Threat assessment method based on logic attack graph, ATTCK and CVSS
By constructing a logical attack graph based on ATT&CK and CVSS, and combining it with Nessus and MulVAL tools, we have achieved accurate reconstruction and risk assessment of potential attack paths in network systems. This solves the problems of coarse expression granularity and incomplete assessment in existing technologies, and provides a more accurate and comprehensive security assessment method.
Patent Information
- Application Number
- CN202510914586.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-12-09
AI Technical Summary
Existing attack graph tools suffer from problems such as coarse-grained representation, difficulty in accurately reconstructing attack paths, and inability to effectively integrate logical attack graphs, ATT&CK, and CVSS when expressing and assessing cybersecurity threats, resulting in inaccurate and incomplete security assessments.
By employing the minimum dependency set theory and combining ATT&CK and CVSS, a logical attack graph is constructed. System information is obtained through the Nessus vulnerability scanning tool, and the attack chain is generated using the MulVAL tool. By combining the ATT&CK and CVSS evaluation metrics, node risk scores are calculated and normalized to achieve accurate assessment of attack paths and node risks.
It improves the accuracy of attack path reconstruction and the comprehensiveness of system risk assessment, enabling more accurate identification of key threat paths and providing more reliable defense measures recommendations.
Smart Images

Figure CN121098526A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of network security analysis, and particularly relates to a threat evaluation method based on a logical attack graph, ATT&CK and CVSS. BACKGROUND
[0002] Attack graph, as an abstract model for potential attack intentions in network environment, has important significance in the field of network security analysis. Many researchers have successively proposed various forms of attack graphs, aiming at in-depth analysis and evaluation of enterprise network security. With the continuous advancement of related technologies, existing attack graph tools have the ability to perform attack graph calculation and construction for networks with thousands of machines, laying a solid technical and theoretical foundation for accurate quantification and visual analysis of large-scale enterprise network security situation. Attack graph uses nodes and edges to represent security threats and their relationships in the system. Nodes cover system attributes, states or attack steps, and edges represent state transitions or dependency relationships. With the help of attack graph, security personnel can quickly familiarize themselves with the attack path and pain point distribution in the system. Logical attack graph is an extension of attack graph. MulVAL, as an open-source framework for building logical attack graphs, is based on Prolog logical reasoning and can analyze and evaluate attack paths more finely. It has excellent scalability and can generate customized attack graphs according to different situations. It builds attack steps and system states into logical formulas, uses logical reasoning technology, and uses pre-set known facts to explore various possible attack paths and their impacts, thereby providing detailed attack path analysis for complex systems.
[0003] Even though attack graph can achieve efficient construction, the scale and complexity of the structure it presents are so large and complex that it is difficult to understand. At the same time, due to the ambiguous meaning of nodes and the rough and simple expression granularity, it greatly increases the difficulty of security personnel's analysis and evaluation work. Even if security personnel can quickly realize that the attacker has the ability to penetrate the system, they still face many difficulties when trying to accurately identify which privileges and vulnerabilities play a decisive key role in the attacker's successful intrusion. AssetRank is a threat assessment method for analyzing logical attack graphs (Sawilla R E, Ou X. Identifying critical attack assets in dependency attack graphs [C] / / Computer Security-ESORICS 2008: 13th European Symposium on Research in Computer Security, Málaga, Spain, October 6-8, 2008. Proceedings 13. Springer Berlin Heidelberg, 2008: 18-34.), which focuses on analyzing the different semantics of logical attack graphs, combining public CVSS vulnerability data to calculate node threat scores, reflecting the importance of nodes in system attacks. In this way, security personnel can identify and evaluate the core threats and potential attack paths in the system, and then determine the priority and improvement method of system protection measures. TriAssetRank (Bouom A L P T, Lienou J P, Geh WE, et al. TriAssetRank: Ranking Vulnerabilities, Exploits, and Privileges for Countermeasures Prioritization [J]. IEEE Transactions on Information Forensics and Security, 2024.) is based on AssetRank, introduces an optimized and improved threat score calculation method, focuses on analyzing the risk scores of nodes and edges from the perspectives of vulnerabilities, exploits, and privileges, and introduces the influence of user behavior on the importance of nodes. However, how to extract priorities from a large amount of information and effectively use scarce manpower, financial resources, and resources to protect system security is also an important problem that security personnel must consider.
[0004] MulVAL is initially designed for the traditional network model in the early years, and the corresponding rules are relatively simple. In the face of new network architecture, highly complex and close system interaction scenarios, and increasingly diverse, complex and highly concealed attack methods, MulVAL cannot fully express these network environments and attack methods, and lacks effective integration of detailed attack techniques and globally applicable vulnerability assessment standards. AssetRank can only assess traditional attack paths described by MulVAL, and cannot effectively identify and analyze new attack paths and risk factors. On the other hand, the ATT&CK framework focuses on the analysis of attack tactics and techniques, and CVSS mainly scores the severity of vulnerabilities. Each of the three has limitations, and there is a lack of a risk assessment method that can effectively integrate logical attack graphs, ATT&CK and CVSS, which cannot provide more accurate and comprehensive decision-making basis for target network systems. SUMMARY
[0005] The main purpose of the present application is to overcome the shortcomings and deficiencies of the prior art, and to provide a threat assessment method based on logical attack graph, ATT&CK and CVSS, which aims to accurately quantify the severity of security risks and deeply analyze potential risk factors in network systems.
[0006] In order to achieve the above purpose, the technical scheme adopted by the present application is as follows: The present application provides a threat assessment method based on logical attack graph, ATT&CK and CVSS, comprising the following steps: Based on the theory of minimal dependence set, according to the content of tactical classification, technical description and reference cases in ATT&CK tactics and techniques, the pre-information required for successful implementation of the technology is obtained and the predicate parameter is set, the necessary minimum condition set required for reasoning rules is selected according to the preset target, and finally the rule set required for MulVAL tool input is constituted; the pre-information includes system environment conditions and the permissions already possessed by the attacker; The scanning results of the target system are obtained by using the Nessus vulnerability scanning tool, and the input file of the MulVAL tool is constructed; Based on the rule set and the input file, the XSB engine and the built-in rule library of the MulVAL tool are called to generate a logical attack graph with reverse attack behavior granularity and to construct an attack chain of the target system; the node types in the logical attack graph include technical nodes and vulnerability nodes; According to the ATT&CK technique standardization evaluation index, combined with the official explanation of ATT&CK and expert knowledge, according to the References in the ATT&CK database and each attack event extracted in the threat intelligence, the index is associated with the performance of the technology in the real attack event, and a technology node evaluation model is constructed; the technology node evaluation model is evaluated from two dimensions of technical feasibility and technical harmfulness; the technical feasibility sets two evaluation indexes of operation permission and remote requirement; the technical harmfulness sets three evaluation indexes of confidentiality, integrity and availability; According to the CVSS vulnerability standardization evaluation index, a vulnerability node evaluation model is constructed; the vulnerability node evaluation model includes the basic indexes obtained from the CVSS official and the time index; the basic indexes include attack vector, attack complexity and permission requirement; the time index includes code maturity and report confidence; The technology node evaluation model and the vulnerability node evaluation model are used to comprehensively evaluate the nodes in the logical attack graph, and normalization processing is performed to obtain the risk score of the nodes; The risk scores of the nodes are sorted according to the types of the nodes and reflected in the logical attack graph.
