Alarm information processing method and system, and device and medium

By obtaining the features of alarm information in the network threat detection system and matching them with plug-ins, using multiple plug-ins to obtain auxiliary information and perform deep learning analysis, the problem of poor readability of alarm information in the existing technology is solved, and detailed and accurate alarm interpretation is achieved.

WO2025200496A1PCT designated stage Publication Date: 2025-10-02BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/132689
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-25
Filing Date
2024-11-18
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing network threat detection systems generate a large number of alarm messages with poor readability, making it difficult to provide detailed and accurate interpretations, leading to difficulties for operations and maintenance personnel in making decisions.

Method used

By obtaining features from network threat detection results and matching them with target plug-ins, auxiliary information is obtained using plug-ins such as Internet search, URL encoding and decoding, and threat intelligence search, and then input into the target model for deep learning analysis to generate detailed interpretation results.

Benefits of technology

Improves the comprehensiveness and accuracy of alarm interpretation, provides easy-to-understand interpretation results, and helps users respond quickly.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024132689_02102025_PF_FP_ABST
    Figure CN2024132689_02102025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are an alarm information processing method and system, and a device and a medium. The method comprises: acquiring a first network traffic analysis result, wherein the first network traffic analysis result comprises at least one piece of alarm information; in response to that a feature comprised in the at least one piece of alarm information matches a target plug-in, acquiring first auxiliary information on the basis of the target plug-in; sending to a first target model first prompt information generated at least on the basis of the first network traffic analysis result and the first auxiliary information, and receiving an interpretation result generated by the first target model with regard to the first network traffic analysis result; and presenting the interpretation result.
Need to check novelty before this filing date? Find Prior Art

Description

Alarm information processing method, system, device and medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on March 25, 2024, with application number 202410346221.8 and invention name “A method, system, device and medium for processing alarm information”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of network security technology, and in particular to an alarm information processing method, system, electronic device, and computer-readable storage medium. Background Art

[0004] With the rapid development of network technology, network traffic analysis (NTA) systems have emerged. These systems analyze network traffic or logs to detect potential threats by combining rule-based detection techniques with machine learning and signature analysis. Summary of the Invention

[0005] In a first aspect, the present application provides a method for processing alarm information, the method comprising:

[0006] Obtaining a first network threat detection result, where the first network threat detection result includes at least one piece of alarm information;

[0007] In response to a feature included in the at least one piece of alarm information matching a target plug-in, obtaining first auxiliary information based on the target plug-in;

[0008] Sending first prompt information generated based at least on the first network threat detection result and the first auxiliary information to a first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result;

[0009] The interpretation results are presented.

[0010] In a second aspect, the present application provides an alarm information processing system, the system comprising:

[0011] A first acquisition module is configured to acquire a first network threat detection result, where the first network threat detection result includes at least one piece of alarm information;

[0012] a second acquisition module, configured to, in response to a feature included in the at least one piece of alarm information matching a target plug-in, acquire first auxiliary information based on the target plug-in;

[0013] a communication module, configured to send first prompt information generated based at least on the first network threat detection result and the first auxiliary information to a first target model, and receive an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result;

[0014] A presentation module is used to present the interpretation result.

[0015] In a third aspect, the present application provides an electronic device, comprising a processor and a memory. The processor and the memory communicate with each other. The processor is configured to execute instructions stored in the memory, so that the electronic device performs the alarm information processing method according to the first aspect or any implementation of the first aspect.

[0016] In a fourth aspect, the present application provides a computer-readable storage medium, in which instructions are stored, and the instructions instruct an electronic device to execute the alarm information processing method described in the above-mentioned first aspect or any implementation method of the first aspect.

[0017] In a fifth aspect, the present application provides a computer program product comprising instructions, which, when executed on an electronic device, enables the electronic device to execute the alarm information processing method described in the first aspect or any one of the implementations of the first aspect.

[0018] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical methods of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments.

[0020] FIG1 is a flow chart of a method for processing alarm information provided in an embodiment of the present application;

[0021] FIG2 is a schematic diagram of a process for obtaining second auxiliary information according to an embodiment of the present application;

[0022] FIG3 is a schematic diagram of a flow chart of an interpretation result generation process provided by an embodiment of the present application;

[0023] 4A and 4B are schematic diagrams of a network threat detection page provided in an embodiment of the present application;

[0024] FIG5 is a schematic diagram of a database synchronization process provided by an embodiment of the present application;

[0025] FIG6 is a schematic diagram of the structure of an alarm information processing system provided in an embodiment of the present application;

[0026] FIG7 is a schematic structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0027] The terms "first" and "second" in the embodiments of this application are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Therefore, features specified as "first" or "second" may explicitly or implicitly include one or more of the features.

[0028] First, some technical terms involved in the embodiments of this application are introduced.

[0029] With the rapid development of network technology, network security issues have become increasingly prominent. Network traffic analysis (NTA) systems have emerged and are widely used in many fields.

