Multi-dimensional behavior unknown network threat detection method, system, device and medium

CN122698280APending Publication Date: 2026-09-04STATE GRID BEIJING ELECTRIC POWER CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610742565.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-27
Publication Date
2026-09-04

AI Technical Summary

Technical Problem

[0004]本发明的目的在于提供一种多维行为的未知网络威胁检测方法、系统、设备及介质,以解决现有网络威胁检测方法对未知网络威胁检测准确性不足的技术问题

Benefits of technology

基于所述上下游关联关系对多个所述异常片段进行证据关联,形成证据链;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122698280A_ABST
    Figure CN122698280A_ABST
Patent Text Reader

Abstract

The application relates to a multi-dimensional behavior unknown network threat detection method, system, device and medium, the method comprising the following steps: acquiring multi-source data and historical normal behavior data, correlating and modeling the multi-source data to obtain a structured security view; calculating multi-dimensional behavior characteristics based on the structured security view, and establishing a behavior baseline based on the historical normal behavior data; performing abnormal deviation analysis according to the multi-dimensional behavior characteristics and the behavior baseline to obtain abnormal segments and abnormal degree scores of the abnormal segments; correlating upstream and downstream evidence of the abnormal segments and reconstructing attack paths to obtain attack chain evaluation results; determining key asset influence degrees and vulnerability exploitation correlations based on the multi-source data, and fusing the abnormal degree scores, the attack chain evaluation results, the key asset influence degrees and the vulnerability exploitation correlations to calculate threat scores, and then outputting alarm levels according to the threat scores. The application has the effect of improving detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical field of network security detection, and in particular relates to a method, system, device and medium for detecting unknown network threats with multi-dimensional behavior. Background Technology

[0002] Currently, as enterprise networks evolve from boundary-based architectures to cloud-edge collaboration, diversified terminals, and dynamic business orchestration, the access objects, communication relationships, and business interaction links in the network environment are becoming more complex. Attackers are also increasingly inclined to use methods such as circumventing feature matching, mimicking normal behavior, phased penetration, and lateral movement to carry out attacks. Unknown threats, variant attacks, and slow, small attacks place higher demands on the real-time performance and accuracy of network security monitoring.

[0003] Existing network threat detection methods typically rely on known feature libraries, rule libraries, or fixed thresholds to determine security events. When faced with unseen behavioral patterns, these methods are prone to problems such as delayed detection results, high false alarm rates, and untimely responses. Summary of the Invention

[0004] The purpose of this invention is to provide a method, system, device, and medium for detecting unknown network threats based on multidimensional behavior, so as to solve the technical problem that existing network threat detection methods are not accurate enough in detecting unknown network threats.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a method for detecting unknown network threats based on multidimensional behavior, the method comprising: Acquire multi-source data and historical normal behavior data, perform correlation modeling on the multi-source data, and obtain a structured security view; Multidimensional behavioral characteristics are calculated based on the structured security view, and a behavioral baseline is established based on the historical normal behavior data; Anomaly deviation analysis is performed based on the multidimensional behavioral characteristics and the behavioral baseline to obtain abnormal segments and their anomality scores. The upstream and downstream evidence of the abnormal fragments are correlated and the attack path is reconstructed to obtain the attack chain evaluation result. Based on the multi-source data, the impact of critical assets and the correlation of vulnerability exploitation are determined. The anomaly score, the attack chain assessment result, the impact of critical assets and the correlation of vulnerability exploitation are fused to calculate the threat score, and then the alarm level is output according to the threat score.

[0006] By adopting the above technical solutions, a structured security view is obtained through correlation modeling of multi-source data. This transforms scattered information such as network traffic, logs, processes, identities, and business topologies into associative security analysis objects, thereby improving the data integrity and contextual consistency of subsequent threat detection. By calculating multi-dimensional behavioral characteristics and establishing behavioral baselines based on the structured security view, normal behavioral states can be characterized from multiple dimensions such as behavioral statistics, temporal changes, relational structures, and asset criticality, thus providing a stable basis for comparison in the identification of unknown threats. By performing anomaly deviation analysis based on multi-dimensional behavioral characteristics and behavioral baselines, abnormal segments deviating from normal behavioral states can be identified and their degree of abnormality can be quantified, thereby improving the ability to detect unknown behavioral patterns and low-speed, small-scale attacks. By correlating upstream and downstream evidence of abnormal segments and reconstructing attack paths, scattered anomalies can be integrated into attack chains with sequential logic, thereby enhancing the interpretability of alert conclusions. By integrating anomaly scores, attack chain assessment results, critical asset impact, and vulnerability exploitation relevance to calculate threat scores, the severity of threats can be comprehensively judged and alert levels can be output, thereby improving the accuracy of unknown network threat detection and graded alerts.