[0007] As a preferred technical scheme, the input file of the MulVAL tool is constructed, specifically: The result file of the Nessus vulnerability scanning tool is parsed, and after detecting the vulnerability, the related information of the vulnerability is found; the related information of the vulnerability includes vulnerability attributes, existence of the vulnerability, CVSS score, network service information and host access control; The XSB rule engine is used for vulnerability translation of the parsed results, and the related information after vulnerability translation is stored in the file; The CVE metadata is queried from the NVD official database according to the CVE number, and is formatted to meet the input file specified by the MulVAL tool; the CVE metadata includes the acquisition range, related software, severity and access permission.
[0008] As a preferred technical scheme, the operation permission indicates the operation permission required by the attacker when performing the attack technology, and the lower the operation permission requirement, the higher the risk; the remote requirement indicates the operation mode required by the attacker when performing the attack technology, including local operation and remote access, and the risk of local operation is low, and the risk of remote access is high; The confidentiality indicates whether the attacker can steal the protected information in the target system through the attack technology; the integrity indicates whether the attack technology can tamper with system information to damage its integrity; the availability indicates whether the attack technology causes system resources to be unable to be normally used; The technology node evaluation model is represented as: T =α X TF + β X The , TF = 10 × (1 - (1 - α 1× TPTI + α 2× TREM ), The = 10 × (1 - (1 - The C ) × (1 - The I ) × (1 - The A )), wherein, TF is technical feasibility, The is technical harmfulness, α , β are weight coefficients of technical feasibility and technical harmfulness respectively and α + β = 1, TPTI is operation authority, The is remote requirement, α 1, α 2 are operation authority and remote requirement respectively and α 1+ α 2 α , The C , The I , The A are confidentiality, integrity and availability respectively.
[0009] As a preferred technical solution, the attack vector is used to measure the way the attacker approaches the target system; the attack complexity reflects the difficulty of launching an attack; the permission requirement represents the operation authority possessed by the attacker; the code maturity represents whether the malicious code exploiting the vulnerability is stable; the report confidence represents the reliability of the report source and the credibility of the report content related to the vulnerability; the vulnerability node evaluation model is represented as: s ( v ) = Edge v × Exploit VS , ExploitVS = Vs / 10, Vs = ( AV × AC × PR × E × RC × 10) / 10, in, s ( v ) is a vulnerable node v The risk value, Edge v It is related to the vulnerable node v The ratio of associated attack paths to the total number of attack paths in the logical attack graph. Exploit VS This refers to the potential risk value of a vulnerability calculated using the CVSS metric. Vs This is the initial risk value for the vulnerability. AV For the attack vector, AC For attack complexity, PR Due to access restrictions, E For code maturity, RC For the report confidence level.
[0010] As a preferred technical solution, the step of comprehensively evaluating the nodes in the logic attack graph and performing normalization processing to obtain the risk score of the nodes is specifically as follows: The original risk values of technical nodes in the logic attack graph are calculated using the technical node evaluation model; the original risk values of vulnerable nodes in the logic attack graph are calculated using the vulnerability node evaluation model. Calculate the weights of edges between nodes, and calculate the risk values of technical nodes and vulnerable nodes; Different weight coefficients are assigned to different types of nodes to give them priority. Different damping factors are set for different types of nodes; the damping factors are used to simulate the probability that an attacker will stop performing the current action or exploiting the current vulnerability. The original risk score of a node is calculated based on its risk value, weight coefficient, and corresponding damping factor. The risk score of the node is then normalized using the L1 norm.
[0011] As a preferred technical solution, the weights of the edges between nodes are specifically calculated as follows: Let the nodes in the logic attack graph be... u and nodes v The weight of the edge is g ( u , v )= m ( v ),but m (v The calculation formula is: , in, s ( v ) is a node v Vulnerability risk score, N + ( v ) is a node v The outbound neighboring region, m ( w ) represents a node in the outgoing edge neighborhood. w The weight, V A set of vulnerable nodes. T A set of technology nodes; Considering the influence between nodes in the target system, nodes with vulnerability types and technology types are mutually updated and iterated based on the adjacency relationship between nodes to obtain the corresponding node risk values: , , in, , They are the first i The first technology node and the first j The node risk value of each vulnerable node, | V | represents the size of the set of vulnerable nodes, | T | represents the size of the set of technical nodes. w ji It is a vulnerable node j To the technology node i The weight of the edge. w ij It is a technology node i To the vulnerable node j The weight of the edge. T i , V j They are the first i The first technology node and the first j The original risk value of each vulnerable node.
[0012] As a preferred technical solution, the formula for calculating the original risk score of the node is: , , in, , They are the first i The first technology node and the first j The original risk score of each vulnerable node, | V| represents the size of the set of vulnerable nodes, | T | represents the size of the set of technical nodes. x i For the first i Damping factor of each technology node w ji It is a vulnerable node j To the technology node i The weight of the edge. α i As a technology node i The weighting coefficients, w ij It is a technology node i To the vulnerable node j The weight of the edge. β j Vulnerable node j The weighting coefficients, , They are the first i The first technology node and the first j The risk value of each vulnerable node. T i , V j It is the first i The first technology node and the first j The original risk value of each vulnerable node.
[0013] As a preferred technical solution, the risk score of a node is obtained by normalization using the L1 norm, and the formula is as follows: , , in, Te i As a technology node i Risk score, E j Vulnerable node j Risk score, L 1 Norm ( ) represents the L1 norm.