[0030] The network threat detection system combines rule-based detection technology with machine learning, feature analysis and other technologies to analyze network traffic or network logs to detect potential threats in the network.

[0031] Network threat detection systems can generate alerts for potential threats. However, since network threat detection systems typically rely on predefined alert rules to identify potential threats, and given the complexity and variability of network traffic, the generated alerts are often numerous and difficult to read.

[0032] In related technologies, network security professionals typically pre-configure information such as alert rules, alert types, and action suggestions. By matching specific fields within the alert information, the alert rules and alert types can be determined, and the corresponding action suggestions can be determined, generating an interpretation result.

[0033] However, because these approaches rely on pre-configured alert rules, alert types, and action suggestions, the resulting interpretations are often brief and repetitive, making it difficult to provide detailed interpretations of different alerts. Furthermore, their accuracy and comprehensiveness are limited, making it difficult for operations and maintenance personnel to make decisions and respond to alerts.

[0034] In view of this, the present application provides a method for processing alarm information. The method first obtains a first network threat detection result, wherein the first network threat detection result includes at least one alarm message, and in response to a feature included in the at least one alarm message matching a target plug-in, obtains first auxiliary information based on the target plug-in, then sends first prompt information generated based on at least the first network threat detection result and the first auxiliary information to a first target model, receives an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate an interpretation result, and then presents the interpretation result.

[0035] Before interpreting the network threat detection results, this method first determines whether the alert contains features that match the plugin. If the features in the alert match the target plugin, the target plugin retrieves auxiliary information. This information, along with the network threat detection results, is then fed into the target model. This auxiliary information allows the target model to conduct targeted analysis of the alert, improving the comprehensiveness and accuracy of the alert interpretation.

[0036] To facilitate understanding of the technical solutions provided in the embodiments of the present application, they will be described below with reference to the accompanying drawings.

[0037] Referring to FIG. 1 , a flowchart of a method for processing alarm information provided by an embodiment of the present application is shown. The method specifically includes:

[0038] S101: Obtain a first network threat detection result.

[0039] The first network threat detection result can be understood as the result of a network security test. In some possible implementations, the first network threat detection result can be generated by a network threat detection system. In other words, a user can use the network threat detection system to test the network security status, and after the network threat detection system completes the test, the first network threat detection result can be generated.

[0040] In some embodiments, the network threat detection system can be a software system. For example, the network threat detection system can be a software system deployed locally or online. In this case, the server provided in the embodiment of the present application for executing the alarm information processing method can be connected to the network threat detection system in the form of a plug-in, cloud service, etc.

[0041] In an embodiment of the present application, the first network threat detection result may include at least one piece of alarm information. The alarm information may refer to information used to describe a network security threat event, for example, the alarm information may include information such as the alarm time, alarm type, alarm data, protocol, and Internet Protocol (IP) address.

[0042] That is, the network threat detection system can analyze and detect network traffic or network logs, detect network security threat events, and generate a first network threat detection result in the form of an alarm message. By viewing the first network threat detection result, the user can obtain the current network security status.

[0043] Considering that the first network threat detection result generated by the network threat detection system often contains many network-related professional terms and codes, which are difficult to read, in an embodiment of the present application, the server can obtain the first network threat detection result so as to subsequently process the first network threat detection result.

[0044] In a specific implementation, the first network threat detection result may be obtained in response to a triggering operation on a preset control in the network threat detection page.

[0045] The network threat detection page is used to present the first network threat detection result. In other words, the network threat detection page may be a page provided by the network threat detection system, and the user may view the first network threat detection result through the network threat detection page.

[0046] In an embodiment of the present application, a preset control is provided on the network threat detection page, and the preset control can be used to trigger the interpretation of the first network threat detection result. For example, a user can trigger the generation of an interpretation result of the first network threat detection result by clicking the preset control. For another example, a user can trigger the generation of an interpretation result of the first network threat detection result by sliding down the preset control. For another example, when the device used by the user supports voice interaction, the user can trigger the generation of an interpretation result of the first network threat detection result by sending a voice command.

[0047] That is to say, the user can directly trigger the interpretation of the first network threat detection result through the preset control on the network threat detection page, realizing "one-click interpretation", simplifying the user interaction process and improving the user interaction efficiency.

[0048] S102: In response to a feature included in at least one piece of alarm information matching a target plug-in, obtaining first auxiliary information based on the target plug-in.

[0049] The plug-in can be understood as a tool for processing warning information to generate auxiliary information. The target plug-in can be understood as a plug-in that matches at least one warning information in the first network threat detection result.

[0050] That is, the server can first analyze the alarm information, determine the features in the alarm information, and use the target plug-in that matches the alarm information to obtain the corresponding first auxiliary information, so as to subsequently interpret the alarm with the help of the first auxiliary information.

[0051] In an embodiment of the present application, the server can determine the target plug-in using a second target model. The second target model can be a language model with natural language processing capabilities, that is, the second target model can understand the meaning of natural language and handle various natural language processing tasks. For example, the second target model can be a deep learning model trained using text data.

