5: Based on the N feature sets obtained in the above process, a candidate feature set for the security log is generated. This is a possible feature set composed of features that frequently appear in the security log. This can be used to mine the correlation between log features and perform security event analysis.
[0104] Step 302: Determine the detection priority of each log feature based on the confidence level of the log feature.
[0105] In an embodiment of the present application, after extracting each log feature from the security log, the detection priority of each log feature will be determined separately by the confidence level representing the degree of abnormal correlation between the corresponding log feature and other log features, which will be used for subsequent security detection processing of each log feature based on the detection priority.
[0106] In one possible implementation, the embodiment of the present application can be based on a preset confidence threshold, and from each log feature, determine the preceding feature with a confidence greater than the confidence threshold, and filter the log features with lower confidence. Since the preceding feature has a strong correlation with other log features, that is, when the preceding feature is abnormal, other log features will most likely be affected and abnormal phenomena will occur. Therefore, the preceding feature with higher confidence has a higher security threat, and the attention of security detection needs to be focused on the preceding feature with higher confidence, so as to give priority to the features with more security threats and improve the accuracy and efficiency of detection. For each preceding feature, according to the preset weight allocation strategy and the confidence of each preceding feature, the detection weight value of each preceding feature is determined, and the detection weight value of each preceding feature is greater than the preset value. According to the relative size of the detection weight values of each preceding feature, the corresponding detection priority is assigned to each log feature, so that the detection priority of each log feature is adjusted in real time according to the change of the detection weight value, so that the security detection operation can quickly adapt to the new risk changes and improve the network security response capability.
[0107] Specifically, the log feature set extracted from a security log is {x1, x2, ..., x n}, x i Take the i-th log feature as an example, the confidence T ij It can be obtained by the following formula:
[0108] Among them, x i represents the i-th log feature in the log feature set, x j Represents the jth log feature in the log feature set; i and j are both positive integers greater than 0 and less than n, where n is the total number of log features contained in the log feature set;
[0109] T ij Represents the log feature x i When an exception occurs, the log feature x j The probability of anomalies occurring.
[0110] num i Represents the number of abnormal records corresponding to the i-th log feature in the log feature set;
[0111] num j Indicates the number of abnormal records corresponding to the jth log feature in the log feature set.
[0112] Furthermore, since the candidate feature xi may have a high abnormal correlation influence on multiple other log features, in order to determine whether the candidate feature is the preceding feature and calculate the corresponding detection weight value through confidence, it is necessary to accumulate all the confidences of the candidate feature xi to obtain the cumulative confidence sum Ai of the candidate feature xi. The calculation formula is as follows:
[0113] Among them, x i represents the i-th log feature in the log feature set, x j Represents the jth log feature in the log feature set; i and j are both positive integers greater than 0 and less than n, where n is the total number of log features contained in the log feature set;
[0114] A i Represents the cumulative sum of confidence scores corresponding to the i-th log feature in the log feature set;
[0115] T ij Represents the log feature x i When an exception occurs, the log feature x j The probability of anomalies occurring;
[0116] n represents the total number of log features in the log feature set corresponding to the security log.
[0117] Therefore, by using the confidence threshold to filter out the preceding features whose cumulative confidence sum Ai is greater than the confidence threshold from each log feature, it can be ensured that each preceding feature has other log features with abnormal correlation influence in the log feature set, that is, when each preceding feature is abnormal, there is at least one other log feature in the log feature set with a higher probability of abnormality.
[0118] In one possible implementation, in order to conveniently and accurately assign different detection weight values to each preceding feature, it is necessary to ensure that each preceding feature has the same dimension and dimensional unit. Therefore, after obtaining the cumulative confidence sum of each preceding feature, the embodiment of the present application will perform data normalization processing on the cumulative confidence sum of each preceding feature, and further perform feature scaling processing on the feature data to eliminate the dimensional influence between each preceding feature, so that each preceding feature has comparability, which facilitates comprehensive comparative evaluation of each preceding feature, thereby determining the detection weight value of each preceding feature according to the preset weight allocation strategy and the confidence of each preceding feature.
[0119] Specifically, the embodiment of the present application determines the maximum confidence and the minimum confidence from the confidence of each preceding feature, and determines the first weight parameter by the difference between the maximum confidence and the minimum confidence. For each preceding feature, the second weight parameter corresponding to each preceding feature is determined by the difference between the confidence of the preceding feature and the minimum confidence. The detection weight value of the preceding feature is obtained by the ratio between the second weight parameter and the first weight parameter of each preceding feature.
