A method and system for a guard chart decision based on defining organizational attack preferences

By jointly searching with threat intelligence knowledge graphs and external intelligence databases, a control and defense map is generated, and honeypot services are automatically generated. This solves the problems of fixed honeypot/honeypot deployment and high cost of manual analysis, and achieves the effects of dynamic defense and rapid response to changes in the network environment.

CN119484109BActive Publication Date: 2026-03-03GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411638079.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-16
Publication Date
2026-03-03
Estimated Expiration
2044-11-16

AI Technical Summary

Technical Problem

In existing technologies, the fixed deployment of honeypots/honey points cannot respond to changes in the network environment in a timely manner, making them easy for attackers to identify. Furthermore, manual analysis is costly and cannot be quickly updated to deal with new threats, resulting in reduced defense effectiveness.

Method used

By jointly searching with threat intelligence knowledge graphs and external intelligence databases, a control and defense graph is generated. Attack patterns and control and defense matrices are used to assess attack patterns and preferences, automatically generate honeypot services, and provide dynamic defense decisions.

Benefits of technology

It enables rapid and automatic generation of honey spots, reducing manpower and time costs, dynamically adjusting defense strategies, improving defense effectiveness, and adapting to changes in the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484109B_ABST
    Figure CN119484109B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on defining organization attack preference guard graph decision method and system, its method includes steps: from the log server of honeypot collection attack information, through the joint search of threat intelligence knowledge graph and external threat intelligence library, ascription defines the behavior mode of attack organization, and the attack preference of attack organization is sorted;From the perspective of attacker, through the topological information in target network, asset information and configuration information generation attack graph, and the mapping of defining organization attack preference to attack graph node is carried out, generates guard graph, and then generates the guard matrix for quantifying calculation attack graph attack mode preference influence;Based on the analysis of the guard matrix of attack graph to defining organization attack preference, with emphasis, generate honeypot service, provide decision support for the deployment of defense measures.The application can more flexible quickly generate the type of honeypot service, greatly saves manpower and time cost for the analysis and deployment of deception defense.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, specifically relating to a control graph decision-making method and system based on defining organizational attack preferences. Background Technology

[0002] With the continuous evolution of attack techniques and the constant changes in the cyberspace landscape, the cybersecurity environment is characterized by high adversarial nature, the sustainability of cyberattack campaigns, and the sophistication and stealth of cyberattack techniques. Attackers are no longer simply engaging in pranks or showing off their skills; they have transformed into organized, profit-driven, and commercially motivated attack groups. Recent major Advanced Persistent Threat (APT) attacks demonstrate that traditional cybersecurity defense strategies are becoming increasingly ineffective in the context of APTs; traditional static security measures are no longer adequate for the flexible and rapidly changing cybersecurity environment. How to respond to and adapt to these evolving threats in real time is a key research topic.

[0003] To supplement traditional security measures such as firewalls and provide more comprehensive monitoring and analysis of potential malicious activities, Intrusion Detection Systems (IDS) monitor network or system traffic and behavior, analyze this data to identify possible intrusions, and issue alerts when potential malicious activity is detected. However, issues such as false positives and false negatives, efficient monitoring and analysis capabilities, and adaptability to constantly updated and upgraded attack techniques have always been pain points for IDS systems. Currently, combining IDS with threat intelligence to improve the ability to detect new and complex attacks is a major trend.

[0004] Honeypot / honeypot-based systems use decoy techniques to attract and analyze attacker behavior, gathering information from the attacker's perspective. They also obfuscate the attack surface to influence the attacker's perception, increasing the risk of detection and delaying the attack's effectiveness. However, maintaining static deployment and configuration gives attackers ample time to discover and infer its existence. Highly interactive honeypots, especially those interacting with the real operating system environment, are particularly vulnerable to exploitation, potentially becoming the hub of an attack system.

[0005] Adaptive security architecture emphasizes a dynamic, real-time responsive security strategy that automatically adjusts defense mechanisms based on changes in threat conditions. Companies providing cybersecurity services typically implement adaptive security architectures through integrated solutions encompassing multiple security products and functions, such as 360 and NSFOCUS. However, integrating multiple security technologies and measures can increase system complexity, thereby increasing the difficulty of management and maintenance.

