信息安全研究 ›› 2023, Vol. 9 ›› Issue (10): 986-.

• 学术论文 • 上一篇    下一篇

网络安全告警降噪基线的智能生成方法

王星凯1,2吴复迪1童明凯1薛见新1张润滋1   

  1. 1(绿盟科技集团股份有限公司北京100089)
    2(清华大学信息科学技术学院北京100084)
  • 出版日期:2023-10-17 发布日期:2023-10-28
  • 通讯作者: 王星凯 博士.主要研究方向为网络安全数据分析. wangxingkai@nsfocus.com
  • 作者简介:王星凯 博士.主要研究方向为网络安全数据分析. wangxingkai@nsfocus.com 吴复迪 主要研究方向为智能安全运营. wufudi@nsfocus.com 童明凯 硕士.主要研究方向为DNS安全和数据驱动的安全运营. tongmingkai@nsfocus.com 薛见新 博士.主要研究方向为图形学习、安全知识图、攻击源、威胁搜索. xuejianxin@nsfocus.com 张润滋 博士.主要研究方向为数据驱动的安全运营和威胁搜索. zhangrunzi@nsfocus.com

Intelligent Generation Method of Noise Reduction Baseline for Cybersecurity Alert

Wang Xingkai1,2 , Wu Fudi1, Tong Mingkai1, Xue Jianxin1, and Zhang Runzi1   

  1. 1(NSFOCUS Technologies Group Co., Ltd., Beijing 100089)
    2(School of Information Science and Technology, Tsinghua University, Beijing 100084)
  • Online:2023-10-17 Published:2023-10-28

摘要: 网络安全运营往往通过预置的基线规则组等方法来过滤告警,在复杂的场景中难以深入适配企业的具体网络和业务环境.随着企业信息化业务的不断扩展,复杂的网络攻击通常隐藏在海量告警中,造成告警疲劳的现象,严重影响安全运营团队的运营效率.提出一种智能的算法用于生成可解释的网络安全告警降噪基线.面向告警载荷进行数据挖掘建立基线,帮助运营人员在不了解公司环境和业务的情况下对海量的告警进行过滤,提升安全运营的效率.最终,在某大型公司的实际生产环境验证发现生成的降噪基线可以有效地过滤告警.

关键词: 告警, 载荷, 可解释基线, 告警降噪, 安全运营

Abstract: The operators often filter alerts through some preset baseline rule groups in cybersecurity operation. It is difficult to deeply adapt to the specific network and business environment of the enterprise. With the continuous expansion of enterprise information services, the complex cyberattack is usually hidden in tons of alerts. It causes the alert fatigue, which reduces the efficiency of security operation center. We propose a cybersecurity alert baseline method based on intelligence algorithm to generate interpretable alert noise reduction baselines, which can filter alerts without understanding the company’s environment and business. It can improve the efficiency of cybersecurity operation. This method can effectively filter alerts in the actual production environment of a large company.

Key words: alert, payload, interpretable baseline, alert noise reduction, Security Operations

中图分类号: