The invention provides a
knowledge graph-based security event automatic
response method, which comprises the following steps of: acquiring multi-source security data, performing de-duplication and
standardization processing, and generating a structured security
data set; based on the
network security ontology model, entities and relationships are extracted from the
data set, and a security
knowledge graph is constructed through entity alignment and conflict resolution; according to ATTamp; the CK framework divides network subnets, generates
attack path diagrams of the subnets, and fuses the
attack path diagrams into a global
attack graph. Then, abnormal behavior nodes in the security
knowledge graph are analyzed, and risk scores of the
service layer, the host layer and the
system layer are calculated in combination with the global
attack graph; and matching a predefined
response strategy library based on the risk scores, executing operations such as banning an IP (
Internet Protocol), isolating a host or updating firewall rules and the like through an SOAR platform, generating a disposal report and updating a security knowledge graph. According to the invention, the
network security event
processing efficiency and accuracy can be improved, and the overall security protection capability of the
system is enhanced.