[0120] Specifically, the calculation formula for the detection weight value is as follows:
[0121] Among them, W i Represents the detection weight value of the i-th preceding feature in the log feature set, where i is a positive integer greater than 0 and less than n, and n is the total number of preceding features contained in the log feature set;
[0122] A i Represents the cumulative confidence sum corresponding to the i-th preceding feature in the log feature set;
[0123] A min Represents the minimum value of the cumulative confidence sum of the previous features;
[0124] A max Represents the maximum value of the cumulative confidence sum of the previous features.
[0125] In one possible implementation, after determining the antecedent feature whose confidence is greater than the confidence threshold, for the subsequent feature whose confidence is less than the confidence threshold, the detection weight value of each subsequent feature can be set to a preset value according to a preset weight distribution strategy. Since the detection weight value of each antecedent feature is greater than the preset value, it can be ensured that the detection priority of the subsequent feature is lower than that of all antecedent features.
[0126] Specifically, when it is determined based on the confidence level that the subsequent features do not have a high abnormal correlation impact on other logs, the detection weight of each subsequent feature can be set to weight 0, without completely excluding the possibility of detecting the subsequent feature. In this way, in the subsequent security detection process, if all the previous features fail to match the detection data set successfully, the subsequent features can be subjected to security detection processing to prevent special circumstances from causing security detection errors.
[0127] Step 303: Based on the preset detection data set, each log feature is matched in descending order of detection priority.
[0128] In an embodiment of the present application, after determining the detection priority of each log feature of the security log, each log feature will be matched with the corresponding data in the detection data set in order from high to low detection priority to determine whether the log feature successfully matches the field information in the detection data set to identify possible security threats in the security log.
[0129] Specifically, taking the detection data set that stores known malicious IP addresses, malicious ports, protocol types and other information as an example, the IP address, port number, protocol type and other log features of the security log are matched with the corresponding field information in the detection data set in sequence according to the detection priority order, so as to output the matching results. The matching results may include the matched threat type, related threat description, recommended response measures and other information.
[0130] Step 304: Based on the obtained matching results and the preset priority update strategy, the detection priority of each log feature is updated.
[0131] In an embodiment of the present application, in the process of matching each log feature in order of detection priority from high to low, the detection priority of each log feature can be updated according to the result of each matching, thereby making full use of real-time log data information and a loop feedback mechanism, and optimizing the next security detection processing with the result of each security detection, so that the security detection processing can adapt to the latest data changes and highly changing security threat environments, thereby improving the accuracy and sensitivity of security detection.
[0132] Specifically, when the matching result indicates that the corresponding log feature successfully matches the detection data set, the detection weight value of each log feature can be updated through a preset weight update formula. The weight update formula is as follows: W i =α*(W i +k*C)
[0133] Among them, W i Represents the detection weight value of the i-th log feature in the log feature set, where i is a positive integer greater than 0 and less than n, and n is the total number of log features contained in the log feature set.
[0134] α is a weighting coefficient used to weight each log feature to ensure that the sum of the detection weights of each log feature after weighting is still 1. α can be a constant or adjusted according to actual conditions, that is, the original weight of each log feature is W = {W1, W2, ..., W n}, the updated weight W after one match · W · ={W · 1,W · 2,…,W · n}={αW1,αW2,…,αW n}.
[0135] k is an adjustable parameter used to adjust the degree of influence of confidence on log features during this weight update process. The k value needs to be set according to actual conditions to ensure that the influence of confidence on the update of the detection weight value of log features meets actual needs.
[0136] Step 305: Perform security detection processing on the next security log according to the latest detection priority.
[0137] In the embodiment of the present application, the priority of each log feature is updated according to the security detection result of each security log for the next security detection process.
[0138] In one possible embodiment, the termination condition for the iterative security detection process in the embodiment of the present application includes: during the current security detection process, all log features contained in the security log are matched, and if all log feature matches fail, an empty set is returned, and there is no need to update the detection weight value of the log feature. Alternatively, once a log feature match is successful, the weight update operation of step 304 is performed to obtain and return the updated detection weight value and the current matching result, so that threat intelligence or security analysis reports can be generated based on the matching results to help relevant personnel understand the current security threat status of the device to be detected and take corresponding security protection measures and response strategies to improve the security of the device.
[0139] The following describes the solution of the embodiment of the present application with reference to a specific example in an APT scenario. Referring to FIG5 , the specific implementation process of the method is as follows:
[0140] Step 501: Obtain the security log data of the APT.
