Network threat intelligence analysis method and system

By adopting the DeBERTa model and attack intelligence link method in cyber threat intelligence analysis, the analysis efficiency and visualization problems in the existing technology are solved, and efficient extraction, classification and visualization of cyber threat intelligence are achieved, and analysis accuracy and efficiency are improved.

CN120105149APending Publication Date: 2025-06-06CENT CHINA BRANCH OF STATE GRID CORP OF CHINA
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510171222.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The prior art is difficult to efficiently analyze and visualize cyber threat intelligence, especially when dealing with unstructured natural language data and rapidly updated cyber attack scenarios, where analysis accuracy and efficiency are problems.

Method used

The integrated model and attack intelligence link based on the DeBERTa model are adopted to achieve efficient extraction, classification and visualization of network threat intelligence through naming entity recognition, precise classification of attack behaviors within the intelligence, and construction of attack intelligence links.

Benefits of technology

It improves the accuracy and efficiency of cyber threat intelligence analysis, can intuitively demonstrate the relationship between the attacker and the target and the connection between different attack types, helping enterprises or organizations better deal with cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105149A_ABST
    Figure CN120105149A_ABST
Patent Text Reader

Abstract

The invention discloses a network threat intelligence analysis method and system, and the method comprises the steps: carrying out named entity recognition, designing a DeBERTa-CRF-BiGRU composite model for named entity analysis, extracting key entities from massive threat intelligence data, and laying a foundation for subsequent intelligence analysis; the method comprises the following steps: performing accurate classification of attack behaviors in intelligence, quickly identifying and responding to potential network threats based on basic data extracted by named entity identification, further refining and classifying intelligence, and providing structured information for constructing an attack intelligence chain; constructing an attack intelligence chain, on the basis of an attack chain framework, constructing the attack intelligence chain from the network threat information extracted in the first two steps, and displaying attack source, path, target and attack type information by using a graphical method; through connection of the nodes and the edges, the relation between the attacker and the target and the relation between different attack types are visually displayed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an analysis method and a system thereof, and in particular to a network threat intelligence analysis method and a system thereof based on an integrated DeBERTa model and an attack intelligence chain. Background Art

[0002] With the promotion of 5G technology and the popularization of Internet of Things (IoT) technology, cyberspace continues to expand, and new network attack surfaces are also expanding, increasing the possibility of network attacks. Traditional threat defense methods include real-time traffic monitoring, user identity authentication, code vulnerability review, etc. Although they can improve network security protection capabilities to a certain extent, they are difficult to cope with rapidly updated and iterated network threats. In order to make up for the shortcomings of traditional network security protection measures, many companies and organizations have begun to combine and use network threat intelligence. However, threat intelligence information is usually presented in the form of unstructured natural language. These data formats are different and lack unified standards, which brings great challenges to the extraction and analysis of information. The deep learning methods used in network threat analysis today have long training time and low efficiency. Furthermore, how to visualize the attack logic of these extracted and identified threat content information in an intuitive and easy-to-understand way is also an important problem.

[0003] In the digital age, with the promotion of 5G technology and the popularization of IoT, cyberspace is constantly expanding, and new network attack surfaces are also expanding, increasing the possibility of network attacks, and network threats are becoming increasingly serious. At present, the variants of network attacks are becoming more and more diverse. Attackers use various digital technologies and artificial intelligence to continuously create new attack methods. These attack methods are updated and iterated at a very fast speed. Often, new attack methods have appeared before the security protection measures are fully deployed. This rapid iteration speed puts tremendous pressure on network security protection. In addition, there may be some undiscovered vulnerabilities in network equipment or software systems, even zero-day vulnerabilities. Zero-day vulnerabilities refer to security vulnerabilities that have been discovered but have not been disclosed or patched. Attackers can use these vulnerabilities to launch attacks, and victims often realize the existence of problems only after the attack occurs. Once these vulnerabilities are exploited by attackers, they will pose a fatal threat to network security. This has led to the expansion of the attack surface and the continuous escalation of network threats, posing a challenge to traditional network security defense. Therefore, many organizations have begun to use network threat intelligence to respond to emerging network threats in a timely manner. However, current methods still face the problem of balancing the accuracy and efficiency of analysis, as well as the difficulty of visual presentation.

