Summary of the invention
The objective of the invention is to use flow of event space-time window to filter, the leading coupling of daily record string is dynamically resolved fast, the powerful algorithm of various dimensions magnanimity incident, event server, advanced technologies such as modern communication, to surpass the association analysis more than 100,000 network safety event ranks of per second fast, find potential safety hazard and abnormal state and the alarm in time that exists in the network in real time and stop to be main purpose, by all kinds of security logs and the incident that constantly produce in complicated IT resource in the computer network and the Prevention-Security facility operation process thereof are unified to gather, transmission, analyze, cross-region is set up in the digital management of overall processes such as issue, the fail safe of complicated IT resource is implemented effectively in a plurality of computer networks, long-acting management and decision-making provide service, correlation analysis system with advanced level.
In order to realize above-mentioned purpose, the present invention takes following technical scheme to realize:
The network safety event correlation analysis system is that a cover is based on the distributed real-time collection, multipoint cooperative working, flow of event and historical events database mixed interconnection pattern, script drives in the thing of engine and the association analysis in real time and the computer network security supervisory control system of historical events association analysis in advance afterwards, in order to improve network operation maintenance management department to the true degree of understanding of linchpin network real time execution situation, strengthen the quick stress reaction ability of network security fault, for building the security protection of collection operation system, operate behavioural analysis on the user network, the new network security monitoring platform of forming " Alliance Defense " system with the existing network safety means lays the foundation.
Network safety event correlation analysis system of the present invention comprises network safety event acquisition layer, communication network layer, association analysis layer and management presentation layer, and is wherein said:
(1) network safety event acquisition layer:
Comprise the collecting device of data sources such as state, daily record and the network packet collection of Network Security Device, the network equipment, host server equipment, operating system, database, middleware, be responsible for gathering required network safety event information;
Network Security Device comprises that fire compartment wall, IPS (Intrusion Prevention System, i.e. intrusion prevention system), IDS(Intrusion Detection System are intruding detection system) etc., the network equipment comprises switch, router etc.
(2) communication network layer:
Comprise communication part; Be responsible for finishing the dynamically parsing fast of the leading coupling of daily record string is carried out in the daily record of various Network Security Device, the network equipment, host server equipment, operating system, database, middleware, daily record and state, network packet after resolving are encapsulated according to communication protocol, the diverse network security incident is transferred to the association analysis layer by network;
(3) association analysis layer:
This layer is the core of whole system.Mainly comprise association analysis engine server, association analysis script, event server, historical database server, connect by data wire each other; Described association analysis engine server is responsible for internal memory flow of event and database historical events stream are carried out the filtration of space-time window, the powerful algorithm process of various dimensions magnanimity incident with self surpasses per second 100,000 network safety event, realize the analysis and the preservation of the complicated incidence relation of a plurality of network safety events, described association analysis script is responsible for the relation of the alarm association between the network safety event is defined, the description of association analysis flow process, the network safety event that participates in association analysis defines, described event server is responsible for carrying out the internal memory form stream of diverse network security incident and the storage that the database form flows, and described historical database server carries out the association analysis result data, the association analysis process is used the storage memory of related datas such as network safety event.
(4) management presentation layer:
This layer is management, the analysis result exposition of whole system.Mainly comprise historical database server, WEB server, application server, core switch, work station and other various relevant devices and software, connect by data wire each other; Described historical database server provides association analysis result data and association analysis process detailed data, and described application server is finished the realization of various relevant application functions, and the WEB server is responsible for final data and is represented.Each relevant departments can be by Internet with authority acquisition separately the data message of browser mode according to oneself.
Aforesaid network safety event correlation analysis system, data are from the data sources such as state, daily record and network packet of Network Security Device (fire compartment wall, IPS, IDS etc.), the network equipment (switch, router etc.), host server equipment, operating system, database, middleware.
Aforesaid communication network layer is based on the TCP/IP network transmission protocol.
Aforesaid event server, association analysis engine server and application server all adopt trunking mode, guarantee the high-performance and the high availability of system.
Aforesaid association analysis layer is except carrying out occurent network safety event association analysis, occurent network safety event can also be combined with the web-based history that had taken place security incident and carry out association analysis, can also predict alarm to contingent network safety event in future simultaneously.
Aforesaid management presentation layer not only can be showed association analysis result and relevant event information with the textual form tabulation, and can graphically show association analysis result and relevant event information with the form of network equipment topological diagram.
The historical data base that comprises in described association analysis layer and the management presentation layer is public server, because the data acquisition amount is very big, and the required precision of association analysis is directly proportional with the time range that incident takes place, and has taked the form of historical data base in order to take into account efficient and correctness.