[0006] Based on the above survey results, the existing technology still has the following shortcomings:

[0007] (1) To facilitate the management of massive amounts of unstructured threat intelligence, constructing knowledge graphs for threat intelligence network security is currently the main way to store and manage knowledge, such as IBM X-Force Exchange, NSFOCUS Threat Intelligence Center (NTI), Microstep Intelligence Community, 360 Security Brain, SkyNet Threat Intelligence Center, and QiAnXin Threat Intelligence Center, etc. These knowledge graphs for network security provide a structured and queryable network security information framework. Although their application scenarios are diverse, the main function of these knowledge graphs currently focuses on using graph database technology to provide efficient query and display functions, and has not yet fully utilized the potential of graphs to conduct more in-depth data analysis and prediction to guide the security issues faced by the current network environment.

[0008] (2) Honeypots, as a proactive defense technology, are designed to attract hacker attacks by mimicking vulnerable systems, thereby protecting real network resources and gathering information about attackers. However, the fixed nature of honeypot deployment poses a significant challenge to its adaptation to rapidly evolving network environments and increasingly sophisticated attack methods. Firstly, honeypot deployment typically requires manual setup and specific configurations, making it difficult to respond promptly to changes in the network environment. Secondly, this fixed deployment makes it easily identifiable by organized and experienced attackers, thus negating its ability to deceive attackers and creating a risk of being exploited by them.

[0009] (3) Honeypot generation technology addresses the issues of fixed deployment and complex management of honeypots. However, when facing specific attack patterns or attackers, deployment often requires in-depth analysis of the attack or the current network by experienced cybersecurity engineers. This significantly increases manpower and time costs. Furthermore, this approach faces timeliness issues in real-world applications. Rapid changes in network environments and attack strategies mean that the effectiveness of honeypots may quickly diminish. If honeypots cannot be quickly updated and adjusted to address new threats, their value is greatly reduced. Therefore, while honeypot-based technology offers greater flexibility and adaptability for deception defense, challenges remain in terms of rapid response and cost reduction. Summary of the Invention

[0010] The technical problem to be solved by the present invention is to provide a control-defense graph decision-making method based on defining organizational attack preferences, which can more flexibly and quickly automatically generate honeypot service types, greatly saving manpower and time costs for the analysis and deployment of deception defense.

[0011] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:

[0012] A control-defense graph decision-making method based on defining organizational attack preferences, the method comprising the following steps:

[0013] Step S1: Collect attack information from the honeypot's log server, and use the joint search of the threat intelligence knowledge graph and the external threat intelligence database to define the behavioral patterns of the attacking organization and rank the attacking organization's attack preferences.

[0014] Step S2: From the attacker's perspective, an attack graph is generated using the topology, asset, and configuration information of the target network. The mapping of attack preferences to attack graph nodes is defined to generate a control graph. Then, a control matrix is ​​generated to quantify the impact of attack mode preferences on the attack graph.

[0015] Step S3: Based on the attack graph-based control and defense matrix analysis to define the organization's attack preferences, honeypot services are generated with a focus to provide decision support for the deployment of defense measures.

[0016] The aforementioned control graph decision-making method based on defining organizational attack preferences, specifically the process in step S1 of attributing and defining the behavioral patterns of attacking organizations through joint search of threat intelligence knowledge graphs and external threat intelligence databases, is as follows:

[0017] S101. Preprocess the unstructured raw attack information data collected from the honeypot's log server into structured attack information data;

[0018] S102. Determine whether the attack information can be matched in the threat intelligence knowledge graph. If it can be matched, extract the evaluation results of major security vendors. If it cannot be matched, transfer the IP address of the attack information and the associated file information to the VT sandbox.

[0019] S103 and VT Sandbox retrieve related files in the VT library, make API calls based on the hash value of the malicious sample in the extracted attack information, obtain the specific behavioral information of the malicious sample and generate behavioral preference data;

[0020] S104. Extract basic information about the malicious sample, detailed information related to the malicious sample, and the attack organization ID related to the malicious sample from the threat intelligence knowledge graph data.