[0141] Specifically, the characteristic data of the APT security log is preprocessed by data cleaning, processing missing values, outliers, and duplicate records to ensure the accuracy and completeness of the data, and converting the original characteristic data information into a transaction database format suitable for subsequent analysis (this embodiment uses abstract expression and does not represent the final specific machine processing format).
[0142] Step 502: Extract features from the security log data to obtain a candidate feature set.
[0143] Specifically, the candidate feature set may include but is not limited to: {{input parameter},…,{access time},…,{input parameter, output parameter},…,{file access record, access time},…,{input parameter, output parameter, link tracking number},…,{process record, file access record, access time},…,{input parameter, output parameter, link tracking number, user request},…,{user request, process record, file access record, access time}.
[0144] Step 503: Based on the support of the log features, a log feature set is selected from the candidate feature set.
[0145] Specifically, the support threshold is set to 0.4, and the support calculation formula is Calculate the support of each log feature, and select the log features with support greater than 0.4 from the candidate feature set as {{input parameter, output parameter, link tracking number, user request}, {input parameter, output parameter, link tracking number, process activity}, {input parameter, link tracking number, user request, process activity}, {link tracking number, user request, process activity, file access record}.
[0146] Step 504: Determine the detection priority of each log feature based on the accumulated confidence of the log features.
[0147] Specifically, we set the confidence threshold to 0.6 and, using the confidence calculation formula, select the preceding features {input parameter}, {link tracking number} with a confidence greater than 0.6 from the log feature set. We then determine the detection weight for each preceding feature using the detection weight calculation formula, while assigning a weight of 0 to each subsequent feature. We then assign a detection priority to each log feature based on its detection weight.
[0148] Step 505: Match each log feature in descending order of detection priority.
[0149] Step 506: When the match is successful, the detection priority of each log feature is updated.
[0150] Specifically, when a log feature is determined to be matched successfully in sequence, the detection weight value of each log feature is recalculated according to the weight update formula, and the detection priority of each log feature is dynamically updated through a loop feedback mechanism.
[0151] Step 507: Perform security detection processing on the next security log according to the latest detection priority.
[0152] Referring to FIG. 6 , based on the same inventive concept, an embodiment of the present application further provides a safety detection device 60 , which includes:
[0153] The processing unit 601 is configured to iteratively perform security detection processing on each security log to be detected until a detection result of each security log is obtained;
[0154] The processing unit includes an acquisition subunit 6011, a determination subunit 6012, and a matching subunit 6013, wherein:
[0155] The acquisition subunit 6011 is used to obtain a log feature set of a target security log;
[0156] The determination subunit 6012 is configured to determine the detection priority of each log feature based on the confidence level of the log feature; the confidence level indicates the degree of abnormal correlation between the corresponding log feature and other log features in the log feature set;
[0157] The matching subunit 6013 is used to match each log feature based on a preset detection data set in descending order of detection priority;
[0158] The updating unit 602 is configured to update the detection priority of each log feature based on the obtained matching result and a preset priority update strategy, and use the next security log as the target security log for the next security detection process.
[0159] Optionally, the acquisition subunit 6011 is specifically used to:
[0160] Extract features from the target security log to obtain the corresponding candidate feature set;
[0161] Based on the support of each candidate feature, log features with support greater than a preset support threshold are screened out from the candidate feature set to obtain a log feature set; the support represents the ratio of the number of abnormal records of the corresponding candidate feature to the total number of abnormal records in the target security log.
[0162] Optionally, the determination subunit 6012 is specifically configured to:
[0163] Based on a preset confidence threshold, determine the preceding feature from each log feature; the confidence of the preceding feature is greater than the confidence threshold;
[0164] Based on the confidence of the preceding feature, the detection weight value of each preceding feature is determined according to a preset weight distribution strategy; wherein the detection weight value of each preceding feature is greater than a preset value;
[0165] Based on the relative sizes of the detection weight values, the detection priority of each log feature is obtained.
[0166] Optionally, the determination subunit 6012 is specifically configured to:
[0167] Determining a maximum confidence and a minimum confidence from the confidences of the preceding features; and determining a first weight parameter based on a difference between the maximum confidence and the minimum confidence;
[0168] For each preceding feature, determining a second weight parameter based on a difference between the confidence level of the preceding feature and the minimum confidence level;
[0169] Based on the ratio between the second weight parameter and the first weight parameter, a detection weight value of the preceding feature is obtained.
[0170] Optionally, after determining the preceding feature from each log feature based on a preset confidence threshold, the determining subunit 6012 is further configured to:
[0171] Determine the subsequent feature in each log feature; the confidence of the subsequent feature is less than the confidence threshold;
[0172] According to the preset weight distribution strategy, the detection weight value of each subsequent feature is determined to be the preset value.