[0004] Existing technologies, such as an automatic cyber threat intelligence (CTI) analysis method called K-CTIAA[1], can extract threat actions from unstructured CTI data by using pre-trained models and knowledge graphs. K-CTIAA improves the automation level and efficiency of threat analysis, but it also relies on pre-trained models and knowledge graphs. If these models or graphs are inaccurate or incomplete, they may have a negative impact on the extraction of threat behaviors and the accuracy of analysis results. In addition, Ehtsham Irshad et al.[2] developed a mechanism to extract features from CTI reports to attribute or profile cyber threat actors (CTAs), but the deep learning model takes a long time to train, which is not conducive to the timely update of CTI. JO H et al.[3] developed a new CTI system called Vulcan. Vulcan focuses on extracting descriptive or static CTI data from unstructured text and makes up for the shortcomings of IOC-centric CTI systems in providing threat technical details and tracking frequently changing infrastructure by determining the semantic relationships between these data. However, the stability of the Vulcan system may be affected by the complexity of unstructured text.

[0005] [1]LI ZX, LI YJ, LIU YW, et al.K-CTIAA: automatic analysis of cyberthreat intelligence based on a knowledge graph[J].Symmetry, 2023, 15(2):337.

[0006] [2] Author: Ehtsham Irshad, Abdul Basit Siddiqui Title: Cyber ​​threat attribution using unstructured reports in cyber threat intelligence

[0007] [3] JO H, LEE Y, SHIN S. Vulcan: Automatic extraction and analysis of cyber threat intelligence from unstructured text [J]. Computers&Security, 2022, 120:102763.

[0008] For existing technologies, first of all, in order to analyze cyber threats, security experts rely on a large amount of threat information, which is usually transmitted in the form of natural language. Natural language information is usually unstructured, which makes it extremely difficult to extract useful information from it. Intelligence may also contain a large amount of text data, network logs, system alerts, etc. These data formats are different and lack unified standards, which brings great challenges to the extraction and analysis of information. In addition, the existing construction models are limited in their semantic understanding ability. This means that although we may have identified certain threat content, the model is not strong enough to understand the deep meaning and contextual associations behind these contents. This limitation leads to poor generalization ability for various emerging attack scenarios and knowledge types. In other words, existing models are difficult to adapt to the evolving network attack patterns and cannot effectively identify and respond to new threats. Furthermore, even if we can extract and identify threat content from unstructured threat intelligence, how to convert this information into intuitive and easy-to-understand attack logic visualization is also a difficult problem. This not only requires a high level of technical processing capabilities, but also requires extremely high professionalism from analysts. Analysts need to have deep knowledge of network security to accurately interpret and present attack logic, which is a considerable challenge for many organizations. Summary of the invention

[0009] In view of these problems, we propose a cyber threat intelligence analysis method based on DeBERTa, a decoding-enhanced BERT based on decoupled attention and an integrated model of pre-trained language representation based on BERT (Transformer-based bidirectional encoder) and attack intelligence chain, which is characterized by:

[0010] Step 1: Perform named entity recognition. A composite model based on DeBERTa is designed for named entity analysis, which can extract key entities from massive threat intelligence data and lay the foundation for subsequent intelligence analysis.

[0011] Step 2: Accurately classify the attack behaviors in the intelligence, quickly identify and respond to potential network threats based on the basic data extracted by named entity recognition, further refine and classify the intelligence, and provide structured information for building the attack intelligence chain;

[0012] Step 3: Build an attack intelligence chain. Based on the attack chain framework, the network threat information extracted through the above two steps is constructed into an attack intelligence chain. A graphical method is used to display the source, path, target, and attack type information of the attack. Through the connection of nodes and edges, the relationship between the attacker and the target, as well as the connection between different attack types, is intuitively displayed.

[0013] Beneficial Effects

[0014] (1) First, the recognition of named entities in CTI was completed, solving the problem of difficulty in extracting unstructured natural language intelligence.

[0015] (2) Secondly, the classification and identification of attack behaviors in CTI were completed, which improved the accuracy and efficiency of identifying network attack behaviors.