The invention has the beneficial effects as follows: because the generation of most of network security problems is not by single network safety event decision, but decide with different time, the interaction of different generations source by a plurality of network safety events, therefore needs that only can't satisfy network security to the record and the simple analysis of single network security incident, the present invention is directed to the difficult point of network security problem analysis, judgement, designed the network safety event correlation analysis system; In the project implementation process according to subject matters such as the real-time that often occurs in the general networking security incident Analytical System Design process, stability, autgmentabilities, adopted technological means to carry out good solution, be used for effective, long-acting management is implemented in the fail safe of the complicated IT resource of computer network, the network information security and the operation system data security situation that can reflect computer network truly, exactly are for the information security rank examination of computer network provides the quantification scale.
(1), system of the present invention uses for reference professional knowledges such as complex network security incident processing, the processing of network safety event stream and log processing algorithm, the network packet that the status data, daily record data, the network information that produce in Network Security Device, the network equipment, host server equipment, operating system, database, the middleware running are mutual is carried out the health characteristics sample analysis, by the contained information of network safety event is carried out association analysis, for network safety prevention provides the quantification scale.
(2), the quick dynamic resolution parser of the leading coupling of daily record string that utilizes collection terminal to dispose can promptly analyze the data of the daily record of devices from different manufacturers, then by network with transfer of data to event server.
(3) but real-time graph displaying association analysis instrument as a result to different association analysis demands, is showed different topological diagram pictures, and can on-the-spotly adjust display layout and information shows details.Graphical demonstration tool uses under the browser mode of operation based on page technology, supports the pattern layout editing machine of visualization function fully, can finish the making of topological diagram layout of the association analysis scene of any complexity.
Embodiment
Below in conjunction with accompanying drawing the present invention is done concrete introduction:
Network safety event correlation analysis system of the present invention comprises network safety event acquisition layer, communication network layer, association analysis layer and manages four layers of presentation layers.
The network safety event acquisition layer is network safety event acquisition principle figure of the present invention as system's meat and potatoes as Fig. 1.Be installed on by the network system core switching device at scene, the crucial monitoring point of each computer network, it comprises state acquisition equipment, log collection equipment, network packet collecting device.Installment state collecting device, log collection equipment, network packet collecting device at the scene can obtain the data of network safety event after the configuration of being correlated with, analyze, reach the buffer queue pond after the arrangement, format.
The communication network layer is finished by the Hessian interface message processor (IMP) bag is organized in each heterogeneous networks security incident in the buffer queue pond in real time, daily record data carries out the leading coupling of daily record string before the group bag dynamically resolves fast, and the network safety event behind the group bag is uploaded to event server.Interface message processor (IMP) and event server adopt the transmission mode of one-to-many, can upload to a plurality of event servers simultaneously with once gathering the network safety event data of obtaining.This service has encapsulated communication protocol based on the TCP/IP network transmission protocol.
The association analysis layer is the core of whole system.Constitute by event handling layer and analysis logic layer, the space-time window that the event handling layer is responsible for internal memory flow of event and database historical events stream filters, analysis logic layer core is the association analysis engine, be association analysis engine fundamental diagram of the present invention as shown in Figure 2, the network safety event after being responsible for filtering requires to carry out association analysis according to the association analysis script.The association analysis result is stored in the historical data base together with several associated network safety events.The association analysis engine possesses following functional characteristics:
1. different with the product of other phase-split network security incident, after association analysis goes out the combination event alarm, increased the source that causes the combination event alarm and reviewed;
2. the network safety event that participates in analyzing can be a network safety event internal memory stream, also can be the web-based history security incident that is stored in database, even can be that network safety event internal memory stream mixes with the web-based history security incident that is stored in database;
3. the method for association analysis and condition are controlled by outside association analysis script, have increased the width and the degree of depth of association analysis;
4. analysis result is preserved for the smallest particles degree by the individual event incident, makes things convenient for the user to observe the detailed information that the network security alarm takes place;
5. analysis result is pressed the storage of graphics data frame mode, can realize that the graphical effect of unusual attack of network fast and user access activity is vividly showed;
6. reasonably the association analysis algorithm guarantees that engine can possess the per second of processing and surpass 100,000 other abilities of network safety event level.
The management presentation layer is management, the analysis result exposition of whole system.Show that by network safety event management, the management of association analysis script, association analysis engine management and association analysis result four are partly formed.Network safety event supervisory packet includes network security incident definition, network safety event change, network safety event issue.The management of association analysis script comprises the definition of association analysis script, the change of association analysis script, association analysis script startup.The association analysis engine management comprises the initialization of association analysis engine, association analysis engine monitoring of working condition.The association analysis result shows and comprises the tabulation displaying and graphically show.Each network of relation operation management department can pass through browser administration association analysis script and association analysis engine working range, inquires about various association analysis result datas.The equipment of management presentation layer guarantees that native system can normally move and leave room for development.Comprise historical database server, WEB server, application server, core switch, work station, monitoring special-purpose computer, communication apparatus, uninterrupted power supply, printer and relevant device etc.
The above only is a preferred implementation of the present invention; should be pointed out that for those skilled in the art, under the prerequisite that does not break away from the technology of the present invention principle; can also make some improvement and distortion, these improvement and distortion also should be considered as protection scope of the present invention.