[0173] By means of the above-mentioned device, when security detection processing is performed on each security log to be detected, a log feature set of the target security log is obtained, and the detection priority of each log feature is determined by the degree of abnormal correlation between each log feature and other log features in the log feature set, i.e., the confidence of the log feature, so as to identify the importance of each log feature in the security detection processing process, thereby flexibly adjusting the detection order of different log features, effectively allocating computing resources, giving priority to key detection of high-risk features, reducing unnecessary detection of low-risk features, and improving the overall security detection efficiency. In descending order of detection priority, each log feature is matched with a preset detection data set. When it is determined that the log feature successfully matches the detection data set, it is detected that the log feature has a potential security threat. The detection priority of each log feature is updated according to the preset priority update strategy, so that the security detection processing described above is performed on the next security log using the updated detection priority, so as to make full use of real-time log data information and a circular feedback mechanism, and optimize the next security detection processing based on the results of each security detection, so that the security detection processing can adapt to the latest data changes and the highly changing security threat environment, and improve the accuracy and sensitivity of security detection.
[0174] For the convenience of description, the above sections are divided into unit modules (or modules) according to their functions and described separately. Of course, when implementing this application, the functions of each unit (or module) can be implemented in the same or multiple software or hardware. The device can be used to execute the methods shown in the embodiments of this application. Therefore, for the functions that can be implemented by each functional module of the device, please refer to the description of the aforementioned embodiments, and no further details will be given.
[0175] Referring to FIG. 7 , based on the same technical concept, an embodiment of the present application further provides a computer device. In one embodiment, the computer device may be, for example, the security detection device shown in FIG. 1 or the security detection system shown in FIG. 2 . As shown in FIG. 7 , the computer device may include a memory 701, a communication module 703, and one or more processors 702.
[0176] The memory 701 is used to store computer programs executed by the processor 702. The memory 701 may mainly include a program storage area and a data storage area. The program storage area may store an operating system; the data storage area may store various operating instruction sets.
[0177] Memory 701 may be a volatile memory, such as random-access memory (RAM); a non-volatile memory, such as read-only memory, flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 701 may be a combination of the above memories.
[0178] The processor 702 may include one or more central processing units (CPUs) or digital processing units, etc. The processor 702 is configured to implement the above security detection method when calling the computer program stored in the memory 701 .
[0179] The communication module 703 is used to communicate with a data sending device, a data receiving device or other network devices.
[0180] The specific connection medium between the memory 701, communication module 703, and processor 702 is not limited in the embodiments of the present application. In Figure 7, the memory 701 and processor 702 are connected via bus 704. Bus 704 is depicted as a bold line in Figure 7. The connection methods between other components are merely illustrative and are not intended to be limiting. Bus 704 can be divided into an address bus, a data bus, a control bus, etc. For ease of description, Figure 7 depicts only one bold line, but this does not indicate that there is only one bus or only one type of bus.
[0181] The memory 701 stores a computer storage medium, which stores computer executable instructions for implementing the security detection method of the embodiment of the present application. The processor 702 is used to execute the security detection method of each of the above embodiments.
[0182] Based on the same inventive concept, an embodiment of the present application also provides a storage medium on which a computer program is stored. When the computer program instructions are executed on a computer, the computer processor executes the steps of the security detection method according to various embodiments of the present application described above in this specification.
[0183] In some possible implementations, various aspects of the security detection method provided in the present application can also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to enable the computer device to execute the steps of the security detection method according to various exemplary embodiments of the present application described above in this specification. For example, the computer device can execute the steps of each embodiment.
[0184] The program product may employ any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0185] The program product of the embodiment of the present application may be a portable compact disc read-only memory (CD-ROM) and include program code, and can be run on a computing device. However, the program product of the present application is not limited thereto. In the present application, a readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with a command execution system, device, or apparatus.
[0186] A readable signal medium may include a data signal transmitted in baseband or as part of a carrier wave, which carries readable program code. Such a transmitted data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with a command execution system, apparatus, or device.
[0187] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0188] The program code for performing the operations of the present application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user equipment, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).
[0189] It should be noted that although several units or subunits of the device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, depending on the embodiment of the application, the features and functions of two or more units described above can be embodied in a single unit. Conversely, the features and functions of a single unit described above can be further divided and embodied by multiple units.