[0016] (3) Finally, based on the MITRE ATT&CK framework, the network threat information extracted through the above model is constructed into an attack intelligence chain in the form of a graph, which facilitates enterprises or organizations to analyze and communicate threat intelligence in a visual form. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a schematic diagram of the main method flow of the present invention;

[0018] Figure 2 This is the basic structure diagram of the DeBERTa-CRF-BiGRU composite model of the present invention;

[0019] Figure 3 A schematic diagram of the network threat attack intelligence chain construction of the present invention. DETAILED DESCRIPTION

[0020] The present invention discloses a network threat intelligence analysis method based on an integrated DeBERTa model and an attack intelligence chain, comprising the following steps:

[0021] Step 1: Perform named entity recognition using a DeBERTa-CRF-BiGRU composite model, whose basic structure is as follows: Figure 2 As shown in the figure, it is used for named entity analysis. Through this step, key entities such as attackers, targets, attack types, etc. can be extracted from massive threat intelligence data, laying a solid foundation for subsequent intelligence analysis:

[0022] This step further includes the following:

[0023] Step 1: Use DeBERTa to extract feature representations from the text. First, it passes through the Tokenizer layer and uses BBPE (byte-level byte pair encoding) to segment the text into meaningful sub-word units. Then it enters the Type Embedding layer, which can distinguish different tags and help the model understand the relationship and context between sentences. Subsequently, the text enters the Sub-word Embedding layer, which converts the words into 768-dimensional vector representations to capture the semantic information and contextual relationships of the words. Finally, the core mechanisms of DeBERTa, including the attention decoupling mechanism and the enhanced mask decoder, are used to further process and optimize these feature representations.

[0024] Step 2: Capture long-term dependencies in text sequences and extract sequence information. GRU (Gated Recurrent Unit) is an improved RNN (Recurrent Neural Network) that solves the problems of gradient vanishing and insufficient long-term dependency learning ability that may occur in traditional RNN when processing long sequences. Compared with the LSTM (Long Short-Term Memory Network) model, GRU simplifies the model structure and merges the input gate, output gate, and forget gate into update gate and reset gate, which makes the model training time shorter, with fewer parameters and simpler structure, thus saving training costs. GRU mainly consists of two gating mechanisms: Update Gate and Reset Gate. These two gating mechanisms allow the model to dynamically decide how much past information to retain in each time step and the extent to which the current hidden state is updated.

[0025] When data enters the GRU, it determines which data can flow to the update gate at the next moment:

[0026] ζ t =σ(W z ·[h t-1 ,x t ]) (1)

[0027] Among them, σ represents the sigmoid function, the symbol · represents the dot product operation relationship, t represents the current time, t-1 represents the previous time, and z t is the output of the update gate, W z is the weight matrix, h t-1 is the hidden state at the previous moment, x t is the input information at the current moment;

[0028] The reset gate that determines which past data needs to be lost:

[0029] r t =σ(w r ·[h t-1 ,x t ]) (2)

[0030] h t =tanh(w·[r t * h t-1 ,x t ]) (3)

[0031]

[0032] Among them, σ represents the sigmoid function, the symbol · represents the dot product operation relationship, tanh represents the tanh function, r t is the output of the reset gate, W ris a reset gate weight matrix, where r represents the reset gate, W is the weight matrix, and h t-1 is the hidden state of the previous moment, h t is the hidden state passed to the next moment, x t is the input information at the current moment, z t represents the update gate;

[0033] Step 3: Consider the dependencies between labels and predict the best label sequence through global optimization. Here, CRF (conditional random field) is used as the last layer of this model. It is an undirected graph model that combines the characteristics of the maximum entropy model and the hidden Markov model. In the prediction task, it can consider the influence of the current prediction result on the adjacent context information or state. Named entity recognition is usually regarded as a sequence labeling process. In the CRF layer of the model, the start, internal and non-entity parts of the entity are marked with BIO marking (Begin, Inside, Outside). BIO marking is a standard marking format used to mark the start, internal and non-entity parts of entities in text.

[0034] Step 2: Accurately classify the attack behaviors in the intelligence, quickly identify and respond to potential network threats based on the basic data extracted by named entity recognition, further refine and classify the intelligence, and provide structured information for building the attack intelligence chain.

