Network security situation awareness method and system based on attack chain analysis
By combining an improved attack chain mapping algorithm with an attack tactical knowledge base and entity behavior graph, the accuracy problem of multi-source security data correlation analysis is solved, enabling precise extraction of potential intrusion events and reconstruction of attack chains, thereby improving the accuracy and logic of network security situation awareness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Filing Date
- 2026-05-21
- Publication Date
- 2026-07-17
AI Technical Summary
Existing technologies for multi-source security data correlation analysis lack attack knowledge support, making it difficult to accurately extract fragments of potential intrusion events, leading to false alarms and missed alarms. They also fail to identify the complete attack path and tactical intent, and cannot fully reflect the network attack situation.
An improved attack chain mapping algorithm is adopted, which combines an attack tactic knowledge base and entity behavior graph to perform multi-source security data correlation analysis, extract potential intrusion event fragments, and reconstruct the complete attack chain by merging attack stages and inferring intent, and calculate security situation quantification indicators.
It effectively identifies scattered intrusion events, reduces false alarms and missed alarms, presents the complete attack process, facilitates accurate understanding of the attack situation, and improves the accuracy and logic of network security situation awareness.
Smart Images

Figure CN122419932A_ABST