[0190] Furthermore, although the operations of the method of the present application are described in a particular order in the accompanying drawings, this does not require or imply that the operations must be performed in this particular order, or that all illustrated operations must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.
[0191] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0192] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.
[0193] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A security detection method, characterized in that, The method includes: Iteratively performing security detection processing on each security log to be detected until the detection results of each security log are obtained; wherein, each security detection processing includes: Obtaining a log feature set of the target security log; Determining the detection priorities of the respective log features based on the confidence levels of the log features; the confidence level represents the degree of abnormal association between the corresponding log feature and other log features in the log feature set; Based on a preset detection data set, matching the respective log features in descending order of the detection priorities; Updating the detection priorities of the respective log features based on the obtained matching results and a preset priority update strategy, and using the next security log as the target security log for the next security detection processing.
2. The method according to claim 1, characterized in that, The obtaining of the log feature set of the target security log includes: Performing feature extraction on the target security log to obtain a corresponding candidate feature set; Filtering out the log features with support degrees greater than a preset support degree threshold from the candidate feature set based on the support degree of each candidate feature to obtain the log feature set; the support degree represents the ratio of the number of abnormal records of the corresponding candidate feature to the total number of abnormal records of the target security log.
3. The method according to claim 1, characterized in that The determining of the detection priorities of the respective log features based on the confidence levels of the log features includes: Determining leading features from the respective log features based on a preset confidence level threshold; the confidence levels of the leading features are greater than the confidence level threshold; Determining the detection weight values of each leading feature according to a preset weight assignment strategy based on the confidence levels of the leading features; wherein, the detection weight values of each leading feature are all greater than a preset value; Obtaining the detection priorities of the respective log features based on the relative magnitudes among the respective detection weight values.
4. The method according to claim 3, wherein The determining of the detection weight values of each leading feature according to a preset weight assignment strategy based on the confidence levels of the leading features includes: Determining the maximum confidence level and the minimum confidence level from the confidence levels of the respective leading features; and determining a first weight parameter based on the difference between the maximum confidence level and the minimum confidence level; For each leading feature, determining a second weight parameter based on the difference between the confidence level of the leading feature and the minimum confidence level; Obtaining the detection weight value of the leading feature based on the ratio between the second weight parameter and the first weight parameter.
5. The method according to claim 3, characterized in that, After determining the leading features from the respective log features based on a preset confidence level threshold, the method further includes: Determining trailing features among the respective log features; the confidence levels of the trailing features are less than the confidence level threshold; Determining the detection weight value of each trailing feature as a preset value according to a preset weight assignment strategy.
6. A safety detection device, characterized in that, The device includes: A processing unit for iteratively performing security detection processing on each security log to be detected until the detection results of each security log are obtained; The processing unit includes an acquisition subunit, a determination subunit, a matching subunit, and an update subunit, wherein: The acquisition subunit is used to obtain a log feature set of the target security log; The determining subunit is configured to determine the detection priorities of the respective log features based on the confidence levels of the log features; the confidence level represents the degree of abnormal association between the corresponding log feature and other log features in the log feature set; The matching subunit is configured to match the respective log features in descending order of the detection priorities based on a preset detection data set; The updating subunit is configured to update the detection priorities of the respective log features based on the obtained matching results and a preset priority updating policy, and use the next security log as the target security log for the next security detection process.
7. The device according to claim 6, characterized in that, The determining subunit is specifically configured to: Determine leading features from the respective log features based on a preset confidence level threshold; the confidence level of the leading features is greater than the confidence level threshold; Determine the detection weight value of each leading feature according to a preset weight allocation policy based on the confidence level of the leading features; wherein the detection weight value of each leading feature is greater than a preset value; Obtain the detection priorities of the respective log features based on the relative magnitudes between the respective detection weight values.
8. A computer device, characterized in that, Comprising: At least one processor, and A memory connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the at least one processor executes the instructions stored in the memory to perform the method according to any one of claims 1-5.
9. A computer storage medium, characterized in that, The computer-readable storage medium is used to store a computer program, and when the computer program runs on a computer, the computer is caused to execute the method according to any one of claims 1-5.
10. A computer program product, comprising computer program instructions, characterized in that When the computer program instructions are executed by a processor, the steps of the method according to any one of claims 1-5 are implemented.
Citation Information
Patent Citations
Log classification method and device
CN112199344A
Association rule mining method and device, computer equipment and storage medium
CN114064723A
Weblog analysis method and device, electronic equipment and readable medium
CN115905149A
Log collecting and filtering method and device, equipment and medium
CN116760682A
Security detection method and device, equipment and storage medium
CN117978450A