[0014] In another aspect, the present invention provides a threat assessment system based on logical attack graphs, ATT&CK, and CVSS, applied to the aforementioned threat assessment method, including a conditional rule construction module, an input file creation module, an attack graph construction module, a technical node assessment module, a vulnerability node assessment module, a risk score calculation module, and a sorting and display module; The condition rule construction module is used for obtaining preconditions required for successful implementation of a technique according to the content of the tactic classification, technique description and reference case in the ATT&CK technique and tactic, setting predicate parameters, selecting a proper predicate according to a preset target to obtain a necessary minimum condition set required for reasoning rules, and finally forming a rule set required for MulVAL tool input, wherein the preconditions include system environment conditions and permissions already possessed by an attacker; The input file making module is used for obtaining a scanning result of a target system by using a Nessus vulnerability scanning tool, and constructing an input file of the MulVAL tool; The attack graph construction module is used for calling an XSB engine and a self-provided rule library by using the MulVAL tool to generate a logical attack graph with a reverse attack behavior granularity and construct an attack chain of the target system based on the rule set and the input file, wherein the node types in the logical attack graph include a technique node and a vulnerability node; The technique node evaluation module is used for associating indexes with technique performance in real attack events by referring to ATT&CK technique and tactic standardized evaluation indexes, combining ATT&CK official explanations and expert knowledge, and according to References in the ATT&CK database and each attack event extracted from threat intelligence, and constructing a technique node evaluation model; the technique node evaluation model is evaluated from two dimensions of technique feasibility and technique harmfulness; the technique feasibility sets two evaluation indexes of operation permission and remote requirement; and the technique harmfulness sets three evaluation indexes of confidentiality, integrity and availability; The vulnerability node evaluation module is used for constructing a vulnerability node evaluation model by referring to CVSS vulnerability standardized evaluation indexes; the vulnerability node evaluation model includes basic indexes and time indexes obtained from the CVSS official; the basic indexes include attack vector, attack complexity and permission requirement; and the time indexes include code maturity and report confidence; The risk score calculation module is used for comprehensively evaluating nodes in the logical attack graph by using the technique node evaluation model and the vulnerability node evaluation model, and performing normalization processing to obtain a risk score of the node; The sorting and displaying module is used for sorting the risk score of the node according to the node type and reflecting the risk score in the logical attack graph.
[0015] The application further provides a computer readable storage medium storing a program, when the program is executed by a processor, the threat evaluation method is realized.
[0016] Compared with the prior art, the application has the following advantages and beneficial effects: 1. Attack path restoration is more accurate: The existing logical attack graph is coarse in granularity, and it is difficult to finely and accurately restore the potential attack path in the system. In view of this problem, the application proposes a more accurate attack graph modeling framework, which is based on the tactics and techniques in the ATT&CK framework, and restores the attack chain in the network system more carefully by deeply analyzing each link and step in the attack process. This not only improves the depth of understanding of the potential attack path, but also provides a more reliable basis for subsequent risk assessment and defense measures.
[0017] 2, the system risk assessment is more comprehensive: The method proposed in the application not only considers the attributes of different types of nodes (technology nodes and vulnerability nodes), but also includes system characteristics and edge associations and other factors. Specifically, for each technology node, the technical feasibility is evaluated according to its operation permission and remote requirement; the technical harmfulness is evaluated from the three dimensions of confidentiality, integrity and availability. For the vulnerability node, the CVSS index is used for evaluation, including the basic index and the time index. This evaluation method no longer considers the attack elements in the graph in isolation, but takes into account their internal logical relationship, ensuring the accuracy of the threat degree measurement, and fully reflecting the high credibility threat information on the attack graph. BRIEF DESCRIPTION OF DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0019] Figure 1 The flowchart of the threat assessment method based on logical attack graph, ATT&CK and CVSS in the embodiment of the application.
[0020] Figure 2 The logical attack graph diagram generated in the embodiment of the application.
[0021] Figure 3 The attack diagram generated in the embodiment of the application.
[0022] Figure 4 The structure diagram of the threat assessment system based on logical attack graph, ATT&CK and CVSS in the embodiment of the application.
[0023] Figure 5 The structure diagram of the computer readable storage medium in the embodiment of the application. DETAILED DESCRIPTION
[0024] In the following, the technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application, so that those skilled in the art can better understand the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.
[0025] Reference to "embodiments" in this application means that the specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily all refer to the same embodiment, nor does it necessarily exclude other embodiments that are not mutually exclusive or alternative to each other. It is explicitly and implicitly understood by those skilled in the art that the embodiments described in the present application can be combined with other embodiments.
[0026] As shown in Figure 1 The present embodiment is based on a threat evaluation method of logical attack graph, ATT&CK and CVSS, including the following steps: S1, based on the theory of minimal dependence set, according to the content of tactical classification, technical description and reference case in ATT&CK technique and tactics, the pre-information required for successful implementation of the technology is obtained and the predicate parameter is set, the necessary minimal condition set required for reasoning rule is selected according to the preset target, and finally the rule set required for MulVAL tool input is constituted.
[0027] ATT&CK is a highly influential network security knowledge framework, which provides a comprehensive and systematic perspective for explaining complex attack scenarios; ATT&CK can integrate scattered attack information and clearly depict the complete attack chain. By detailing the attack techniques at different stages, it effectively helps security personnel understand the attack behavior logic of attackers. Security personnel can quickly classify and analyze attack behavior according to the classification and description of ATT&CK, so as to more accurately formulate targeted defense strategies. ATT&CK framework comprehensively covers tactics, techniques and procedures at each stage from initial reconnaissance to final target achievement, providing a very systematic and effective methodology for understanding, analyzing and responding to attacks, helping security practitioners to deeply understand the internal logic and behavior patterns of network attacks, so as to formulate targeted defense strategies and detection mechanisms.