[0035] This step is based on the pre-trained language model and LightGBM classifier to quickly and accurately identify network threat information. The steps are as follows:

[0036] Step 1: First, enter the preprocessing stage, use DeBERTa to segment the input text, add special tags, and generate the corresponding input ID and attention mask. Then, the text is converted into a word embedding representation, and position encoding is added to capture the position information of the word in the sequence. In the encoder layer, the input passes through a multi-layer Transformer encoder, each layer contains self-attention and feedforward neural networks. DeBERTa's self-attention mechanism is implemented here through a decoupled attention mechanism, which enhances the model's learning of representations of different parts.

[0037] Step 2: Then, through SVD (singular value decomposition), the features that contribute most to the data manifold structure can be identified, and feature dimensionality reduction and selection can be achieved. It can not only reduce the dimension of the data, but also retain the most valuable information in the data.

[0038] SVD works by decomposing any input matrix A into the product of three matrices:

[0039] A=UΣV T (5)

[0040] Among them, A is an m×n matrix, U is an m×n unitary matrix, and AA T contains the eigenvectors, Σ is an m×n diagonal matrix containing the singular values ​​of the matrix A, V T is an n×n unitary matrix containing A T The eigenvector of A.

[0041] Next, these selected features are used to construct a new low-dimensional feature matrix, which becomes the basis for subsequent data analysis and modeling. The uniqueness of SVD in feature selection is that it can capture the global structure of the data, rather than relying solely on local statistical characteristics, which will help to extract features with higher relevance to the attack behavior classification task.

[0042] Step 3: Finally, LightGBM is a decision tree algorithm that solves the task of classifying attack behaviors. It adopts a leaf-node-based growth strategy when constructing a decision tree, which means that the split of each tree is conditional and whether to expand new leaves is determined by the gain. A notable feature of LightGBM is exclusive feature bundling, which reduces the dimension of the data by combining exclusive features, thereby increasing processing speed. GBDT (Gradient Boosted Decision Tree) is an ensemble model based on decision trees trained over multiple iterations. GBDT trains decision trees by fitting the negative gradient, that is, the residual error, at each iteration. It is a method of describing the GBDT model f(x) as a collection of decision trees.

[0043]

[0044] Where M is the number of trees in the model, γ m is the learning rate, D(x;θ m ) is the mth decision tree, x is the input data, θ m is the tree parameter. By minimizing m The relevant loss function L, trains the mth tree to predict the residual error.

[0045]

[0046] in, It is the value of the variable that makes the following formula reach the minimum value, y i is the target variable, x i is the input data, f m-1 (x i ) is the prediction of the previous tree, and N is the number of training instances. Optimization is usually performed using gradient descent, which calculates the gradient of the loss function based on the parameters of the tree.

[0047] Step 3: Build an attack intelligence chain. Based on the attack chain framework, the network threat information extracted in the first two steps is constructed into an attack intelligence chain, and key information such as the source, path, target, and attack type of the attack is displayed graphically. Through the connection of nodes and edges, the relationship between the attacker and the target in the threat intelligence, as well as the connection between different attack types, can be intuitively displayed. The principle structure is as follows: Figure 3 shown.

[0048] Step 1: First, enumerate each node k in the attack intelligence chain and find the alignment candidate node for each node i in the template by calculating the alignment score of node Γ(i:k). The alignment score between two nodes is calculated by formulas (8) and (9):

[0049]

[0050] Where type is a node attribute, if node i and node k have different types, then the alignment score will be zero. Otherwise, they will get a basic type match score γ.

[0051] Sim(i,k)=Max(sim(i IOC ,k IOC ),sim(i NLP ,k NLP ))(9)

[0052] Next, Max represents the maximum value, and sim represents the similarity calculation. The similarity between node attributes is evaluated by checking and calculating the similarity between the indicator of compromise (IOC) and the natural language description (NLP) one by one (expressed as Sim(i,k)). Once the alignment score of a node meets the pre-set threshold, it is recorded as a candidate match in the list of the corresponding template node.