[0021] S105. A characterization of the malicious sample is formed using basic information and related details of the malicious sample. The attack organization ID associated with this malicious sample is used as the prediction target to construct a training set.

[0022] S106. Characterize the features of malicious samples and predict the attack organization ID as the basis for identifying the organization.

[0023] The control graph decision-making method described above, based on defining organizational attack preferences, includes the following specific process in step S1: ranking the attack preferences of attacking organizations.

[0024] Step S107: Retrieve and define the organization's historical attack patterns in the threat intelligence knowledge graph;

[0025] Step S108: Use the behavioral information of the attack pattern to form an attack preference matrix.

[0026] The aforementioned control graph decision-making method based on defining organizational attack preferences utilizes Cypher statements in step S107 when retrieving and defining the organization's historical attack patterns in the threat intelligence knowledge graph.

[0027] The aforementioned control graph decision-making method based on defining organizational attack preferences, in step S2, when generating the attack graph from the attacker's perspective using topology, asset, and configuration information of the target network, employs the MulVAL method. The specific process is as follows:

[0028] Step S201: Given the network topology and asset configuration information of the target network, obtain the known vulnerability information based on the asset configuration information; and assume the unknown vulnerability information.

[0029] Step S202: Determine the daily security strategy of the target system based on its task requirements;

[0030] Step S203: Define the node types of the attack graph to obtain the attack graph of the target network.

[0031] The aforementioned control-guard graph decision-making method based on defining organizational attack preferences, specifically step S2, involves mapping organizational attack preferences to attack graph nodes, generating a control-guard graph, and then generating a control-guard matrix for quantifying the influence of attack mode preferences on the attack graph. The specific process is as follows:

[0032] Step S204: Directed attack graph G of the target network a The formal representation is shown in formula (F1):

[0033] G a =(V a E a X a )=(A a X a (F1)

[0034] Among them, V a ={v a1 v a2 , ..., v an} is a set of attack graph nodes with n nodes; Xa ∈R n×d E represents a d-dimensional feature matrix with n nodes; a Let A be a set of m edges. a ∈{0,1} n×n The adjacency matrix is ​​a binary adjacency matrix, as shown in formula (F2):

[0035]

[0036] Where i takes the value of a natural number from 1 to n, j takes the value of a natural number from 1 to n, and its element A in the i-th row and j-th column is... ij As shown in formula (F2):

[0037]

[0038] Where i takes the value of a natural number from 1 to n, j takes the value of a natural number from 1 to n, and A ij Represents a directed attack graph G a Middle node v ai and node v aj The adjacency relationship between them;

[0039] Step S205: Quantify the impact X of attack pattern preference on the attack graph using formula (F3). c :

[0040] X c =X a wX o T (F3)

[0041] Among them, the attack preference matrix X of the organization is obtained by the attack preference ranking module for threat intelligence identification. o ∈R l×k l represents attack pattern preference, k represents attack behavior; w is an m-row, k-column behavior alignment weight matrix;

[0042] Step S206: Generate the control and defense diagram;

[0043] Step S207: Generate a control matrix from the attacker's perspective to quantify the influence of attack pattern preferences on the attack graph, as shown in formula (F4):

[0044] G c ={V a E a X c} (F4).

[0045] The aforementioned control-defense graph decision-making method based on defining organizational attack preferences, in step S3, involves analyzing the control-defense matrix based on the attack graph to define organizational attack preferences, generating honeypot services with a focus, and providing decision support for the deployment of defense measures. The specific process is as follows:

[0046] Step S301: Based on the self-defined objectives, assess and define the degree of threat impact of the organization's attack preferences on the target system. The specific process is as follows:

[0047] Step S3011: Given the target P, calculate p in the control diagram according to formulas (F5) and (F6). ij Is it reachable?

[0048]

[0049] P(G c )=[p ij ] nxn =A 0 ∨A 1 ∨...∨A n-1 (F6)

[0050] Among them, A 0 Let v be an n x n identity matrix, and ∨ be the disjunction operation used to find v. ai to v aj Is there a path of length n-1?