[0028] The present application carries out innovative correlation work on the tactics contained in the ATT&CK technique; by a systematic classification method, the techniques and tactics are correlated according to the time sequence logic of attack behavior, since ATT&CK contains a large number of sub-techniques, the present application does not involve more detailed sub-techniques. Based on the theory of minimum dependence set, according to the description of tactic classification and technology in ATT&CK and the content of reference cases, the system environment conditions required for successful implementation of the technology, the permissions already possessed by the attacker and other pre-information are obtained, and the predicate parameters are set, the necessary minimum condition set required by the reasoning rule is selected according to the preset target, and finally the rule set required by the MulVAL tool input is constituted. The following steps are referred to when designing the rules: 1) define the range (clearly define the scene that the attack graph modeling needs to cover, the relevant scene in the present application is the attack chain in the network restored from the technique and tactic dimension), determine the granularity (clearly describe the detail degree and abstraction level of network attack and network element, the basic network elements such as host, server, network device and protection device are clearly expressed in the present application, and the abstraction level is attack behavior, which only describes a single attack technique without containing specific operations that may be involved in the technique), list actions (list potential behaviors such as possible attack behaviors and network operations), determine predicates (determine appropriate semantic descriptions), and create rules (build attack paths and causal relationships through rule logic). The reference steps can also be applied to the expansion of scene predicates and rules. One example of the reasoning rule of ATT&CK mapping is shown in Table 1 below: Table 1: Example of reasoning rule of ATT&CK mapping
[0029] The example in Table 1 shows that when an attacker uses the T1021 Remote Services technology for lateral movement, the attacker only needs to obtain the IP address of the target host and an account with certain permissions to log in to the target host through remote services to achieve lateral movement, so only four types of Host_Dst, User_Dst, Password_Dst, and Permission_Dst are set when setting the predicate parameters, and the values of the predicate parameters are provided by the conditions of the inference rules, wherein the following two cases need to be considered: 1) the relationship between the front and the back: when an attacker wants to achieve an attack target, a series of attack behaviors are needed as a cushion, such as information collection on the Internet, scanning and detection, launching attacks on Internet services, and finally executing commands, or deepening the intranet to obtain the control right of the target host. This involves multiple tactics such as Reconnaissance, Execution, Discovery, LateralMovement and a number of subordinate technologies; then when setting the conditions, the type of parameters provided by the previous technology needs to be considered. The attacker will collect before lateral movement, so the T1016 System NetworkConfiguration Discovery can provide the Host_Dst value for LateralMovement, and at the same time form the sequence of Discovery→LateralMovement sub-attack chain. 2) Parallel relationship: when an attacker obtains certain permissions, the next step may be to further consolidate the attack results through multiple parallel steps such as discovery, persistence, and collection. Due to the characteristics of the Prolog language, although these steps may have a certain order, they still belong to the same attack stage from a macro perspective, so they can all obtain parameters from the previous attack behavior and reason.
[0030] On this basis, full consideration is given to different application scenarios and diversified security requirements, and a more refined inference rule system covering tactics, techniques, and even sub-techniques is flexibly and accurately mapped from the ATT&CK framework; the system can be effectively applied to the accurate restoration of network attack scenarios, providing extremely powerful technical support and data basis for in-depth analysis of the internal mechanism of network attacks, formulating efficient security defense strategies, and carrying out comprehensive network security risk assessment, greatly improving the pertinence and effectiveness of network security protection work.
[0031] S2, use the Nessus vulnerability scanning tool to obtain the scanning results of the target system, and build the input file of the MulVAL tool.
[0032] When modeling the attack on the target network, how to maximize the key facilities in the network system is also a very critical task. The key architecture and elements of the target network should be fully covered in the modeling scenario. Based on the theory of minimum dependence set, combined with customized rule parameters and vulnerability utilization parameters, the scene input is constructed, which involves host information, topology information, vulnerability information, etc. For example, the host information sets the host ip, network segment, running service, open port and other information; and the topology information includes the physical topology structure of the network. Therefore, predicates for describing switches, routers and other devices are specially added to describe the logical topology structure, such as VLAN division, network address translation rules and the like. These information helps to determine the propagation path and scope of the attack.
[0033] The application uses the scanning results of the Nessus vulnerability scanning tool to construct the input file of the MulVAL tool. Through the Nessus result mapping script in the MulVAL tool, the required parameter requirements and expression granularity of the new rule can be met, the parameter meaning of the predicate is refined, the predicate type is increased to meet the requirements of restoring the attack scene, and the compatibility of multiple reasoning rules is also considered to avoid redundancy caused by setting multiple similar predicates. The specific construction method is as follows: S2.1, first, the result file of the Nessus vulnerability scanning tool is parsed, after detecting the vulnerability, the vulnerability attributes, the existence of the vulnerability, the CVSS score, the network service information and the host access control and other aspects of the vulnerability related information are found; S2.2, then the XSB rule engine is used for vulnerability translation of the parsed results, and the related information after vulnerability translation is stored in the file; S2.3, then according to the vulnerability CVE number, the range, related software, severity, access permission and other CVE metadata are obtained from the NVD official database, and finally formatted into an input file conforming to the MulVAL tool.
[0034] In this embodiment, part of the input file is shown in Table 2 as follows: Table 2 Part of the input file format example
[0035] S3, based on the rule set and the input file, the MulVAL tool is used to call the XSB engine and the built-in rule library to generate the logical attack graph of the reverse attack behavior granularity and construct the attack chain of the target system. The node types in the logical attack graph include technical nodes and vulnerability nodes. The logical attack graph constructed in this embodiment is shown in Figure 2 , and the attack chain is shown in Figure 3 . It should be noted that Figure 2 , Figure 3The content does not affect the understanding of the technical solutions of the present application.
[0036] S4, referring to the ATT&CK technique standardized evaluation index, combining the official explanation of ATT&CK and expert knowledge, according to the References in the ATT&CK database and each attack event extracted in the threat intelligence, the index is associated with the technical performance in the real attack event, and a technical node evaluation model is constructed. The technical node evaluation model is evaluated from two dimensions of technical feasibility and technical harmfulness; wherein, the technical feasibility sets two evaluation indexes of operation permission and remote requirement; the technical harmfulness sets three evaluation indexes of confidentiality, integrity and availability; the four evaluation indexes of operation permission, confidentiality, integrity and availability are divided into three levels of None (None-N), Low (Low-L) and High (High-H), and the remote requirement is divided into local operation (Local) and remote access (Remote). The numerical value of the evaluation index can be personalized to adjust the weight proportion in combination with the system characteristics and the characteristics of the attack behavior.
[0037] Further, the technical feasibility evaluation index is evaluated from operation permission and remote requirement; wherein, the operation permission represents the operation permission required by the attacker to execute the attack technology, and the lower the operation permission requirement, the higher the risk; the remote requirement represents the operation mode required by the attacker to execute the attack technology, including local operation and remote access, and the risk of local operation is low, and the risk of remote access is high.
[0038] The technical harmfulness is evaluated from confidentiality, integrity and availability; wherein, the confidentiality represents whether the attacker can steal the protected information in the target system through the attack technology; the integrity represents whether the attack technology can tamper with system information to destroy its integrity; and the availability represents whether the attack technology causes the system resources to be unable to be normally used.