[0052] In a specific implementation, the second target model can determine the target plug-in based on prompt engineering technology. In some possible implementations, the server can send a second prompt message generated based on at least one alarm message to the second target model, receive the target plug-in information returned by the second target model, and obtain the first auxiliary information based on the target plug-in indicated by the target plug-in information.

[0053] The second prompt information can be used to instruct the second target model to determine a target plug-in for obtaining the first auxiliary information. In this way, the second target model can analyze the at least one piece of alarm information in combination with the prompt capability of the second prompt information, determine the characteristics of the at least one piece of alarm information, and determine a target plug-in that matches the alarm information based on the different capabilities corresponding to different plug-ins, so that the server can call the target plug-in to obtain the first auxiliary information.

[0054] Different target plug-ins may correspond to different first auxiliary information. In some embodiments, the target plug-in includes an Internet search plug-in. Specifically, in response to at least one alarm information including information related to an unknown alarm indicator, the first auxiliary information is obtained based on the Internet search plug-in.

[0055] The unknown alarm indicator is an alarm indicator that is not included in the existing database. In this case, the first auxiliary information is related to the unknown alarm indicator.

[0056] Due to the large number of alarm indicators and their rapid changes, existing databases struggle to dynamically update information related to these indicators in real time. However, when alarm information includes information related to unknown alarm indicators, generating accurate interpretation results is difficult without this information.

[0057] Therefore, when the alarm information includes information related to the unknown alarm indicator, the first auxiliary information related to the unknown alarm indicator is obtained by calling the Internet search plug-in, so that the first auxiliary information can be used to interpret the network threat detection result later.

[0058] The internet search plug-in can be used to search based on an internet search engine. The server can call the internet search plug-in, pass the search keywords and the number of search matches extracted from the alarm information to the internet search plug-in, receive the corresponding number of search results returned by the internet search plug-in, and obtain the first auxiliary information based on the search results. In this way, with the help of the internet search plug-in, real-time information related to the unknown alarm indicator can be obtained from the internet.

[0059] In some other embodiments, the target plug-in includes a uniform resource locator (URL) encoding and decoding plug-in. Specifically, in response to at least one alert message including URL-encoded content, the first auxiliary information is obtained based on the URL encoding and decoding plug-in. In this case, the first auxiliary information includes content after decoding the URL-encoded content.

[0060] In some other embodiments, the target plug-in includes a Base64 encoding / decoding plug-in for representing binary data based on 64 printable characters. Specifically, in response to at least one alarm message including Base64-encoded content, the first auxiliary information is obtained based on the Base64 encoding / decoding plug-in. In this case, the first auxiliary information includes content decoded from the Base64-encoded content.

[0061] When the alarm information includes encoded content (such as URL-encoded content or Base64-encoded content), it is difficult to identify it during the subsequent alarm interpretation process. Therefore, the encoded content in the alarm information is decoded by calling the target plug-in for decoding different formats, so that the first auxiliary information can be used to interpret the network threat detection results subsequently.

[0062] In some other embodiments, the target plug-in includes a threat intelligence search plug-in. Specifically, in response to at least one alert message including a threat intelligence indicator to be identified, the threat intelligence search plug-in obtains first auxiliary information. In this case, the first auxiliary information is related to the threat intelligence indicator to be identified.

[0063] Among them, the threat intelligence search plug-in can be used to search from an existing database. The server can call the threat intelligence search plug-in, pass the threat intelligence indicator to be identified extracted from the alarm information to the threat intelligence search plug-in, receive the search results returned by the threat intelligence search plug-in, and obtain the first auxiliary information based on the search results. In this way, with the help of the threat intelligence search plug-in, information related to the threat intelligence indicator to be identified is obtained from an existing database (such as a local existing database or an external existing database).

[0064] Based on the above description, the training data of the second target model can include multiple URL encodings, multiple Base64 encodings, threat intelligence indicator data in an existing database, etc. The second target model is trained using the above training data. Combined with the natural language processing capabilities of the second target model, the second target model can analyze the alarm information and determine the matching target plug-in.

[0065] Furthermore, the server can also obtain auxiliary information in combination with the alarm knowledge base. In specific implementation, the server can obtain the second auxiliary information from the alarm knowledge base based on at least one alarm information.

[0066] The alarm knowledge base includes multiple historical alarm information and alarm context information corresponding to the multiple historical alarm information. For example, the alarm context information may include network threat feature information, attack mode information, vulnerability details information, etc.

[0067] That is, the server can obtain the second auxiliary information based on the retrieval augmented generation (RAG) technology by using the knowledge retrieved from the alarm knowledge base.

[0068] In some possible implementations, the alarm knowledge base can be a private database of the network threat detection system. It is understood that when different users use the network threat detection system to perform network threat detection, multiple historical alarm information may be generated, such as Common Vulnerabilities & Exposures (CVE) information. Different historical alarm information may have corresponding alarm context information. Therefore, the alarm knowledge base may include historical alarm information and alarm context information corresponding to the historical alarm information.

[0069] In some embodiments, the server can obtain the second auxiliary information from the alarm knowledge base through similarity retrieval. Referring to FIG2 , which illustrates a process flow diagram for obtaining the second auxiliary information, the server can determine a vector representation corresponding to at least one piece of alarm information, calculate the similarity between the vector representation corresponding to the at least one piece of alarm information and the vector representations corresponding to multiple pieces of historical alarm information in the alarm knowledge base, and then, based on target historical alarm information whose similarity meets set conditions, determine the alarm context information corresponding to the target historical alarm information, and determine the second auxiliary information based on the alarm context information corresponding to the target historical alarm information.

[0070] In other words, the historical alarm information and alarm context information in the alarm knowledge base can be stored in the form of vectors. For example, the historical alarm information and alarm context information can be segmented to generate text knowledge blocks. Then, using a vector model, the vector representation of the text knowledge blocks can be determined to generate a vector database.

[0071] In the process of obtaining the second auxiliary information, the server can use the vector model to determine the vector representation of the alarm information in the network threat detection results, and then perform a similarity search with the vector representation corresponding to the historical alarm information in the vector database to determine the vector representation corresponding to the target historical alarm information whose similarity meets the set conditions (for example, the similarity is greater than the similarity threshold), and then restore the vector representation corresponding to the target historical alarm information and the vector representation of the alarm context information corresponding to the target historical alarm information to text to determine the second auxiliary information.

[0072] S103: Sending first prompt information generated at least based on the first network threat detection result and the first auxiliary information to the first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result.

[0073] In an embodiment of the present application, the warning information in the first network threat detection result is analyzed with the help of the first target model, thereby generating an interpretation result that is highly readable and easy to understand.

[0074] The first target model may be a language model with natural language processing capabilities, that is, the first target model can understand the meaning of natural language and can handle various natural language processing tasks. For example, the first target model may be a deep learning model trained using text data.

[0075] In some embodiments, the first target model can be deployed on the server, and the server can directly interpret the alarm through the first target model. In other embodiments, considering the large size of the first target model, the first target model can also be deployed externally, and the server can interpret the network threat detection results by calling the external first target model interface.

[0076] Referring to a flow chart of interpretation result generation shown in FIG3 , taking into account user information security issues, before the server sends the first prompt information generated based on the first network threat detection result and the first auxiliary information to the first target model, the server can also extract key identification information from at least one alarm message, and then encrypt the key identification information to update the first network threat detection result.

[0077] The key identification information may be information related to user information, for example, network identification information (such as an IP address). By extracting the key identification information from the alarm information and encrypting the key identification information, the key identification information in the first network threat detection result sent to the first target model is encrypted and desensitized, thereby protecting user information security.

[0078] As shown in FIG3 , the server may encrypt key identification information in the alarm information, obtain first auxiliary information through the target plug-in, obtain second auxiliary information through the alarm knowledge base, and interpret the first network threat detection result using the first target model.

[0079] It should be noted that the present embodiment does not limit the order in which the three steps of encrypting the key identification information in the alarm information, obtaining the first auxiliary information by invoking the target plug-in, and obtaining the second auxiliary information from the alarm knowledge base are executed. For example, the server may first encrypt the key identification information in the alarm information, then obtain the second auxiliary information by invoking the target plug-in and obtaining the second auxiliary information from the alarm knowledge base.

[0080] In addition, the first target model used to generate the interpretation result and the second target model used to determine the target plug-in can be the same language model or different language models, which is not limited in this embodiment of the present application.

[0081] Similarly, the first target model can generate an interpretation result based on prompt engineering technology. In specific implementations, the server can generate the first prompt information based on at least the first network threat detection result and the first auxiliary information. In this way, the first target model can analyze the first network threat detection result in combination with the first auxiliary information using the prompt capability of the first prompt information to generate an interpretation result for the first network threat detection result that meets the user's needs.

[0082] In the case where the server also obtains other auxiliary information (i.e., second auxiliary information), the server can generate first prompt information based on at least the first network threat detection result, the first auxiliary information and the second auxiliary information, send the first prompt information to the first target model, and receive the interpretation result generated by the first target model for the first network threat detection result.

[0083] It should be noted that in the embodiments of the present application, in addition to the first network threat detection result and the first auxiliary information (some embodiments also include the second auxiliary information), the first prompt information can also be generated based on other information, for example, based on the instruction information for the first target model, background information related to the alarm interpretation, information related to the output format, etc., the first prompt information can be generated together.

[0084] By sending the second auxiliary information together with the first network threat detection result and the first auxiliary information to the first target model, the first target model can integrate the alarm information and various types of auxiliary information. In this way, the first target model can use the rich auxiliary information to conduct a more comprehensive analysis of the alarm information, thereby improving the detail and accuracy of the interpretation results.

[0085] Specifically, the interpretation result may indicate at least one of the following: the type of alarm information, the meaning of the alarm data associated with the alarm information, the level of the alarm information, the impact scope of the alarm information, and reference information related to the interpretation result.