[0051] If the target P is unreachable, modify the target P; if it is reachable, construct the target path based on the adjacency matrix in the control graph and add the necessary nodes on the path to form the path point set S. ij ;

[0052] Step S3012: The attack pattern preferences of the organization are assessed and defined using the control matrix to identify the set of threat nodes along the target pathway, as shown in formulas (F7) and (F8):

[0053] S={N(x)|S ij (F7)

[0054] S ij ={v k ∈V a |p ik =1∩p kj =1} (F8)

[0055] For the set of path points S ij When p ik =1 and p kj When = 1, it indicates that node v k It is v i to v jThe path points on the connected path; for the parent node of a path point, define a set N(v) as shown in formula (F9):

[0056] N(v)={v j |(v j ,v i )∈E} (F9)

[0057] When v j to v i The existence of a directed edge indicates that v j It is v i The parent node;

[0058] Step S302: Based on the threat type, guide the generation type of the honeypot service. The specific process is as follows:

[0059] Step S3021: Given a honeypot type set C, make a decision on the honeypot service generation type based on the fact nodes in the node types corresponding to the threat node set S.

[0060] Step S3022: Based on the rule nodes in the node types corresponding to the threat node set S, provide suggestions for the configuration of the honeypot service.

[0061] This invention also discloses a control graph decision system based on defining organizational attack preferences to implement the above method, comprising:

[0062] Attack preference ranking module for threat intelligence-based organization identification: It is used to collect attack information from the honeypot's log server, and through joint search of threat intelligence knowledge graph and external threat intelligence database, it identifies the behavioral patterns of attacking organizations and ranks their attack preferences.

[0063] The attack graph-based control and defense matrix calculation module is used to generate an attack graph from the attacker's perspective by using topology information, asset information and configuration information in the target network, and to define and organize the mapping of attack preferences to attack graph nodes, generate a control and defense graph, and then generate a control and defense matrix for quantifying the impact of attack mode preferences on the attack graph.

[0064] Honeypot Generation Decision Module: Used to analyze the attack graph-based control matrix to define an organization's attack preferences, generating honeypot services with a focus to provide decision support for the deployment of defense measures.

[0065] Compared with the prior art, the present invention has the following advantages:

[0066] 1. Since traditional honeypot / honeypot-based deception defense technology requires certain professional capabilities to complete, this invention proposes a method that uses threat intelligence to jointly attribute attack organizations and designs an attack preference ranking module for threat intelligence-based organizations. It calculates attack pattern preferences based on historical information to achieve targeted and focused defense.

[0067] 2. This invention designs a controllable defense mechanism from the attacker's perspective—the control-defense graph—to assess the threat risk of attack patterns to the target network, predict potential attack trends and strategies in the target network, and enable real-time adjustment of control-defense strategies.

[0068] 3. The controllable defense mechanism based on the control graph designed in this invention effectively bridges the semantic gap between attack mode description and attack graph description, and uses the control matrix to quantitatively evaluate the degree of influence of attack graph nodes on attack modes.

[0069] 4. This invention proposes a honeypot generation decision module, which allows users to define target tasks and automatically generate honeypot service types based on the target network environment and attack patterns. This provides more flexible and faster automatic generation of honeypot services, moving beyond the limitations of manual analysis and decision-making. It significantly saves manpower and time costs for the analysis and deployment of deception defense.

[0070] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0071] Figure 1 This is a flowchart of the control-defense graph decision-making method based on defining organizational attack preferences, as described in this invention.

[0072] Figure 2 This is a schematic diagram of the control-defense graph decision-making method based on defining organizational attack preferences, as described in this invention.

[0073] Figure 3 This is a flowchart illustrating the attack preference ranking of an organization as defined in this invention;

[0074] Figure 4 This is a flowchart of the attack graph generation process of the MulVAL method in this invention. Detailed Implementation

[0075] Example 1

[0076] like Figures 1-4 As shown in this embodiment, the control-defense graph decision-making method based on defining organizational attack preferences includes the following steps:

[0077] Step S1: Collect attack information from the honeypot's log server, and use the joint search of the threat intelligence knowledge graph and the external threat intelligence database to define the behavioral patterns of the attacking organization and rank the attacking organization's attack preferences.