[0039] Therefore, the technical node evaluation model is represented as: T = α × TF + β × The , TF =10 × ( α 1× TPTI + α 2× TREM ), The = 10 × (1 - (1 - The C ) × (1 - The I ) × (1 - TheA )), wherein, TF is the technical feasibility, The is the technical harmfulness, α , β are the weight coefficients of the technical feasibility and the technical harmfulness respectively and α + β = 1, TPTI is the operation authority, The is the remote requirement, α 1, α 2 are the operation authority and the remote requirement respectively and α 1+ α 2= α , The C , The I , The A are the confidentiality, the integrity and the availability respectively. When the above formula is used to evaluate the technical node, the operation authority index and the remote requirement index are amplified (i.e. multiplied by 10) to ensure the weight of the technical feasibility in the risk score, and the feasibility of the current attack behavior is the primary consideration for an attacker to launch an attack, and the feasibility is the basis for judging the risk of all a series of attack behaviors; then the confidentiality, the integrity and the availability are comprehensively processed (and the amplification processing is performed to maintain data consistency) to obtain the comprehensive influence on the technical harmfulness, and finally the weight coefficient α , β is used to adjust the contribution degree of the technical feasibility and the technical harmfulness.
[0040] S5, referring to the CVSS vulnerability standardized evaluation index, a vulnerability node evaluation model is constructed for calculating the potential risk value of the vulnerability node. The vulnerability node evaluation model includes the basic indexes obtained from the CVSS official and the time indexes; wherein, the basic indexes include the attack vector, the attack complexity and the permission requirement indexes; the time indexes include the code maturity and the report confidence indexes.
[0041] Specifically, the attack vector (AV) is used to measure the way in which the attacker approaches the target system; the attack complexity (AC) reflects the difficulty of launching an attack; the permission requirement (PR) indicates the operation authority possessed by the attacker; the code maturity (E) indicates whether the malicious code for exploiting the vulnerability is stable; and the report confidence (RC) indicates the reliability of the report source and the credibility of the report content related to the vulnerability.
[0042] Therefore, the vulnerability node evaluation model is expressed as: s ( v ) = Edge v xExploit VS , Vs = ( AV × AC × PR × E × RC × 10) / 10, Exploit VS = Vs / 10, wherein, s ( v ) is a risk value of a vulnerability node, v Edge v is a ratio of an attack vector associated with the vulnerability node to a total number of paths in a logical attack graph, v Exploit VS is a vulnerability potential risk value calculated by using a CVSS index, Vs is a vulnerability initial risk value, AV is an attack vector, AC is an attack complexity, PR is a permission requirement, E is a code maturity, RC is a report confidence. In the vulnerability node evaluation model, the attack vector, the attack complexity and the permission required for exploiting the vulnerability (i.e., the permission requirement) are the most basic consideration indexes, which can intuitively reflect the severity of a vulnerability, and the code maturity and the report confidence in the time index are added to reflect the importance of the vulnerability from the perspective of the extent of the vulnerability and the importance of the manufacturer, so as to evaluate the risk of the vulnerability node.
[0043] S6, comprehensively evaluate the nodes in the logical attack graph by using the technical node evaluation model and the vulnerability node evaluation model, and perform normalization processing to obtain a risk score of the nodes.
[0044] Further, the application evaluates the risk degree of the nodes in the attack graph from two aspects of the technique and tactics describing the attack behavior and the CVSS describing the vulnerability risk, quantifies the risk of the technique and tactics according to the multi-dimensional evaluation indexes, extracts the CVSS evaluation indexes to quantize the risk of the system vulnerability in combination with the in-degree and out-degree of the nodes (step S5), and then comprehensively evaluates the nodes in the attack graph, specifically as follows: S6.1, calculate the original risk value of the technical node in the logical attack graph by using the technical node evaluation model, and calculate the original risk value of the vulnerability node in the logical attack graph by using the vulnerability node evaluation model.
[0045] S6.2, calculate the weight of the edge between the nodes, and calculate the risk value of the technical node and the vulnerability node.
[0046] Specifically, each node type in the attack graph has its unique characteristics and potential impact on system security, and the relationship between nodes should not be ignored when evaluating the attack graph. Therefore, the weight of the edge between nodes needs to be calculated, and the process is as follows: Let the nodes in the logical attack graph be u and the weight of the edge between the nodes v be g ( u , v )= m ( v ), then m ( v ) is calculated as follows: , where s ( v ) is the original risk value of node v , N + ( v ) is the out-edge neighborhood of node v , m ( w ) is the weight of node w in the out-edge neighborhood, V is the set of vulnerability nodes, T is the set of technology nodes. In the above formula, when node v is a vulnerability node, it is the original risk value of node v multiplied by the weight of all related edges of node v , and when node v is a technology node, the maximum value of the weight of the related edge of node v is selected.
[0047] Considering the mutual influence of different factors in the target system, that is, the influence between nodes, if a node of one type is the neighborhood of a high-risk node of another type, the risk value of the node will also be affected and become high. There should be a mutual strengthening logical relationship between nodes, so based on the adjacency relationship between nodes, the two types of nodes (vulnerability type and technology type) are iteratively updated to obtain the corresponding node risk value: , , where , are the node risk values of the i th technology node and the j th vulnerability node, respectively, V | is the size of the set of vulnerability nodes, T | is the size of the set of technology nodes.w ji It is a vulnerable node j To the technology node i The weight of the edge. w ij It is a technology node i To the vulnerable node j The weight of the edge. T i , V j They are the first i The first technology node and the first j The original risk value of each vulnerable node.
[0048] S6.3. Set different weight coefficients for different types of nodes to assign priority to the nodes.
[0049] Weighting coefficients can be used to enhance the weight of a network device in an attack graph. For example, assigning a high weighting coefficient to a critical database node highlights the target of focus, guiding subsequent assessments to pay more attention to this critical node when calculating node scores. The aim is to help security personnel identify the impact related to critical assets and prioritize limited resources for protecting the most important assets. Non-priority nodes, on the other hand, are assigned an arbitrarily small weighting coefficient. ϵ >0, while priority nodes are assigned a value of 1-(| A |-1) ϵ The weighting coefficients, where A It is the vertex set of the attack graph.
[0050] S6.4 Set different damping factors for different types of nodes; where the damping factor is used to simulate the probability that an attacker will stop performing the current action or exploiting the current vulnerability.
[0051] Attackers may stop their attacks at a certain node for various reasons. For example, when an attacker gains access to a server, they might implant a Trojan horse to perform privilege escalation, persistence, or other operations. However, there's a chance the attacker will discover and exploit other system vulnerabilities, rendering the attack path meaningless in the attack graph. Therefore, this invention sets different damping factor matrices for two different types of nodes, namely the technical damping factor matrix Δ. T = diag ( x 1, x 2, ..., x |T| ) and vulnerability damping factor matrix Δ V = diag ( y 1, y 2, ..., y |V|For attacks that are difficult for attackers to complete easily or quickly, the corresponding damping factor may be large, making attackers more likely to try other easier attack techniques. The damping factor can be customized according to the environment. For attack techniques, it can be set with reference to information such as the frequency of use of the technique; for vulnerabilities, it can be set with reference to the difficulty of exploiting the vulnerability.
[0052] S6.5. The original risk score of the node is calculated based on the node's risk value, weight coefficient, and corresponding damping factor. The node's risk score is then normalized using the L1 norm.
[0053] Specifically, considering the weighting coefficients and corresponding damping factors, the original risk score of the node is calculated: , , in, , They are the first i The first technology node and the first j The original risk score of each vulnerable node, | V | represents the size of the set of vulnerable nodes,| T | represents the size of the set of technical nodes. x i ∈Δ T For the first i Damping factor of each technology node w ji It is a vulnerable node j To the technology node i The weight of the edge. α i As a technology node i The weighting coefficients, y j ∈Δ V For the first j Damping factor of each vulnerable node, w ij It is a technology node i To the vulnerable node j The weight of the edge. β j Vulnerable node j The weighting coefficients, , They are the first i The first technology node and the first j The risk value of each vulnerable node. T i , V j They are the first i The first technology node and the firstj the original risk value of the vulnerability node.
[0054] Specifically, in order to ensure the interpretability of the node risk score, the L1 norm is used to normalize the original score of the node: , , wherein, Te i the risk score of the technology node i , E j the risk score of the vulnerability node j , L 1 Norm ( ) is the L1 norm.
[0055] S7, the risk scores of the nodes are sorted according to the node types and reflected in the logical attack graph.
[0056] Finally, the risk scores of the nodes are calculated, the nodes are sorted according to the types, and the nodes with larger risk scores are reflected in the attack graph, so as to help the security personnel allocate more protection resources to the specific devices associated with the nodes and better prevent system risks. The example node risk scores are shown in Table 3 as follows: Table 3 Example node risk scores
[0057] To sum up, in one aspect, the present application addresses the problem that the existing logical attack graph has a relatively rough expression granularity and is difficult to finely and accurately restore the potential attack path in the system. The reasoning rules are formulated to be more suitable for the attack process. Compared with the original MulVAL rules, the description of the attack must pass through a certain vulnerability and can only include a few attack methods. The logical attack graph of the present application can restore the attack chain by attack technology and show the complete attack process at one time. On the other hand, the existing attack graph evaluation method does not consider the logical relationship between the techniques, tactics, and vulnerabilities in the attack graph. A new evaluation method is created according to the node expression information in the attack graph. The risk score is calculated according to the node attributes, system characteristics, and edge association, so as to facilitate the screening of the highest risk attack path and strive to fully display the threat information with effectiveness and high credibility on the attack graph, so as to enhance the usability and effectiveness of the attack graph tool in practical application.
[0058] It should be noted that, for the foregoing method embodiments, in order to facilitate description, they are all described as a series of action combinations, but those skilled in the art should know that the present application is not limited by the action sequence described, because according to the present application, certain steps can be performed in other sequences or simultaneously.
[0059] Based on the same idea as the threat assessment method based on logical attack graph, ATT&CK and CVSS in the above embodiment, the application also provides a threat assessment system based on logical attack graph, ATT&CK and CVSS, which can be used to execute the threat assessment method based on logical attack graph, ATT&CK and CVSS described above. For the convenience of description, in the structural schematic diagram of the embodiment of the threat assessment system based on logical attack graph, ATT&CK and CVSS, only the part related to the embodiment of the application is shown, and those skilled in the art can understand that the illustrated structure does not constitute a limitation on the device, and can include more or fewer components than the illustrated, or combine certain components, or different component arrangements.
[0060] As shown in Figure 4 Another embodiment of the application provides a threat assessment system based on logical attack graph, ATT&CK and CVSS, which includes a conditional rule construction module, an input file making module, an attack graph construction module, a technology node evaluation module, a vulnerability node evaluation module, a risk score calculation module and a sorting display module. The conditional rule construction module is used to obtain the pre-information required for successful implementation of technology and set the predicate parameters based on the minimum dependence set theory according to the content of the tactical classification, technical description and reference case in the ATT&CK tactics and techniques, select the appropriate predicate according to the preset target to form the necessary minimum condition set required for the reasoning rule, and finally form the rule set required for the input of the MulVAL tool; the pre-information includes system environment conditions and the permissions already possessed by the attacker, etc. The input file making module is used to obtain the scanning results of the target system by using the Nessus vulnerability scanning tool, and construct the input file of the MulVAL tool. The attack graph construction module is used to generate the logical attack graph of the reverse attack behavior granularity and construct the attack chain of the target system by using the MulVAL tool to call the XSB engine and the built-in rule library based on the rule set and the input file; the node types in the logical attack graph include technology nodes and vulnerability nodes. The technology node evaluation module is used to reference the ATT&CK tactics and techniques standardized evaluation index, combine the ATT&CK official explanation and expert knowledge, associate the index with the technology performance in the real attack event according to the References in the ATT&CK database and each attack event extracted in the threat intelligence, and construct a technology node evaluation model; the technology node evaluation model is evaluated from two dimensions of technology feasibility and technology harmfulness; wherein, the technology feasibility sets two evaluation indexes of operation permission and remote requirement; the technology harmfulness sets three evaluation indexes of confidentiality, integrity and availability. The vulnerability node evaluation module is configured to refer to the CVSS vulnerability standardized evaluation index to build a vulnerability node evaluation model; the vulnerability node evaluation model includes a basic index and a time index obtained from the CVSS official website; wherein the basic index includes an attack vector, attack complexity and permission requirement; the time index includes code maturity and report confidence; The risk score calculation module is configured to comprehensively evaluate the nodes in the logical attack graph by using the technology node evaluation model and the vulnerability node evaluation model, and perform normalization processing to obtain the risk score of the nodes; The sorting and display module is configured to sort the risk scores of the nodes according to the node types and reflect the risk scores in the logical attack graph.
[0061] It should be noted that the threat evaluation system based on the logical attack graph, ATT&CK and CVSS of the present application corresponds to the threat evaluation method based on the logical attack graph, ATT&CK and CVSS of the present application, and the technical features and advantages described in the above embodiment of the threat evaluation method based on the logical attack graph, ATT&CK and CVSS are applicable to the embodiment of the threat evaluation system based on the logical attack graph, ATT&CK and CVSS, and the specific content can be referred to the description in the method embodiment of the present application, which will not be described here again, and hereby declared.
