Network security situation awareness method and system based on attack chain analysis

By combining an improved attack chain mapping algorithm with an attack tactical knowledge base and entity behavior graph, the accuracy problem of multi-source security data correlation analysis is solved, enabling precise extraction of potential intrusion events and reconstruction of attack chains, thereby improving the accuracy and logic of network security situation awareness.

CN122419932APending Publication Date: 2026-07-17
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Filing Date
2026-05-21
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies for multi-source security data correlation analysis lack attack knowledge support, making it difficult to accurately extract fragments of potential intrusion events, leading to false alarms and missed alarms. They also fail to identify the complete attack path and tactical intent, and cannot fully reflect the network attack situation.

Method used

An improved attack chain mapping algorithm is adopted, which combines an attack tactic knowledge base and entity behavior graph to perform multi-source security data correlation analysis, extract potential intrusion event fragments, and reconstruct the complete attack chain by merging attack stages and inferring intent, and calculate security situation quantification indicators.

Benefits of technology

It effectively identifies scattered intrusion events, reduces false alarms and missed alarms, presents the complete attack process, facilitates accurate understanding of the attack situation, and improves the accuracy and logic of network security situation awareness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419932A_ABST
    Figure CN122419932A_ABST
Patent Text Reader

Abstract

本发明涉及网络安全技术领域,具体为基于攻击链分析的网络安全态势感知方法及系统,包括:采集目标网络环境中的网络流量日志、主机系统日志、应用程序日志及威胁情报数据等多源安全数据;采用基于攻击战术知识库和实体行为图谱的改进攻击链映射算法,对多源安全数据进行关联分析,提取潜在入侵事件片段;对潜在入侵事件片段进行攻击阶段归并与意图推断,重构出包含时间顺序攻击阶段序列及各阶段战术意图的完整攻击链;计算反映网络整体脆弱性的安全态势量化指标,生成包含威胁处置建议的网络安全态势报告。该方法可精准提取入侵事件片段、完整呈现攻击路径,提升网络安全态势感知的准确性和针对性。
Need to check novelty before this filing date? Find Prior Art