[0053] Step 2: Then align the chain using G a and G t Represent the attack graph and template graph respectively, traverse all potential node candidates, use i to represent the node in the template graph, j to represent the template in the attack graph, and convert Γ(G a ) is calculated into two parts: one is the node-level alignment score Γ N (G t ::G a ), and the other part is the edge-level alignment score Γ E (G t ::G a ). The alignment score between the attack mode template and the attack chain is evaluated according to formulas (10), (11) and (12):

[0054]

[0055] When performing node-level alignment, i occur Represents the number of times a node appears, and calculates the alignment score Γ for each node N (G t ::G a ), and weighted sum them. The weight is determined according to the frequency of the node in the template. Although the traversal method is used, the computational overhead of the entire algorithm is acceptable due to the limited size of the attack graph and attack mode template. It can strengthen the important entities that are common in multiple reports and the relationships between them.

[0056]

[0057] Edge-level alignment Γ E (G t ::G a ) score, i and j are two nodes in the template graph, i→j represents the edge formed by the two nodes, and k and l are two nodes in the template graph, k→l represents the edge formed by the two nodes, and the subscript occur represents the number of times the edge occurs. The edge-level alignment score considers three factors: the alignment scores Γ(i:k) and Γ(j:l) of the two end nodes of the dependency relationship, the shortest path length C between the two ends of the dependency relationship in the attack graph, and the edge-level alignment score Γ(i:k) and Γ(j:l) of the two end nodes of the dependency relationship. min (k→l), and the number of node occurrences recorded in the template; if there is no direct connection between two nodes, the dependency score between them is considered infinite; finally, these alignment scores are normalized to be in the range of 0 to 1; although the traversal algorithm is used, the computational cost of the entire algorithm is controllable due to the limited size of the attack graph and attack mode template;

[0058]

[0059] Step 3: After calculating the alignment score for each candidate attack method, compare these scores with the set standard threshold to screen out subgraphs that meet the attack method alignment requirements; a single node in the attack graph may match multiple attack methods, provided that as long as the alignment scores of these subgraphs reach or exceed the threshold we set, the corresponding attack method can be identified multiple times in the graph; use the results of graph alignment to integrate the common information contained in the technical template into the corresponding links of the attack intelligence chain.

[0060] The present invention is based on a network threat analysis method based on the DeBERTa integrated model and the attack intelligence chain. First, we built a DeBERTa-BiGRU-CRF model for named entity recognition. DeBERTa provides powerful contextual understanding to accurately identify entity boundaries and extract key named entity information. Secondly, we combine DeBERTa with the LightGB model, extract input text features through singular value decomposition (SVD), and use LightGBM for fast classification to ensure efficiency. Finally, the information of the first two steps is integrated, and an attack intelligence chain is built based on the ATT&CK framework to graphically display the attack source, path, target and type. To help decision makers analyze network threat intelligence efficiently and intuitively. --The technical solution summarized in "first / second / last" does not correspond to the technical solution claimed for protection in this invention, please modify and adjust. The effectiveness of the method is confirmed by experimental results. The proposed method is generally superior to other models in threat classification prediction accuracy and recall rate, with average values ​​reaching 98.49% and 94.9% respectively. It ensures the efficient operation of the network and provides new perspectives and tools for network security protection.

[0061] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions only describe the principles of the present invention. The present invention may be subject to various changes and improvements without departing from the spirit and scope of the present invention. These changes and improvements fall within the scope of the present invention. The scope of protection claimed by the present invention is defined by the attached claims and their equivalents.

Claims

1. A network threat intelligence analysis method based on the DeBERTa integrated model and attack intelligence chain, characterized by: Step 1: Perform named entity recognition and use a composite model based on DeBERTa for named entity analysis to extract key entities from massive threat intelligence data, laying the foundation for subsequent intelligence analysis; the composite model of DeBERTa is an integrated model of pre-trained language representation based on a decoder-enhanced BERT with decoupled attention and a bidirectional encoder BERT based on Transformer; Step 2: Accurately classify the attack behaviors in the intelligence, quickly identify and respond to potential network threats based on the basic data extracted by named entity recognition, further refine and classify the intelligence, and provide structured information for building the attack intelligence chain; Step 3: Construct an attack intelligence chain. Based on the attack chain framework, the network threat information extracted through the above two steps is constructed into an attack intelligence chain. A graphical method is used to display the source, path, target, and attack type information of the attack; through the connection of nodes and edges, the relationship between the attacker and the target, as well as the connection between different attack types, is intuitively displayed.

2. The network threat intelligence analysis method based on the DeBERTa integrated model and attack intelligence chain according to claim 1 is characterized by: The step 1 comprises the following steps: Step 1: Use DeBERTa to extract feature representations from text. First, the text is segmented into meaningful subword units using byte-level byte pair encoding (BBPE) through the Tokenizer layer. Then, the text is segmented into meaningful subword units using the Type Embedding layer to distinguish different tokens, helping the model understand the relationship and context between sentences. Subsequently, the text enters the Sub-word Embedding layer, which converts the words into 768-dimensional vector representations to capture the semantic information and contextual relationships of the words. Finally, the core mechanisms of DeBERTa, including the attention decoupling mechanism and the enhanced mask decoder, are used to further process and optimize these feature representations. Step 2: Capture the long-term dependencies in the text sequence and extract the data sequence information through the gated recurrent unit GRU, so that the network can selectively forget some unimportant information while retaining the long-term dependency information; When data enters the GRU, it determines which data can flow to the update gate at the next moment; z t =σ(W z ·[h t-1 ,x t ]) (1) Among them, σ represents the sigmoid function, the symbol · represents the dot product operation relationship, t represents the current time, t-1 represents the previous time, and z t is the output of the update gate, W z is the weight matrix, h t-1 is the hidden state at the previous moment, x t is the input information at the current moment; The reset gate that determines which past data needs to be lost: r t =σ(W r ·[h t-1 ,x t ]) (2) Among them, σ represents the sigmoid function, the symbol · represents the dot product operation relationship, tanh represents the tanh function, r t is the output of the reset gate, W r is a reset gate weight matrix, where r represents the reset gate, W is the weight matrix, and h t-1 is the hidden state of the previous moment, h t is the hidden state passed to the next moment, x t is the input information at the current moment, z t represents the update gate; Step 3, predict the best label sequence through global optimization, use conditional random field CRF as the last layer of this model, and combine the characteristics of maximum entropy model and hidden Markov model.

3. The network threat intelligence analysis method based on the DeBERTa integrated model and attack intelligence chain according to claim 1 is characterized by: The step 2 comprises the following steps: Step 1: First, enter the preprocessing stage, use DeBERTa to segment the input text, add special tags, and generate the corresponding input ID and attention mask; Subsequently, the text is converted into word embedding representations, and positional encoding is added to capture the position information of words in the sequence. At the encoder layer, the input passes through multiple layers of Transformer encoders, each of which contains self-attention and feed-forward neural networks. DeBERTa's self-attention mechanism is implemented here through a decoupled attention mechanism, which enhances the model's learning of representations of different parts. Step 2: Through singular value decomposition (SVD), the features that contribute most to the data manifold structure can be identified, and feature dimensionality reduction and selection can be achieved; SVD works by decomposing any input matrix A into the product of three matrices: A=UΣV T (5) Among them, A is an m×n matrix, U is an m×n unitary matrix, and AA T contains the eigenvectors, Σ is an m×n diagonal matrix containing the singular values ​​of the matrix A, V T is an n×n unitary matrix containing A T The eigenvector of A; Next, a new low-dimensional feature matrix is ​​constructed using the selected features; Step 3: Solve the task of attack behavior classification through LightGBM. It adopts a leaf-based growth strategy when building a decision tree, which means that the split of each tree is conditional and whether to expand new leaves is determined by the gain. The gradient boosting decision tree GBDT is based on a decision tree trained through multiple iterations. The decision tree is trained by fitting the negative gradient in each iteration. The GBDT model f(x) is described as a set of decision trees: Where M is the number of trees in the model, γ m is the learning rate, D(x;θ m ) is the mth decision tree, x is the input data, θ m is the parameter of the tree; by minimizing m The loss function Train the mth tree to predict the residual error: in, It is the value of the variable that makes the following formula reach the minimum value, y i is the target variable, x i is the input data, f m-1 (x i ) is the prediction value of the previous tree, and N is the number of training instances; Finally, an attack intelligence chain is constructed. Based on the attack chain framework, the network threat information extracted through the first two steps is constructed into an attack intelligence chain, and key information such as the source, path, target, and attack type of the attack is displayed using a graphical method; through the connection of nodes and edges, the relationship between the attacker and the target in the threat intelligence, as well as the connection between different attack types, can be intuitively displayed.