[0062] In addition, in the implementation of the threat evaluation system based on the logical attack graph, ATT&CK and CVSS of the above embodiment, the logical division of each program module is only an example, and in actual application, the above functions can be completed by different program modules according to the needs, for example, according to the configuration requirements of the corresponding hardware or the convenience of software implementation, that is, the internal structure of the threat evaluation system based on the logical attack graph, ATT&CK and CVSS is divided into different program modules to complete all or part of the functions described above.
[0063] As shown in FIG. Figure 5 In one embodiment, a computer readable storage medium is provided, which stores a program in the memory, and the program is executed by a processor to implement the threat evaluation method based on the logical attack graph, ATT&CK and CVSS, specifically: Based on the minimum dependency set theory, the pre-information required for successful implementation of the technology is obtained and the predicate parameters are set according to the content of the tactic classification, technical description and reference case in the ATT&CK technique and tactics, the necessary minimum condition set required for the reasoning rule is selected according to the preset target, and finally the rule set required for the input of the MulVAL tool is formed; the pre-information includes system environment conditions and the permissions possessed by the attacker; The scanning result of the target system is obtained by using the Nessus vulnerability scanning tool, and the input file of the MulVAL tool is constructed; Based on the rule set and the input file, the MulVAL tool is used to call the XSB engine and the built-in rule library to generate a logic attack graph with a reverse attack behavior granularity and build an attack chain of the target system; the node types in the logic attack graph include technical nodes and vulnerability nodes; According to the ATT&CK technique and tactics standardized evaluation index, combined with the official explanation of ATT&CK and expert knowledge, the index is associated with the technical performance in the real attack event according to the References in the ATT&CK database and each attack event extracted in the threat intelligence, and a technical node evaluation model is constructed; the technical node evaluation model is evaluated from two dimensions of technical feasibility and technical harmfulness; wherein, the technical feasibility sets two evaluation indexes of operation permission and remote requirement; the technical harmfulness sets three evaluation indexes of confidentiality, integrity and availability; According to the CVSS vulnerability standardized evaluation index, a vulnerability node evaluation model is constructed; the vulnerability node evaluation model includes the basic indexes obtained from the official CVSS, and the time index and the environment index; wherein, the basic indexes include the attack vector, the attack complexity and the permission requirement; the time index includes the code maturity and the report confidence; The technical node evaluation model and the vulnerability node evaluation model are used to comprehensively evaluate the nodes in the logic attack graph, and the risk scores of the nodes are normalized to obtain the risk scores of the nodes; The risk scores of the nodes are sorted according to the node types and reflected in the logic attack graph.
[0064] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The program can be stored in a non-volatile computer readable storage medium, and when the program is executed, the processes of the above-mentioned embodiment methods can be included. Any reference to memory, storage, database or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0065] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist, it should be considered as the scope of the present application.
[0066] The above embodiments are the preferred embodiments of the present application, but the embodiments of the present application are not limited to the above embodiments, and any changes, modifications, substitutions, combinations and simplifications of the embodiments of the present application without departing from the spirit and principles of the present application are equivalent replacement methods, and are included in the protection scope of the present application.
Claims
1. A threat assessment method based on logical attack graphs, ATT&CK, and CVSS, characterized in that, Includes the following steps: Based on the minimum dependency set theory, and according to the tactical classifications, technical descriptions, and reference cases in ATT&CK tactics, the necessary preconditions for successful technical implementation are obtained and predicate parameters are set. Appropriate predicates are selected according to the preset objectives to form the necessary minimum condition set for inference rules, which ultimately constitutes the set of rules required for input to the MulVAL tool. The preconditions include system environment conditions and the permissions already possessed by the attacker. Use the Nessus vulnerability scanning tool to obtain the scan results of the target system, and then construct the input file for the MulVAL tool; Based on the rule set and input file, the MulVAL tool is used to call the XSB engine and its built-in rule base to generate a logical attack graph at the granularity of reverse attack behavior and to construct the attack chain of the target system; the node types in the logical attack graph include technical nodes and vulnerability nodes. Referring to ATT&CK's standardized technical and tactical evaluation indicators, combined with ATT&CK's official explanations and expert knowledge, and based on references in the ATT&CK database and various attack events extracted from threat intelligence, the indicators are correlated with the technical performance in real attack events to construct a technical node evaluation model. The technical node evaluation model evaluates from two dimensions: technical feasibility and technical harmfulness. The technical feasibility is set with two evaluation indicators: operation permissions and remote requirements. The assessment criteria for the harmfulness of technology include confidentiality, integrity, and availability. A vulnerability node assessment model was constructed based on the CVSS vulnerability standardization assessment metrics. The vulnerability node assessment model includes basic metrics and time metrics obtained from the official CVSS documentation. The basic metrics include attack vector, attack complexity, and privilege requirements. The time metrics include code maturity and report confidence. The nodes in the logical attack graph are comprehensively evaluated using the technical node evaluation model and the vulnerability node evaluation model, and the risk score of the node is obtained by normalization. The risk scores of nodes are sorted according to node type and reflected in the logic attack graph.
2. The threat assessment method according to claim 1, characterized in that, The input file for building the MulVAL tool is specifically as follows: The results file of the Nessus vulnerability scanning tool is parsed, and after a vulnerability is detected, relevant vulnerability information is searched. The relevant vulnerability information includes vulnerability attributes, vulnerability existence status, CVSS score, network service information, and host access control. The XSB rule engine is used to perform vulnerability translation on the parsed results, and the relevant information after vulnerability translation is stored in a file; The CVE metadata is retrieved from the NVD official database based on the vulnerability CVE number and formatted into an input file that conforms to the MulVAL tool's specifications. The CVE metadata includes the scope of access, related software, severity, and access permissions.
3. The threat assessment method according to claim 1, characterized in that, The operation permissions refer to the operation permissions required by the attacker to execute the attack technique. The lower the operation permission requirement, the higher the risk. The remote requirements refer to the operation methods required by the attacker to execute the attack technique, including local operation and remote access. Local operation has low risk, while remote access has high risk. The confidentiality refers to whether an attacker can steal protected information within the target system using attack techniques; the integrity refers to whether attack techniques can tamper with system information to compromise its integrity. The availability indicator demonstrates whether the attack technique causes system resources to become unusable. The technology node evaluation model is represented as follows: T = α × TF + β × THE , TF =10 × ( α 1 × TPTI + α 2 × TREM ), THE = 10 × (1 - (1 - THE C ) × (1 - THE I ) × (1 - THE A )), in, TF For technical feasibility, THE Due to the harmfulness of the technology, α , β The weighting coefficients for technical feasibility and technical harmfulness are respectively. α + β =1, TPTI For operation permissions, THE For remote requirements, α 1. α 2 represents operation permissions and remote access requirements, respectively. α 1+ α 2= α , THE C , THE I , THE A These are confidentiality, integrity, and availability.