[0078] Step S2: From the attacker's perspective, an attack graph is generated using the topology, asset, and configuration information of the target network. The mapping of attack preferences to attack graph nodes is defined to generate a control graph. Then, a control matrix is ​​generated to quantify the impact of attack mode preferences on the attack graph.

[0079] Step S3: Based on the attack graph-based control and defense matrix analysis to define the organization's attack preferences, honeypot services are generated with a focus to provide decision support for the deployment of defense measures.

[0080] In this embodiment, the specific process of attributing and defining the behavioral patterns of attacking organizations through the joint search of threat intelligence knowledge graph and external threat intelligence database in step S1 is as follows:

[0081] S101. Preprocess the unstructured raw attack information data collected from the honeypot's log server into structured attack information data;

[0082] S102. Determine whether the attack information can be matched in the threat intelligence knowledge graph. If it can be matched, extract the evaluation results of major security vendors. If it cannot be matched, transfer the IP address of the attack information and the associated file information to the VT sandbox.

[0083] S103 and VT Sandbox retrieve related files in the VT library, make API calls based on the hash value of the malicious sample in the extracted attack information, obtain the specific behavioral information of the malicious sample and generate behavioral preference data;

[0084] S104. Extract basic information about the malicious sample, detailed information related to the malicious sample, and the attack organization ID related to the malicious sample from the threat intelligence knowledge graph data.

[0085] S105. A characterization of the malicious sample is formed using basic information and related details of the malicious sample. The attack organization ID associated with this malicious sample is used as the prediction target to construct a training set.

[0086] S106. Characterize the features of malicious samples and predict the attack organization ID as the basis for identifying the organization.

[0087] In this embodiment, the specific process of sorting the attack preferences of the attacking organization in step S1 is as follows:

[0088] Step S107: Retrieve and define the organization's historical attack patterns in the threat intelligence knowledge graph;

[0089] Step S108: Use the behavioral information of the attack pattern to form an attack preference matrix.

[0090] In practice, the sorting strategy can be dynamically adjusted based on historical data and changes in the current network environment, and the final attack preference matrix form can be determined from different perspectives.

[0091] In this embodiment, when retrieving and defining the organization's historical attack patterns in the threat intelligence knowledge graph in step S107, the Cypher statement is used.

[0092] In this embodiment, step S2, which involves generating an attack graph from the attacker's perspective using topology, asset, and configuration information of the target network, employs the MulVAL method. MulVAL (multi-host, multi-stage vulnerability analysis language) is an open-source, publicly available, logic-based attack graph generation tool. MulVAL is based on Datalog, a subset of the Prolog logic programming language. The specific process is as follows:

[0093] Step S201: Given the network topology and asset configuration information of the target network, obtain known vulnerability information based on the asset configuration information; and assume unknown vulnerability information; by assuming unknown vulnerability information, the repair capability of the target network can be tested.

[0094] Step S202: Determine the daily security strategy of the target system based on its task requirements;

[0095] Step S203: Define the node types of the attack graph to obtain the attack graph of the target network.

[0096] In this embodiment, the specific process of defining the mapping from attack preferences to attack graph nodes, generating a control graph, and then generating a control matrix for quantifying the impact of attack mode preferences on the attack graph in step S2 is as follows:

[0097] Step S204: Directed attack graph G of the target network a Formal representation allows for a deeper understanding of the attack graph and its application in subsequent calculations, as shown in formula (F1):

[0098] G a =(V a E a X a )=(A a X a (F1)

[0099] Among them, V a ={v a1 v a2 , ..., v an} is a set of attack graph nodes with n nodes; X a ∈R n×d E represents a d-dimensional feature matrix with n nodes; a Let A be a set of m edges. a ∈{0,1} n×n The adjacency matrix is ​​a binary adjacency matrix, as shown in formula (F2):

[0100]

