Security Event Detection Using Rolling Log Windows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in quickly and accurately detecting security events due to the need for manual data retrieval and filtering, leading to delayed response times and inefficient post-tracing after attacks, with existing association analysis methods lacking real-time performance.
Innovation Solution
A method utilizing a rolling time window to match log data with a security event model, generating a matching result set to restore the attack process, and employing a security event detection tree to enhance real-time performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual data retrieval and filtering is used to detect security events, then accuracy of attack detection is improved, but response time deteriorates
Solution Approach 1:
The patent pre-processes and structures log data into standardized formats with predefined fields and relationships before security events occur. Association rules and attack patterns are pre-configured in the system, allowing rapid matching and detection when security events happen, eliminating the need for manual data retrieval and filtering during incident response.
2Measurement precision
If association analysis method processes all mass data to generate security event alarms, then accuracy of attack detection is improved, but real-time performance deteriorates
Solution Approach 1:
The patent segments the data processing into distinct stages: log collection, standardization, association rule matching, and alarm generation. By dividing the mass data into manageable segments and processing them through standardized pipelines with predefined association rules, the system achieves both high detection accuracy and real-time performance without requiring to process all data at once.
3Loss of information
If manual tracing is performed after attack events, then completeness of attack scenario reconstruction is improved, but efficiency of post-tracing deteriorates
Solution Approach 1:
The patent introduces an automated tracing system that acts as an intermediary between attack detection and scenario reconstruction. When security events are detected, the system automatically retrieves related log data, applies association rules to reconstruct attack scenarios, and generates comprehensive reports without requiring manual intervention, thereby maintaining complete attack scenario information while dramatically improving tracing efficiency.
Data Source
AI summary
The present disclosure discloses a method and apparatus for detecting security event, and a non-transitory computer-readable storage medium, and relates to the field of big data. The method includes: acquiring a time window, and acquiring log data, wherein the time window is a rolling window in a preset period; matching the log data with a security event model in each time window, so as to generate a matching result set in each time window, wherein the security event model is a model comprising a plurality of rule models for identifying whether the log data has an attack behavior; and generating security event data according to the matching result set, so as to restore an attack process according to the security event data.