[0007] In one example, the present invention can be further configured as follows: the association modeling of the multi-source data to obtain a structured security view includes: Obtain network traffic metadata, host and terminal logs, process events, authentication behavior, and service topology information from the multi-source data; From the network traffic metadata, the host and terminal logs, the process events, the authentication behavior, and the service topology information, determine users, hosts, sessions, processes, IP addresses, domain names, and file objects as entities; The structured security view is obtained by performing association modeling based on the access relationships, authentication relationships, execution relationships, communication relationships, and file operation relationships between the entities.

[0008] By adopting the above technical solutions, and by acquiring network traffic metadata, host and terminal logs, process events, authentication behaviors, and business topology information from multi-source data, it is possible to cover multiple security contexts such as network communication, host status, process activity, account authentication, and business relationships, thereby reducing false positives and false negatives caused by a single data source. By identifying users, hosts, sessions, processes, IP addresses, domain names, and file objects as entities, data objects from different sources can be unified into associative analysis objects, thereby improving the ability to correlate and process multi-source data. By performing correlation modeling based on access relationships, authentication relationships, execution relationships, communication relationships, and file operation relationships between entities, a structured security view reflecting the entity interaction process can be formed, thereby providing a clear data foundation for subsequent behavioral feature calculation and evidence tracing.

[0009] In one example, the present invention can be further configured as follows: calculating multi-dimensional behavioral features based on the structured security view and establishing a behavioral baseline based on the historical normal behavior data includes: The entities and entity pairs to be analyzed are determined based on the structured security view. Calculate statistical characteristics, time series characteristics, graph relationship characteristics, access frequency characteristics, failure rate characteristics, path length characteristics, and asset criticality characteristics for the entity and the entity pair to obtain the multidimensional behavioral characteristics; Based on the historical normal behavior data, the normal behavior distribution of the entity and the entity pair is determined, and then the behavior baseline is established based on the normal behavior distribution.

[0010] By adopting the above technical solutions, and by determining the entities and entity pairs to be analyzed based on a structured security view, it is possible to simultaneously cover the behavioral state of a single object and the interaction state between objects, thereby improving the completeness of the behavioral analysis scope. By calculating statistical characteristics, time series characteristics, graph relationship characteristics, access frequency characteristics, failure rate characteristics, path length characteristics, and asset criticality characteristics of entities and entity pairs, the current security behavior state can be characterized from a multi-dimensional perspective, thereby improving the ability to characterize complex attack behaviors. By determining the distribution of normal behavior based on historical normal behavior data and establishing a behavioral baseline, a normal reference for measuring the degree of deviation of current behavior can be obtained, thereby improving the stability and accuracy of anomaly identification.

[0011] In one example, the present invention can be further configured such that establishing the behavioral baseline based on the normal behavioral distribution includes: Extract the statistical mean and fluctuation range used to characterize the steady state of behavior from the normal behavior distribution; Based on the relational representation of the normal behavior distribution in the structured security view, extract the normal relational graph pattern; The statistical mean, the fluctuation range, and the normal relationship diagram pattern are combined to form the behavioral baseline that characterizes the entity and the entity's behavior in response to normal behavior.

[0012] By adopting the above technical solutions, and by extracting the statistical mean and fluctuation range from the normal behavior distribution, the behavioral center and allowable range of change of entities and entity pairs under normal conditions can be determined, thereby improving the quantification of behavior deviation judgment; by extracting the normal relationship graph pattern based on the relationship representation of the normal behavior distribution in the structured security view, the interaction structure between entities under normal conditions can be reflected, thereby improving the ability to identify abnormal relationships and lateral movement behaviors; by combining the statistical mean, fluctuation range, and normal relationship graph pattern to form a behavior baseline, both behavioral numerical changes and relationship structure changes can be constrained, thereby improving the behavior baseline's ability to support the detection of unknown threats.