[0101] Where i takes the value of a natural number from 1 to n, j takes the value of a natural number from 1 to n, and its element A in the i-th row and j-th column is... ij As shown in formula (F2):

[0102]

[0103] Where i takes the value of a natural number from 1 to n, j takes the value of a natural number from 1 to n, and A ij Represents a directed attack graph G a Middle node v ai and node v aj The adjacency relationship between them;

[0104] Step S205: In order to obtain the mapping from the organization's attack preferences to the attack graph nodes, the influence X of the attack graph on the attack pattern preferences is quantified using formula (F3). c :

[0105] X c =X a wX o T (F3)

[0106] Among them, the attack preference matrix X of the organization is obtained by the attack preference ranking module for threat intelligence identification. o ∈R l×k l represents attack pattern preference, k represents attack behavior; w is an m-row, k-column behavior alignment weight matrix; therefore, X c ∈R n×l ;

[0107] Step S206: Generate the control and defense diagram;

[0108] A control graph is a cybersecurity strategy and analysis tool that combines attack patterns / preferences with attack graphs. It primarily takes the attacker's perspective to design a controllable defense mechanism. By comprehensively analyzing attacker preferences and potential attack paths within the target network, it depicts possible attack behaviors and strategies within the network, thereby helping defenders effectively predict and prepare to respond to attacks.

[0109] Building upon this foundation, the core of the control graph lies in providing a method for understanding network defense from an attacker's perspective. It not only displays the relationships between various vulnerabilities in the network but also demonstrates the interaction between these vulnerabilities and network security configurations, as well as the potential threats arising from this interaction. The control graph enables network security managers to more clearly see the various directed attack paths within the network targeting specific attack patterns or preferences. These paths represent the continuous attack actions an attacker might take from the attacker node to the target node.

[0110] Using control graphs, security teams can dynamically adjust and optimize defense strategies based on attacker behavior patterns and preferences. This includes, but is not limited to, modifying network configurations, strengthening security protection for specific nodes, or deploying targeted countermeasures. Therefore, control graphs are not only a visual representation of defense strategies, but also a dynamic, attacker-centric approach to network defense.

[0111] Step S207: Generate a control matrix from the attacker's perspective to quantify the influence of attack pattern preferences on the attack graph, as shown in formula (F4):

[0112] G c ={V a E a X c} (F4).

[0113] A control matrix is ​​a matrix structure used to quantify and represent the attack paths and strategies of a target network attack graph in a control graph. In a control matrix, rows typically represent individual nodes or systems in the network, while columns represent possible attack types or attacker strategies.

[0114] In this embodiment, the attack graph-based control matrix analysis in step S3, which defines the organization's attack preferences, generates honeypot services with a focus, providing decision support for the deployment of defense measures. The specific process is as follows:

[0115] Step S301: Based on the self-defined objectives, assess and define the degree of threat impact of the organization's attack preferences on the target system. The specific process is as follows:

[0116] Step S3011: Given the target P, calculate p in the control diagram according to formulas (F5) and (F6). ij Is it reachable?

[0117]

[0118] P(G c )=[p ij ] nxn =A 0 ∨A 1 ∨...∨A n-1 (F6)

[0119] Among them, A 0 Let v be an n x n identity matrix, and ∨ be the disjunction operation (logical addition / union), used to calculate v. ai to v aj Is there a path of length n-1?

[0120] If unreachable, modify the target P; if reachable, construct target paths (potentially multiple) based on the adjacency matrix in the control graph and add necessary nodes to the paths, forming a path point set S. ij ;

[0121] Step S3012: The attack pattern preferences of the organization are assessed and defined using the control matrix to identify the set of threat nodes along the target pathway, as shown in formulas (F7) and (F8):

[0122] S={N(x)|S ij (F7)

[0123] S ij ={v k ∈V a |p ik =1∩p kj =1} (F8)

[0124] For the set of path points S ij When p ik =1 and p kj When = 1, it indicates that node v k It is v i to v j The path points on the connected path; for the parent node of a path point, define a set N(v) as shown in formula (F9):

[0125] N(v)={v j |(v j ,v i )∈E} (F9)

[0126] When v j to v i The existence of a directed edge indicates that v j It is v i The parent node;

[0127] Step S302: Based on the threat type, guide the generation type of the honeypot service. The specific process is as follows:

[0128] Step S3021: Given a honeypot type set C, make a decision on the honeypot service generation type based on the fact nodes in the node types corresponding to the threat node set S.