4. The network threat intelligence analysis method based on the DeBERTa integrated model and attack intelligence chain according to claim 1 is characterized by: The step 3 comprises the following steps: Step 1: First, enumerate each node k in the attack intelligence chain, and find the alignment candidate node for each node i in the template by calculating the alignment score of node Γ(i:k); the alignment score between two nodes is calculated by formulas (8) and (9): Where type is a node attribute. If node i and node k have different types, the alignment score will be zero; otherwise, they will get a basic type matching score γ. Sim(i,k)=Max(sim(i IOC ,k IOC ),sim(i NLP ,k NLP )) (9) Next, Max represents the maximum value, and sim represents the similarity calculation. The similarity between node attributes is evaluated by checking and calculating the similarity between the indicator of compromise (IOC) and the natural language description (NLP) one by one, expressed as Sim(i,k). Once the alignment score of a node meets the preset threshold, it is recorded as a candidate match in the list of the corresponding template node. Step 2: Then align the chain using G a and G t Represent the attack graph and template graph respectively, traverse all potential node candidates, use i to represent the node in the template graph, j to represent the template in the attack graph, and convert Γ(G a ) is calculated into two parts: one is the node-level alignment score Γ N (G t ::G a ), and the other part is the edge-level alignment score Γ E (G t ::G a ); the alignment score between the attack mode template and the attack chain is evaluated according to formulas (10), (11) and (12): When performing node-level alignment, i occur Represents the number of times a node appears, and calculates the alignment score Γ for each node N (G t ::G a ), and weighted sum them; the weight is determined according to the frequency of the node in the template. Although the traversal method is used, the computational overhead of the entire algorithm is acceptable due to the limited size of the attack graph and attack mode template; important entities that are common in multiple reports and the relationships between them can be strengthened; Edge-level alignment Γ E (G t ::G a ) score, i and j are two nodes in the template graph, i→j represents the edge formed by the two nodes, and k and l are two nodes in the template graph, k→l represents the edge formed by the two nodes, and the subscript occur represents the number of times the edge occurs; the edge-level alignment score considers three factors: the alignment scores Γ(i:k) and Γ(j:l) of the two end nodes of the dependency relationship, the shortest path length C between the two ends of the dependency relationship in the attack graph min (k→l), and the number of node occurrences recorded in the template; if there is no direct connection between two nodes, the dependency score between them is considered infinite; finally, these alignment scores are normalized to be in the range of 0 to 1; although the traversal algorithm is used, the computational cost of the entire algorithm is controllable due to the limited size of the attack graph and attack mode template; Step 3: After calculating the alignment score for each candidate attack method, compare these scores with the set standard threshold to screen out subgraphs that meet the attack method alignment requirements; a single node in the attack graph may match multiple attack methods, provided that as long as the alignment scores of these subgraphs reach or exceed the threshold we set, the corresponding attack method can be identified multiple times in the graph; use the results of graph alignment to integrate the general information contained in the technical template into the corresponding links of the attack intelligence chain.

5. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored program, wherein the program controls the device where the non-volatile storage medium is located to execute the method according to any one of claims 1 to 4 when the program is executed.

6. A network threat intelligence analysis system integrating DeBERTa model and attack intelligence chain, characterized in that: It comprises a processor and a memory; the memory stores computer-readable instructions, and the processor is used to execute the computer-readable instructions, wherein the computer-readable instructions execute the method described in any one of claims 1 to 4 when executed.

Citation Information

Cited By

  • Attack chain detection model training method, attack chain detection method, attack chain detection device and vehicle

    CN120915607A

  • Security alarm processing method and device, equipment and storage medium

    CN121217467A

  • Security alarm processing method, device, equipment and storage medium

    CN121217467B