[0013] In one example, the present invention can be further configured as follows: the step of performing anomaly deviation analysis based on the multidimensional behavioral features and the behavioral baseline to obtain anomaly segments and anomaly scores of the anomaly segments includes: The obtained multidimensional behavioral features are compared with the behavioral baseline to determine the deviation of the multidimensional behavioral features from the behavioral baseline. Identify behavioral segments that deviate from the behavioral baseline based on the deviation; The persistence of the behavior segments is determined, and the behavior segments that meet the persistence condition are associated and integrated to obtain the abnormal segments; An anomalousness score is generated for the anomalous segment based on the degree of deviation of the anomalous segment from the behavioral baseline.

[0014] By employing the above technical solutions, the deviation of the current behavior from the normal behavior state can be determined by comparing the obtained multidimensional behavioral features with the behavioral baseline, thus providing a basis for identifying abnormal segments. By identifying behavioral segments that deviate from the behavioral baseline based on the deviation, abnormal behavioral units that may correspond to unknown threats can be screened out, thereby reducing the interference of irrelevant behaviors on subsequent analysis. By continuously judging and integrating behavioral segments, continuously occurring or interconnected deviation behaviors can be grouped into abnormal segments, thereby improving the completeness of the anomaly analysis results. By generating anomaly scores based on the degree of deviation of abnormal segments from the behavioral baseline, the risk strength of abnormal segments can be quantified, thus providing a calculable basis for subsequent threat scoring.

[0015] In one example, the present invention can be further configured as follows: the step of correlating upstream and downstream evidence of the anomalous fragment and reconstructing the attack path to obtain the attack chain evaluation result includes: Based on the correlation of the abnormal segments in the structured security view and the occurrence order of the abnormal segments recorded in the multi-source data, the upstream and downstream correlation relationships between multiple abnormal segments are determined. Based on the upstream and downstream relationships, evidence is linked among multiple abnormal segments to form an evidence chain; Reconstruct the attack path based on the chain of evidence; Based on the attack path, the completeness of the evidence chain and the continuity of the attack stages are determined, and the attack chain evaluation result is obtained.

[0016] By adopting the above technical solutions, and determining the upstream and downstream relationships based on the correlation and occurrence sequence of abnormal fragments in the structured security view, the sequential connection between multiple abnormal fragments can be identified, thus avoiding fragmented analysis caused by isolated alarms. By forming an evidence chain by associating multiple abnormal fragments based on upstream and downstream relationships, multiple abnormal events can be integrated into a mutually supporting evidence set, thereby enhancing the completeness of the threat judgment basis. By reconstructing the attack path based on the evidence chain, the propagation process of abnormal behavior between different entities and different stages can be restored, thereby improving the ability to identify complex attack behaviors. By determining the completeness of the evidence chain and the continuity of attack stages based on the attack path, the completeness of the attack chain and the stage connection can be evaluated, thereby improving the credibility of the attack chain evaluation results.

[0017] In one example, the present invention can be further configured as follows: determining the impact of critical assets and the correlation of vulnerability exploitation based on the multi-source data, fusing the anomaly score, the attack chain assessment result, the impact of critical assets, and the correlation of vulnerability exploitation to calculate a threat score, and then outputting an alert level based on the threat score, including: Extract asset criticality from the multi-source data, and determine the impact of the critical assets based on the asset criticality corresponding to the assets involved in the abnormal fragments; Vulnerability information is extracted from the multi-source data, and the vulnerability exploitation correlation between the abnormal fragment and the vulnerability exploitation is determined based on the vulnerability information; The threat score is calculated by integrating the anomaly score, the attack chain assessment result, the impact of the critical assets, and the vulnerability exploitation correlation. The alarm level is output based on the matching result between the threat score and the classification conditions.

[0018] By adopting the above technical solutions, and by extracting asset criticality from multi-source data and determining the impact of critical assets, it is possible to distinguish the degree of impact of abnormal segments on different important assets, thereby improving the ability of threat scoring to reflect the impact on business. By extracting vulnerability information from multi-source data and determining the vulnerability exploitation correlation between abnormal segments and vulnerability exploitation, it is possible to determine whether abnormal behavior is related to vulnerability exploitation risk, thereby improving the ability to identify high-risk threats. By integrating anomaly scores, attack chain assessment results, critical asset impact, and vulnerability exploitation correlation to calculate threat scores, it is possible to comprehensively assess threats based on behavioral anomalies, evidence chains, asset impact, and vulnerability risks, thereby improving the accuracy and interpretability of threat scoring. By outputting alarm levels based on the matching results between threat scores and classification conditions, it is possible to classify and present threats of different severity levels, thereby improving the efficiency of priority judgment in alarm handling.

[0019] In a second aspect, the present invention provides a method and system for detecting unknown network threats based on multidimensional behavior, the system comprising: The view building module is used to acquire multi-source data and historical normal behavior data, perform correlation modeling on the multi-source data, and obtain a structured security view; The feature baseline module is used to calculate multi-dimensional behavioral features based on the structured security view and to establish a behavioral baseline based on the historical normal behavior data. The deviation analysis module is used to perform abnormal deviation analysis based on the multidimensional behavioral features and the behavioral baseline to obtain abnormal segments and abnormality scores of the abnormal segments. The link evaluation module is used to correlate upstream and downstream evidence of the abnormal segment and reconstruct the attack path to obtain the attack chain evaluation result. The scoring and alerting module is used to determine the impact of critical assets and the correlation of vulnerability exploitation based on the multi-source data, and to integrate the anomaly score, the attack chain assessment result, the impact of critical assets and the correlation of vulnerability exploitation to calculate the threat score, and then output the alert level based on the threat score.

[0020] By adopting the above technical solutions, a structured security view is obtained through correlation modeling of multi-source data. This transforms scattered information such as network traffic, logs, processes, identities, and business topologies into associative security analysis objects, thereby improving the data integrity and contextual consistency of subsequent threat detection. By calculating multi-dimensional behavioral characteristics and establishing behavioral baselines based on the structured security view, normal behavioral states can be characterized from multiple dimensions such as behavioral statistics, temporal changes, relational structures, and asset criticality, thus providing a stable basis for comparison in the identification of unknown threats. By performing anomaly deviation analysis based on multi-dimensional behavioral characteristics and behavioral baselines, abnormal segments deviating from normal behavioral states can be identified and their degree of abnormality can be quantified, thereby improving the ability to detect unknown behavioral patterns and low-speed, small-scale attacks. By correlating upstream and downstream evidence of abnormal segments and reconstructing attack paths, scattered anomalies can be integrated into attack chains with sequential logic, thereby enhancing the interpretability of alert conclusions. By integrating anomaly scores, attack chain assessment results, critical asset impact, and vulnerability exploitation relevance to calculate threat scores, the severity of threats can be comprehensively judged and alert levels can be output, thereby improving the accuracy of unknown network threat detection and graded alerts.

[0021] In a third aspect, the present invention provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method for detecting unknown network threats with multidimensional behavior.

[0022] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method for detecting unknown network threats with multidimensional behavior. Attached Figure Description

[0023] The accompanying drawings, which form part of this specification, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings: Figure 1 This is a flowchart of a method for detecting unknown network threats with multidimensional behavior in an embodiment of the present invention; Figure 2 This is a structural block diagram of the unknown network threat detection method system with multi-dimensional behavior in this embodiment of the invention; Figure 3 This is a structural block diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0024] The present invention will now be described in detail with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0025] The following detailed description is exemplary and intended to provide further detailed explanation of the invention. Unless otherwise specified, all technical terms used in this invention have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this invention is for describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention.

[0026] Example 1 like Figure 1 As shown, this invention discloses a method for detecting unknown network threats based on multidimensional behavior, specifically including the following steps: S10: Acquire multi-source data and historical normal behavior data, perform correlation modeling on the multi-source data, and obtain a structured security view.

[0027] Specifically, multi-source data reflecting network communication, host operation, process activity, identity authentication, asset context, vulnerability status, and business topology is obtained from enterprise intranets, cloud-edge hybrid environments, or critical business areas. At the same time, historical normal behavior data representing normal access, normal communication, normal login, normal process activity, and normal business access patterns is also obtained. Based on this, objects, events, and interaction records that can be correlated in the multi-source data are uniformly organized, so that scattered traffic records, log records, identity records, asset records, and business topology records can be expressed in the same security analysis context, thereby forming a structured security view that reflects the interaction relationships and security context between objects.

[0028] S20: Calculate multi-dimensional behavioral characteristics based on structured security views and establish behavioral baselines based on historical normal behavior data.

[0029] Specifically, based on the object relationships and interaction contexts already formed in the structured security view, the current behavioral state is characterized from multiple dimensions such as access frequency, communication continuity, behavior sequence, relationship connection status, access failure, access path changes, and asset importance. This yields multi-dimensional behavioral features that reflect the overall characteristics of the current network behavior. At the same time, the long-term stable normal access, normal authentication, normal communication, and normal resource access records in historical normal behavior data are used as a reference to form a behavioral baseline for measuring whether the current behavior deviates from the normal state.

[0030] S30: Perform anomaly deviation analysis based on multidimensional behavioral characteristics and behavioral baseline to obtain abnormal segments and their anomalousness scores.

[0031] Specifically, the obtained multidimensional behavioral features are compared with the behavioral baseline to determine the degree of deviation of the current behavior from the normal behavioral state in terms of frequency changes, time sequence changes, relationship changes, path changes, and asset access changes. Behavioral records with high deviation and persistence or correlation within a certain observation range are identified as abnormal segments. An anomalousness score is generated based on the strength of the deviation of the abnormal segment from the behavioral baseline, so that each abnormal segment has a quantitative basis that can participate in subsequent evidence association and threat scoring.

[0032] S40: Correlate upstream and downstream evidence of the abnormal fragments and reconstruct the attack path to obtain the attack chain evaluation results.

[0033] Specifically, based on the interaction relationships, occurrence order, and involved objects of anomalous fragments in the structured security view, scattered anomalous access, anomalous authentication, anomalous process activities, anomalous communication, and anomalous asset access records are correlated sequentially to identify whether there are upstream and downstream connections between anomalous fragments. Anomalous fragments that can support each other are organized into evidence chains, and the attack path is reconstructed based on the chronological order and correlation direction of the anomalous fragments in the evidence chain. In this way, an attack chain evaluation result that can reflect the sufficiency of evidence and the connection between attack stages is obtained.

[0034] S50: Based on multi-source data, determine the impact of critical assets and the correlation of vulnerability exploitation. Integrate the anomaly score, attack chain assessment results, impact of critical assets and correlation of vulnerability exploitation to calculate the threat score, and then output the alert level based on the threat score.

[0035] Specifically, the importance of assets involved in abnormal segments and the correlation between abnormal behavior and vulnerability exploitation are determined from multi-source data. The abnormality score of abnormal segments, attack chain assessment results, impact of key assets and vulnerability exploitation are used as common basis for threat judgment and integrated calculation. The threat score reflects the degree of behavioral deviation, the degree of evidence chain support, the degree of impact on key assets, the degree of connection of attack stages and the probability of vulnerability hit. Then, the corresponding alarm level is output according to the level range of the threat score.

[0036] In one embodiment, step S10, namely, performing correlation modeling on multi-source data to obtain a structured security view, includes: S11: Obtain network traffic metadata, host and terminal logs, process events, authentication behavior, and business topology information from multi-source data.

[0037] Specifically, network traffic metadata, host and terminal logs, process events, identity authentication behaviors, and business topology information are obtained from traffic mirroring, session records, host logs, terminal agent records, process event records, identity authentication records, asset management records, and business topology records. Among them, network traffic metadata is used to reflect the communication parties, session connections, and external access; host and terminal logs are used to reflect login, file access, and host status changes; process events are used to reflect process creation, process invocation, and suspicious execution; identity authentication behaviors are used to reflect account login, authentication failure, and login from abnormal geographical locations; and business topology information is used to reflect the business dependencies and access path relationships between assets.

[0038] S12: Identify users, hosts, sessions, processes, IP addresses, domain names, and file objects as entities from network traffic metadata, host and terminal logs, process events, authentication behavior, and service topology information.

[0039] Specifically, the system parses the communication endpoint, session identifier, IP address, and domain name in network traffic metadata; organizes the host identifier, user identifier, and file object in host and terminal logs; extracts the process name, process source, and process call object from process events; merges the account, login source, and authentication result in identity authentication behavior; and combines the asset ownership and business connection relationships recorded in the business topology information to determine users, hosts, sessions, processes, IP addresses, domain names, and file objects as entities that can participate in correlation analysis.

[0040] S13: Perform association modeling based on the access relationships, authentication relationships, execution relationships, communication relationships, and file operation relationships between entities to obtain a structured security view.

[0041] Specifically, users, hosts, sessions, processes, IP addresses, domain names, and file objects are used as objects for association modeling. Access relationships, authentication relationships, execution relationships, communication relationships, and file operation relationships are used as the basis for connecting objects. Relationship connections are established according to the interaction forms such as user access to host, account authentication, process execution, host communication, and file reading or modification. The relationship connections are associated with and saved with the corresponding original messages, log records, process events, authentication records, and business topology records to obtain a structured security view that can support subsequent multi-dimensional feature calculation and evidence tracing.

[0042] In one embodiment, step S20, namely calculating multi-dimensional behavioral features based on the structured security view and establishing a behavioral baseline based on historical normal behavior data, includes: S21: Identify the entities and entity pairs to be analyzed based on the structured security view.

[0043] Specifically, in the structured security view, users, hosts, sessions, processes, IP addresses, domain names, and file objects that need to be analyzed are selected as entities to be analyzed. At the same time, entity pairs are determined based on the access, authentication, execution, communication, and file operation relationships that have been formed between entities, so that the independent behavioral state of a single entity and the interactive behavioral state between two entities can be included in the subsequent multi-dimensional behavioral feature calculation process.

[0044] S22: Calculate statistical features, time series features, graph relationship features, access frequency features, failure rate features, path length features, and asset criticality features for entities and entity pairs to obtain multidimensional behavioral features.

[0045] Specifically, for entities and entity pairs, multidimensional behavioral features that reflect the scale, changes, and relationship structure of behavior are calculated. Among them, statistical features are used to characterize statistical states such as the number of accesses, the number of communications, the amount of data, or the number of events; time series features are used to characterize the changing trend of behavior within different observation windows; graph relationship features are used to characterize the connection patterns and relationship changes of entities in the structured security view; access frequency features are used to characterize the density of access behavior; failure rate features are used to characterize the abnormal proportion of authentication failures or access failures; path length features are used to characterize the extension of access paths or attack paths; and asset criticality features are used to characterize the importance of the assets involved in the entity in the business. These multidimensional behavioral features are then used for subsequent anomaly deviation analysis.

[0046] S23: Determine the normal behavior distribution of entities and entity pairs based on historical normal behavior data, and then establish a behavior baseline based on the normal behavior distribution.

[0047] Specifically, historical normal behavior data is collected according to entities and entity pairs. The access frequency, authentication results, communication relationships, process behavior, resource access and relationship connection patterns of each entity and entity pair under normal business operation conditions are statistically analyzed to obtain a normal behavior distribution that reflects the normal behavior state. The statistical states, fluctuation ranges and relationship graph patterns that appear stably in the normal behavior distribution are used as the basis for constructing the behavior baseline, so that the behavior baseline can simultaneously constrain the deviation of behavior values ​​and relationship structures.

[0048] In one embodiment, step S23, namely establishing a behavioral baseline based on the normal behavioral distribution, includes: S231: Extract the statistical mean and fluctuation range from the normal behavior distribution to characterize the steady state of behavior.