4. The threat assessment method according to claim 1, characterized in that, The attack vector is used to measure how an attacker approaches the target system; The attack complexity reflects the ease or difficulty of launching an attack; The permission requirements refer to the operational permissions possessed by the attacker; The code maturity level indicates whether the malicious code that exploits the vulnerability is stable; The report confidence level indicates the reliability of the report source and the credibility of the report content related to the vulnerability; The vulnerability node assessment model is represented as follows: s ( v ) = Edge v × Exploit VS , Exploit VS = Vs / 10, Vs = ( AV × AC × PR × E × RC × 10) / 10, in, s ( v ) is a vulnerable node v The risk value, Edge v It is related to the vulnerable node v The ratio of associated attack paths to the total number of attack paths in the logical attack graph. Exploit VS This refers to the potential risk value of a vulnerability calculated using the CVSS metric. Vs This is the initial risk value for the vulnerability. AV This is the attack vector. AC For attack complexity, PR Due to access restrictions, E For code maturity, RC For the report confidence level.
5. The threat assessment method according to claim 1, characterized in that, The process of comprehensively evaluating and normalizing the nodes in the logic attack graph to obtain a risk score for each node is as follows: The original risk value of the technical nodes in the logic attack graph is calculated using the technical node evaluation model. The original risk value of the vulnerable nodes in the logic attack graph is calculated using the vulnerability node assessment model. Calculate the weights of edges between nodes, and calculate the risk values of technical nodes and vulnerable nodes; Different weight coefficients are assigned to different types of nodes to give them priority. Different damping factors are set for different types of nodes; The damping factor is used to simulate the probability that an attacker will stop performing the current action or exploiting the current vulnerability; The original risk score of a node is calculated based on its risk value, weight coefficient, and corresponding damping factor. The risk score of the node is then normalized using the L1 norm.
6. The threat assessment method according to claim 5, characterized in that, The weights of the edges between the calculated nodes are specifically as follows: Let the nodes in the logic attack graph be... u and nodes v The weight of the edge is g ( u , v )= m ( v ),but m ( v The calculation formula is: , in, s ( v ) is a node v Vulnerability risk score, N + ( v ) is a node v The outbound neighboring region, m ( w ) represents a node in the outgoing edge neighborhood. w The weight, V A set of vulnerable nodes. T A set of technology nodes; Considering the influence between nodes in the target system, nodes with vulnerability types and technology types are mutually updated and iterated based on the adjacency relationship between nodes to obtain the corresponding node risk values: , , in, , They are the first i The first technology node and the first j The node risk value of each vulnerable node, | V | represents the size of the set of vulnerable nodes, | T | represents the size of the set of technical nodes. w ji It is a vulnerable node j To the technology node i The weight of the edge. w ij It is a technology node i To the vulnerable node j The weight of the edge. T i , V j They are the first i The first technology node and the first j The original risk value of each vulnerable node.
7. The threat assessment method according to claim 5, characterized in that, The formula for calculating the original risk score of the node is as follows: , , in, , They are the first i The first technology node and the first j The original risk score of each vulnerable node, | V | represents the size of the set of vulnerable nodes, | T | represents the size of the set of technical nodes. x i For the first i Damping factor of each technology node w ji It is a vulnerable node j To the technology node i The weight of the edge. α i As a technology node i The weighting coefficients, w ij It is a technology node i To the vulnerable node j The weight of the edge. β j Vulnerable node j The weighting coefficients, , They are the first i The first technology node and the first j The risk value of each vulnerable node. T i , V j It is the first i The first technology node and the first j The original risk value of each vulnerable node.
8. The threat assessment method according to claim 7, characterized in that, The risk score of a node is obtained by normalization using the L1 norm, and the formula is as follows: , , in, Te i As a technology node i Risk score, E j Vulnerable node j Risk score, L 1 Norm ( ) represents the L1 norm.
9. A threat assessment system based on logical attack graphs, ATT&CK, and CVSS, characterized in that, The threat assessment method applied to any one of claims 1-8 includes a condition rule construction module, an input file creation module, an attack graph construction module, a technical node assessment module, a vulnerability node assessment module, a risk score calculation module, and a sorting and display module; The condition rule construction module is used to obtain the prerequisite information required for the successful implementation of the technology based on the minimum dependency set theory, according to the tactical classification, technical description and reference case content in ATT&CK tactics, and set predicate parameters. It selects appropriate predicates according to the preset goal to form the necessary minimum condition set required for the inference rule, and finally forms the rule set required for the input of the MulVAL tool. The prerequisite information includes system environment conditions and the permissions already possessed by the attacker. The input file creation module is used to obtain the scan results of the target system using the Nessus vulnerability scanning tool and construct the input file for the MulVAL tool. The attack graph construction module is used to generate a logical attack graph with reverse attack behavior granularity and construct the attack chain of the target system based on the rule set and input file, using the MulVAL tool to call the XSB engine and its built-in rule base; the node types in the logical attack graph include technical nodes and vulnerability nodes. The technical node evaluation module is used to reference ATT&CK's standardized technical and tactical evaluation indicators, combine ATT&CK's official explanations and expert knowledge, and, based on references in the ATT&CK database and various attack events extracted from threat intelligence, correlate the indicators with the technical performance in real attack events to construct a technical node evaluation model. This model evaluates technical nodes from two dimensions: technical feasibility and technical harmfulness. Technical feasibility is evaluated using two indicators: operational permissions and remote access requirements. Technical harmfulness is evaluated using three indicators: confidentiality, integrity, and availability. The vulnerability node assessment module is used to construct a vulnerability node assessment model by referring to the CVSS vulnerability standardization assessment indicators. The vulnerability node assessment model includes basic indicators and time indicators obtained from the official CVSS documentation. The basic indicators include attack vector, attack complexity, and privilege requirements. The time indicators include code maturity and report confidence. The risk score calculation module is used to comprehensively evaluate the nodes in the logic attack graph using the technical node evaluation model and the vulnerability node evaluation model, and then perform normalization processing to obtain the risk score of the node. The sorting and display module is used to sort the risk scores of nodes according to node type and reflect them in the logic attack graph.
10. A computer-readable storage medium storing a program, characterized in that, When the program is executed by the processor, it implements the threat assessment method according to any one of claims 1-8.