[0129] Step S3022: Based on the rule nodes in the node types corresponding to the threat node set S, provide suggestions for the configuration of the honeypot service.

[0130] In summary, this invention designs a control-guard graph decision-making system based on defining organizational attack preferences. The system utilizes alert information generated by honeypots and combines it with knowledge information from a network security knowledge graph oriented towards threat intelligence to analyze attacker behavior patterns and define the characteristics of the attacker organization. By analyzing the organization's historical attack behavior, the system can map possible attack patterns onto the target network's attack graph, thereby creating a dynamically adjustable control-guard graph. By calculating the control-guard matrix, the system dynamically adjusts the characteristics and deployment locations of honeypot services tailored to the defined organizational attack preferences in real time, achieving the effect of slowing down and confusing attackers, thus buying time for the defender in a network attack. Furthermore, it automates the decision-making process for honeypot service types, significantly saving manpower and time costs.

[0131] Example 2

[0132] This embodiment of the control graph decision system for defining organizational attack preferences includes:

[0133] Attack preference ranking module for threat intelligence-based organization identification: It is used to collect attack information from the honeypot's log server, and through joint search of threat intelligence knowledge graph and external threat intelligence database, it identifies the behavioral patterns of attacking organizations and ranks their attack preferences.

[0134] In practice, the attack preference ranking module can also dynamically adjust the ranking strategy based on its historical data and changes in the current network environment.

[0135] The attack graph-based control and defense matrix calculation module is used to generate an attack graph from the attacker's perspective by using topology information, asset information and configuration information in the target network, and to define and organize the mapping of attack preferences to attack graph nodes, generate a control and defense graph, and then generate a control and defense matrix for quantifying the impact of attack mode preferences on the attack graph.

[0136] Honeypot Generation Decision Module: Used to analyze the attack graph-based control matrix to define an organization's attack preferences, generating honeypot services with a focus to provide decision support for the deployment of defense measures.

[0137] The above description is merely a preferred embodiment of the present invention and does not constitute any limitation on the present invention. Any simple modifications, alterations, or equivalent structural changes made to the above embodiments based on the technical essence of the present invention shall still fall within the protection scope of the present invention.