[0086] Among them, the type of alarm information may refer to the interpretation information for the alarm information, such as alarm indicators, alarm rules, etc. The meaning of the alarm data associated with the alarm information may refer to the interpretation information for the code data packet, such as explaining the meaning of the code data packet in natural language. The level of the alarm information may refer to the severity of the alarm information, such as low, medium, and high. The scope of impact of the alarm information may refer to servers, hosts and other devices affected by the alarm information. The reference information related to the interpretation results may refer to the reference materials when the first target model generates the interpretation results, such as auxiliary information.

[0087] Continuing as shown in FIG3 , after the first target model generates an interpretation result, considering that the server can encrypt the key identification information in the first network threat detection result, in order to present a complete interpretation result to the user, the server can also extract the result information associated with the key identification information in the interpretation result, decrypt the result information associated with the key identification information, and update the interpretation result.

[0088] That is, for the interpretation results generated by the first target model, the server can restore the desensitized key identification information (such as the IP address). By encrypting the key identification information before sending the alarm information to the first target model, and decrypting the result information associated with the key identification information before presenting the interpretation results to the user, it not only protects the user's information security, but also presents the user with complete and detailed interpretation results, helping the user to quickly understand the network threat detection results and make timely and effective responses.

[0089] In an embodiment of the present application, the aforementioned process of encrypting key identification information, determining a target plug-in to obtain first auxiliary information, obtaining second auxiliary information from an alarm knowledge base, generating an interpretation result, and decrypting the result information associated with the key identification information can be implemented based on a language model agent. The language model agent is an intelligent model system that combines a language model, search-enhanced generation technology, processing tools, and workflow orchestration. The language model agent can orchestrate a workflow as shown in Figure 3. The server executes each node in the workflow to implement the functions of encryption, auxiliary information acquisition, interpretation result generation, and decryption.

[0090] S103: Presenting the interpretation results.

[0091] After the first target model generates an interpretation result, the server can present the interpretation result on the network threat detection page.

[0092] 4A and 4B illustrate schematic diagrams of a network threat detection page. As shown in FIG4A , the network threat detection page 40 includes an alarm information presentation area 401. The alarm information presentation area 401 is used to present at least one alarm message. FIG4A illustrates the presentation of one alarm message as an example.

[0093] Specifically, the alarm information presentation area 401 can present the contents of multiple fields related to the alarm information. For example, the alarm information presentation area 401 can present the alarm host, attack direction, processing status, alarm time, alarm type (i.e., threat name), source IP, protocol, destination IP, destination port, attack results, and code data packet. In some embodiments, the alarm information presentation area 401 can also present a detailed legend of the alarm information so that the user can intuitively understand the alarm information through the legend.

[0094] Furthermore, in this embodiment of the present application, network threat detection page 40 provides a preset control 402, which can be used to trigger the generation of an interpretation result of the first network threat detection result. Specifically, the user can click preset control 402 to achieve a one-click interpretation of the network threat detection result, reducing the interactive dialogue between the user and the language model and improving interpretation efficiency.

[0095] As shown in Figure 4B, after the user triggers the generation of the interpretation result of the first network threat detection result, the network threat detection page 40 can display the interpretation result presentation area 403. Among them, the interpretation result presentation area 403 can be used to present the interpretation result. Specifically, the interpretation result may include the contents of multiple fields, such as the "alarm interpretation" field, the "data packet interpretation" field, the "level analysis" field, the "scope of impact" field, the "handling suggestions" field, and the "reference material" field. The user can quickly understand the nature, severity, and handling method of the alarm information through the interpretation results presented in the interpretation result presentation area 403, providing a decision-making basis for the user to handle the alarm information.

[0096] In some possible implementations, the interpretation result presentation area 403 may present the interpretation result to the user sentence by sentence in a streaming manner, thereby enhancing the interactive experience, reducing the user's anxiety while waiting for the interpretation result to be generated, and improving the user's usage experience.

[0097] Based on the above description, an embodiment of the present application provides a method for processing alarm information. The method first obtains a first network threat detection result, wherein the first network threat detection result includes at least one alarm message, and in response to a feature included in the at least one alarm message matching a target plug-in, obtains first auxiliary information based on the target plug-in, then sends first prompt information generated by at least the first network threat detection result and the first auxiliary information to a first target model, receives an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate an interpretation result, and then presents the interpretation result.

[0098] Before interpreting the network threat detection results, this method first determines whether the alert contains features that match the plugin. If the features in the alert match the target plugin, the target plugin retrieves auxiliary information. This information, along with the network threat detection results, is then fed into the target model. This auxiliary information allows the target model to conduct targeted analysis of the alert, improving the comprehensiveness and accuracy of the alert interpretation.

[0099] The preceding article describes the alarm information processing method provided by this application. In its specific implementation, the server can use a multi-instance approach to process alarm interpretation requests submitted by different users, or multiple alarm interpretation requests submitted by the same user. In other words, alarm interpretation requests submitted by different users can be assigned to different instances for information processing, and multiple alarm interpretation requests submitted by the same user can also be assigned to different instances for information processing.

[0100] Referring to a flowchart of database synchronization shown in FIG5 , after obtaining the first network threat detection result, the server may generate a first identifier corresponding to the first network threat detection result. The first identifier may be used to uniquely identify the first network threat detection result.

[0101] The server can then query the cache to see if the first identifier exists. It is understood that after generating the interpretation result, the server can store the interpretation result in the cache of the current instance. Therefore, after the server obtains the first network threat detection result, it can use the first identifier as an index to query the cache to see if there is an interpretation result corresponding to the first identifier.

[0102] If the first identifier does not exist in the cache, the server can add the first identifier to the database and update the database so that other instances can update their caches synchronously. Furthermore, the server can generate an interpretation result, add the interpretation result, expiration time, and analysis status corresponding to the first identifier to the database, and update the database again, thus achieving data synchronization between caches of multiple instances in the database.

[0103] If the first identifier exists in the cache, the server can determine whether the interpretation result corresponding to the first identifier has expired. If the interpretation result has expired, the server can clear the interpretation result, expiration time, and analysis status corresponding to the first identifier and update the database. Furthermore, the server can generate a new interpretation result, add the interpretation result, expiration time, and analysis status corresponding to the first identifier to the database, and update the database again, thereby achieving data synchronization between caches of multiple instances in the database.

[0104] If the interpretation result has not expired, the server can determine whether the analysis status corresponding to the first identifier is Completed. If so, the server can directly obtain the interpretation result from the cache without calling the first target model to regenerate the interpretation result, improving the efficiency of alarm interpretation. If not, it indicates that another instance is already processing the alarm information. The server can wait until the analysis status changes to Completed before obtaining the interpretation result from the cache, effectively avoiding repeated submission of interpretation generation requests for the same network threat detection result and saving computing resources.

[0105] The above text has provided a detailed introduction to the alarm information processing method provided in the embodiment of the present application in conjunction with Figures 1 to 5. The system and device provided in the embodiment of the present application will be introduced in conjunction with the accompanying drawings.

[0106] Referring to the structural diagram of the alarm information processing system shown in FIG6 , the system 60 includes:

[0107] A first acquisition module 601 is configured to acquire a first network threat detection result, where the first network threat detection result includes at least one piece of alarm information;

[0108] A second acquisition module 602 is configured to acquire first auxiliary information based on the target plug-in in response to a feature included in the at least one piece of alarm information matching the target plug-in;

[0109] a communication module 603 configured to send first prompt information generated based at least on the first network threat detection result and the first auxiliary information to a first target model, and receive an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result;

[0110] The presentation module 604 is configured to present the interpretation result.

[0111] In some possible implementations, the target plug-in includes an Internet search plug-in; and the second acquisition module 602 is specifically configured to:

[0112] In response to the at least one alarm information including information related to an unknown alarm indicator, first auxiliary information is obtained based on the Internet search plug-in, the unknown alarm indicator is an alarm indicator not included in the existing database, and the first auxiliary information is related to the unknown alarm indicator.

[0113] In some possible implementations, the target plug-in includes a URL encoding and decoding plug-in; and the second obtaining module 602 is specifically configured to:

[0114] In response to the at least one piece of warning information including URL-encoded content, first auxiliary information is obtained based on the URL encoding and decoding plug-in, where the first auxiliary information includes content after decoding the URL-encoded content.

[0115] In some possible implementations, the target plug-in includes a Base64 encoding and decoding plug-in; and the second acquisition module 602 is specifically configured to:

[0116] In response to the at least one piece of alarm information including Base64-encoded content, first auxiliary information is obtained based on the Base64 encoding and decoding plug-in, where the first auxiliary information includes content decoded from the Base64-encoded content.

[0117] In some possible implementations, the target plug-in includes a threat intelligence search plug-in; and the second acquisition module 602 is specifically configured to:

[0118] In response to the at least one piece of alarm information including the threat intelligence indicator to be identified, first auxiliary information is obtained based on the threat intelligence search plug-in, where the first auxiliary information is related to the threat intelligence indicator to be identified.

[0119] In some possible implementations, the first obtaining module 601 is specifically configured to:

[0120] In response to a triggering operation on a preset control in a network threat detection page, a first network threat detection result is obtained, where the preset control is used to trigger an interpretation of the first network threat detection result.

[0121] In some possible implementations, the second obtaining module 602 is specifically configured to:

[0122] sending second prompt information generated at least based on the at least one warning information to a second target model, and receiving target plug-in information returned by the second target model, wherein the second prompt information is used to instruct the second target model to determine a plug-in for obtaining the first auxiliary information;

[0123] First auxiliary information is acquired based on the target plug-in indicated by the target plug-in information.

[0124] In some possible implementations, the second obtaining module 602 is further configured to:

[0125] Acquiring second auxiliary information from an alarm knowledge base according to the at least one alarm information, the alarm knowledge base including a plurality of historical alarm information and alarm context information corresponding to the plurality of historical alarm information;

[0126] The communication module 603 is specifically used for:

[0127] Sending first prompt information generated at least based on the first network threat detection result, the first auxiliary information, and the second auxiliary information to a first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result.

[0128] In some possible implementations, the second obtaining module 602 is specifically configured to:

[0129] Determining a vector representation corresponding to the at least one piece of warning information;

[0130] respectively calculating similarities between the vector representation corresponding to the at least one piece of alarm information and the vector representations corresponding to the plurality of pieces of historical alarm information in the alarm knowledge base;

[0131] Determining alarm context information corresponding to the target historical alarm information according to the target historical alarm information whose similarity meets the set conditions;

[0132] Second auxiliary information is determined according to the alarm context information corresponding to the target historical alarm information.

[0133] In some possible implementations, the system 60 further includes an encryption and decryption module, which is configured to:

[0134] Extracting key identification information from the at least one piece of warning information;

[0135] The key identification information is encrypted, and the first network threat detection result is updated.

[0136] In some possible implementations, the encryption and decryption module is further configured to:

[0137] Extracting result information associated with key identification information from the interpretation result;

[0138] The result information associated with the key identification information is decrypted, and the interpretation result is updated.

[0139] In some possible implementations, the first target model or the second target model includes a language model with natural language processing capabilities.

[0140] In some possible implementations, the interpretation result indicates at least one of the following: the type of alarm information, the meaning of alarm data associated with the alarm information, the level of the alarm information, the impact scope of the alarm information, and reference information related to the interpretation result.

[0141] According to the embodiment of the present application, the alarm information processing system 60 can correspond to executing the method described in the embodiment of the present application, and the above-mentioned and other operations and / or functions of each module / unit of the alarm information processing system 60 are respectively for implementing the corresponding processes of each method in the embodiment shown in Figure 1. For the sake of brevity, they will not be repeated here.

[0142] The present application also provides an electronic device, which is specifically configured to implement the functions of the alarm information processing system 60 in the embodiment shown in FIG6 .

[0143] FIG7 provides a schematic structural diagram of an electronic device 700. As shown in FIG7, the electronic device 700 includes a bus 701, a processor 702, a communication interface 703, and a memory 704. The processor 702, the memory 704, and the communication interface 703 communicate with each other via the bus 701.

[0144] Bus 701 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified as address buses, data buses, control buses, etc. For ease of illustration, FIG7 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.

[0145] The processor 702 may be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0146] The communication interface 703 is used for communicating with the outside, for example, the communication interface 703 can be used for communicating with a terminal.

[0147] The memory 704 may include volatile memory, such as random access memory (RAM), or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0148] The memory 704 stores executable code, and the processor 702 executes the executable code to perform the aforementioned alarm information processing method.

[0149] Specifically, when implementing the embodiment shown in FIG6 , and when each module or unit of the alarm information processing system 60 described in the embodiment of FIG6 is implemented by software, the software or program code required to execute the functions of each module / unit in FIG6 may be partially or completely stored in the memory 704. The processor 702 executes the program code corresponding to each unit stored in the memory 704 to perform the aforementioned alarm information processing method.

[0150] The present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the above-mentioned alarm information processing method applied to the alarm information processing system 60.

[0151] The present application also provides a computer program product comprising one or more computer instructions that, when loaded and executed on a computing device, fully or partially generate the process or function described in the present application.

[0152] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0153] When the computer program product is executed by a computer, the computer performs any of the aforementioned alarm information processing methods. The computer program product may be a software installation package. When any of the aforementioned alarm information processing methods is needed, the computer program product may be downloaded and executed on the computer.

[0154] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to the various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the prescribed logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the prescribed function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0155] The units involved in the embodiments described in this application may be implemented in software or hardware, wherein the name of a unit / module does not, in some cases, constitute a limitation on the unit itself.

[0156] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0157] In the context of the present application embodiment, machine-readable medium can be a tangible medium that can contain or store a program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0158] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems or devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0159] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0160] It should also be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0161] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0162] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for processing alarm information, comprising: Obtaining a first network threat detection result, where the first network threat detection result includes at least one piece of alarm information; In response to a feature included in the at least one piece of alarm information matching a target plug-in, obtaining first auxiliary information based on the target plug-in; Sending first prompt information generated based at least on the first network threat detection result and the first auxiliary information to a first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result; The interpretation results are presented.

2. The method according to claim 1, wherein The target plug-in includes an Internet search plug-in; The response to the feature included in the at least one alarm message matching the target plug-in, obtaining the first auxiliary information based on the target plug-in includes: in response to the at least one alarm message including information related to an unknown alarm indicator, obtaining the first auxiliary information based on the Internet search plug-in, the unknown alarm indicator is an alarm indicator not included in the existing database, and the first auxiliary information is related to the unknown alarm indicator.