Claims

1. A decision method based on a guard map that defines the preferences of an organization for an attack, characterized in that, The method comprises the following steps: Step S1, collect attack information from the honeypot's log server, attribute define the attack organization's behavior mode through the joint search of threat intelligence knowledge graph and external threat intelligence library, and sort the attack preferences of the attack organization; Step S2, from the perspective of the attacker, generate an attack graph through the topology information, asset information and configuration information in the target network, and map the defined organization attack preference to the attack graph node to generate a guard graph, and then generate a guard matrix for quantitatively calculating the attack pattern preference of the attack graph; Step S3, based on the guard matrix of the attack graph, the analysis of the defined organization attack preference generates a honeypot service with emphasis, providing decision support for the deployment of defense measures; When generating an attack graph from the perspective of the attacker through the topology information, asset information and configuration information in the target network in step S2, the MulVAL method is used, and the specific process is as follows: Step S201, given the network topology and asset configuration information of the target network, obtain the known vulnerability information according to the asset configuration information; and assume unknown vulnerability information; Step S202, determine the daily security policy of the target system according to its task requirements; Step S203, define the node type of the attack graph, and obtain the attack graph of the target network; When mapping the defined organization attack preference to the attack graph node to generate a guard graph, and then generating a guard matrix for quantitatively calculating the attack pattern preference of the attack graph in step S2, the specific process is as follows: Step S204, obtaining a directed attack graph of the target network A formal representation is made, as shown in formula (F1): (F1), wherein, is a set of attack graph nodes with n nodes; represents a d-dimensional feature matrix of n nodes; denotes a set of m edges, is a binary adjacency matrix whose element in the i-th row and the j-th column denotes the presence of an edge between the i-th node and the j-th node; denotes the absence of an edge between the i-th node and the j-th node; as shown in formula (F2): (F2), wherein, the value of n is a natural number from 1 to n, the value of n is a natural number from 1 to n, represents an adjacency relationship between node and node in the directed attack graph . Step S205, quantitatively calculate the impact of attack graph attack mode preference with formula (F3) : (F3), Wherein the attack preference matrix of the organization defined by the organization facing threat intelligence defines the attack preference ordering module , represents the attack mode preference, represents the attack behavior; is a behavior alignment weight matrix of row column Step S206, generate a guard graph; Step S207, generate a guard matrix for quantitatively calculating the attack pattern preference of the attack graph from the perspective of the attacker, as shown in formula (F4): (F4)。 2. The method of claim 1, wherein the method is a guard map decision method based on defining organizational attack preference. When attributing the behavior mode of the attack organization through the joint search of threat intelligence knowledge graph and external threat intelligence library in step S1, the specific process is as follows: S101, preprocess the unstructured raw attack information data collected from the log server of the honeypot into structured attack information data; S102, determine whether the attack information can be matched in the threat intelligence knowledge graph, when it can be matched, extract the evaluation results of major security manufacturers; when it cannot be matched, transmit the IP address of the attack information and the associated file information into the VT sandbox; S103, the VT sandbox retrieves the associated file in the VT library, calls the API according to the hash value of the malicious sample in the extracted attack information, obtains the specific behavior information of the malicious sample and generates behavior preference data; S104, export the basic information of the malicious sample, the detailed information related to the malicious sample, and the attack organization ID related to the malicious sample from the threat intelligence knowledge graph data; S105, form a portrait of the malicious sample with the basic information of the malicious sample and the detailed information related to the malicious sample, take the attack organization ID related to the malicious sample as a prediction target, and construct a training set; S106, characterize the features of the malicious sample and predict the attack organization ID as the defined organization.

3. A guard map based decision method for defining organizational attack preference bias as claimed in claim 2, wherein: The specific process for sorting the attack preferences of the attack organization in step S1 is as follows: Step S107, searching the historical attack mode of the defined organization in the threat intelligence knowledge graph; Step S108, forming an attack preference matrix using the behavior information of the attack mode.

4. The method of claim 3, wherein the decision method is based on a guard chart that defines the organization's attack preference. In step S107, the historical attack mode of the defined organization is searched in the threat intelligence knowledge graph using a Cypher statement.

5. The method of claim 1, wherein the method is a guard map decision method based on defining organizational attack preference, characterized in that: In step S3, the analysis of the attack preference of the defined organization based on the guard matrix of the attack graph generates honeypot services with emphasis, and provides decision support for the deployment of defense measures. The specific process is as follows: Step S301, evaluating the threat degree of the attack preference of the defined organization to the target system according to the self-defined target; Step S302, guiding the generation type of the honeypot service according to the threat type.

6. A guard map based decision system implementing the method of claim 1, wherein, It includes: The attack preference sorting module of the threat intelligence facing the defined organization: used for collecting attack information from the log server of the honeypot, searching the threat intelligence knowledge graph and the external threat intelligence library, attributing the behavior mode of the defined attack organization, and sorting the attack preference of the defined attack organization; The guard matrix calculation module based on the attack graph: used for generating an attack graph from the perspective of the attacker through the topology information, asset information and configuration information in the target network, mapping the attack preference of the defined organization to the nodes of the attack graph, generating a guard graph, and generating a guard matrix for quantitatively calculating the attack graph affected by the attack mode preference; The honeypot generation decision module: used for analyzing the attack preference of the defined organization based on the guard matrix of the attack graph, generating honeypot services with emphasis, and providing decision support for the deployment of defense measures.

Citation Information

Patent Citations

  • Control and defense graph construction method for four-honey dynamic defense system

    CN118233223A

  • Network security protection method and system based on virtual cloud

    CN118631592A