3. The method according to claim 1, wherein The target plug-in includes a URL encoding and decoding plug-in; The step of obtaining first auxiliary information based on the target plug-in in response to the feature included in the at least one alarm message matching the target plug-in includes: obtaining first auxiliary information based on the URL encoding and decoding plug-in in response to the at least one alarm message including URL-encoded content, wherein the first auxiliary information includes content decoded from the URL-encoded content.

4. The method according to claim 1, wherein The target plug-in includes a Base64 encoding and decoding plug-in; The step of obtaining first auxiliary information based on the target plug-in in response to the feature included in the at least one alarm message matching the target plug-in includes: obtaining first auxiliary information based on the Base64 encoding and decoding plug-in in response to the at least one alarm message including Base64-encoded content, wherein the first auxiliary information includes content decoded from the Base64-encoded content.

5. The method according to claim 1, wherein The target plug-in includes a threat intelligence search plug-in; The response to the feature included in the at least one alarm message matching the target plug-in and obtaining the first auxiliary information based on the target plug-in includes: in response to the at least one alarm message including the threat intelligence indicator to be identified, obtaining the first auxiliary information based on the threat intelligence search plug-in, wherein the first auxiliary information is related to the threat intelligence indicator to be identified.

6. The method according to claim 1, wherein The obtaining of the first network threat detection result includes: In response to a triggering operation on a preset control in a network threat detection page, a first network threat detection result is obtained, where the preset control is used to trigger an interpretation of the first network threat detection result.

7. The method according to any one of claims 1 to 5, wherein: In response to a feature included in the at least one piece of alarm information matching a target plug-in, obtaining first auxiliary information based on the target plug-in includes: sending second prompt information generated at least based on the at least one warning information to a second target model, and receiving target plug-in information returned by the second target model, wherein the second prompt information is used to instruct the second target model to determine a plug-in for obtaining the first auxiliary information; First auxiliary information is acquired based on the target plug-in indicated by the target plug-in information.

8. The method according to claim 1, further comprising: Acquiring second auxiliary information from an alarm knowledge base according to the at least one alarm information, the alarm knowledge base including a plurality of historical alarm information and alarm context information corresponding to the plurality of historical alarm information; The sending of the first prompt information generated at least based on the first network threat detection result and the first auxiliary information to the first target model, and receiving the interpretation result generated by the first target model for the first network threat detection result, includes: sending the first prompt information generated at least based on the first network threat detection result, the first auxiliary information and the second auxiliary information to the first target model, and receiving the interpretation result generated by the first target model for the first network threat detection result.

9. The method according to claim 8, wherein The acquiring second auxiliary information from an alarm knowledge base according to the at least one piece of alarm information includes: Determining a vector representation corresponding to the at least one piece of warning information; respectively calculating similarities between the vector representation corresponding to the at least one piece of alarm information and the vector representations corresponding to the plurality of pieces of historical alarm information in the alarm knowledge base; Determining alarm context information corresponding to the target historical alarm information according to the target historical alarm information whose similarity meets the set conditions; Second auxiliary information is determined according to the alarm context information corresponding to the target historical alarm information.

10. The method according to claim 1, wherein Before sending the first prompt information generated based on the first network threat detection result and the first auxiliary information to the first target model, the method further includes: Extracting key identification information from the at least one piece of warning information; The key identification information is encrypted, and the first network threat detection result is updated.

11. The method according to claim 10, wherein: Before presenting the interpretation result, the method further includes: Extracting result information associated with key identification information from the interpretation result; The result information associated with the key identification information is decrypted, and the interpretation result is updated.

12. The method according to claim 1, 7 or 8, wherein The first target model or the second target model includes a language model having natural language processing capabilities.

13. The method according to any one of claims 1 to 12, wherein: The interpretation result indicates at least one of the following: the type of alarm information, the meaning of alarm data associated with the alarm information, the level of the alarm information, the impact range of the alarm information, and reference information related to the interpretation result.

14. An alarm information processing system comprising: A first acquisition module is configured to acquire a first network threat detection result, where the first network threat detection result includes at least one piece of alarm information; a second acquisition module, configured to, in response to a feature included in the at least one piece of alarm information matching a target plug-in, acquire first auxiliary information based on the target plug-in; a communication module, configured to send first prompt information generated based at least on the first network threat detection result and the first auxiliary information to a first target model, and receive an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result; A presentation module is used to present the interpretation result.

15. An electronic device comprising a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the electronic device performs the method according to any one of claims 1 to 13. 16 . A computer-readable storage medium comprising instructions, wherein the instructions instruct an electronic device to execute the method according to claim 1 .

Citation Information

Patent Citations

  • Threat alarm information processing method and device, computer equipment and storage medium

    CN116155519A

  • Attack detection method and device, terminal equipment and storage medium

    CN117240598A

  • Power monitoring system network attack monitoring method and device, and storage medium

    CN117749492A

  • Alarm information processing method, system, equipment and medium

    CN118264450A

  • Systems and methods for intelligent configuration and deployment of alert suppression parameters in a cybersecurity threat detection and mitigation platform

    US20230325498A1