[0049] Specifically, the historical normal behavior distribution of entities and entity pairs is statistically analyzed within the observation window. The statistical mean and fluctuation range of behavioral dimensions such as access frequency, authentication count, communication count, failure count, path change, and asset access are extracted. The behavioral baseline can be represented as B_i={mu_i,sigma_i,G_i}, where B_i represents the behavioral baseline of the i-th entity or entity pair within the observation window, mu_i represents the statistical mean, which is used to characterize the central state of normal behavior, sigma_i represents the fluctuation range, which is used to characterize the allowable range of change in normal behavior, and G_i represents the normal relationship graph pattern, which is used to characterize the relationship structure under normal conditions.

[0050] S232: Extract normal relationship graph patterns based on the relationship representation of normal behavior distribution in the structured security view.

[0051] Specifically, the distribution of normal behavior is mapped onto a structured security view, and the access relationships, authentication relationships, execution relationships, communication relationships, and file operation relationships of entities and entity pairs under normal conditions are extracted to form a normal relationship graph pattern that can represent normal connection objects, normal connection directions, normal connection frequencies, and normal connection paths. The normal relationship graph pattern corresponds to G_i in B_i={mu_i,sigma_i,G_i}, and is used to measure the degree of difference between the current relationship graph and the historical normal relationship graph in subsequent anomaly deviation analysis.

[0052] S233: Combine statistical mean, fluctuation range and normal relationship diagram pattern to form a baseline for characterizing entities and their behavior in response to normal behavior states.

[0053] Specifically, the statistical mean mu_i, the fluctuation range sigma_i, and the normal relationship graph pattern G_i are combined into a behavioral baseline B_i={mu_i,sigma_i,G_i}. This allows the behavioral baseline to express both the numerical distribution of entities and entity pairs under normal conditions and the relational structure of entities and entity pairs under normal conditions, thus providing a unified reference for subsequent deviation analysis between current behavioral characteristics and normal behavioral states.

[0054] In one embodiment, step S30 involves performing anomaly deviation analysis based on multidimensional behavioral characteristics and a behavioral baseline to obtain abnormal segments and their anomaly scores, including: S31: Compare the currently obtained multidimensional behavioral features with the behavioral baseline to determine the deviation of the multidimensional behavioral features from the behavioral baseline.

[0055] Specifically, the currently obtained multidimensional behavioral features are taken as new observed behaviors x_i and compared with the behavioral baseline B_i={mu_i,sigma_i,G_i}. The degree of abnormal deviation can be expressed as Anom_i=lambda1×||x_i-mu_i|| / sigma_i+lambda2×GraphDist(G_i,G_i'), where Anom_i represents the degree of abnormal deviation of the i-th new observed behavior, x_i represents the currently obtained new observed behavioral features, mu_i represents the statistical mean of historical normal behavior, sigma_i represents the fluctuation range of historical normal behavior, G_i represents the historical normal relationship graph pattern, G_i' represents the current relationship graph pattern, GraphDist represents the degree of difference between the current relationship graph and the historical normal relationship graph, and lambda1 and lambda2 represent the weights used to adjust the degree of influence of statistical deviation and relationship graph difference.

[0056] S32: Identify behavioral segments that deviate from the baseline behavior based on the deviation.

[0057] Specifically, the degree of abnormal deviation (Anom_i) is used to determine the strength of the deviation of the current behavior from the behavior baseline. When the access frequency, authentication failure, communication path, process execution, resource access, or relationship graph pattern deviates significantly from the normal behavior state, the behavior record in the corresponding observation window is identified as a behavior segment that deviates from the behavior baseline. The entity, entity pair, occurrence order, association relationship, and original record source corresponding to the behavior segment are retained to provide a basis for subsequent continuous judgment and association integration.

[0058] S33: Perform a persistence determination on the behavior segments, and integrate the behavior segments that meet the persistence condition to obtain abnormal segments.

[0059] Specifically, the identified behavioral fragments are continuously assessed to determine whether they appear continuously in multiple observation windows or are associated with other deviating behavioral fragments in terms of entity, relationship, or order of occurrence. When a behavioral fragment continuously deviates from the behavioral baseline or multiple behavioral fragments can be associated around the same user, host, process, session, IP address, domain name, or file object, the behavioral fragments that meet the persistence condition are associated and integrated to obtain abnormal fragments that can be used for subsequent evidence association.

[0060] S34: Generate an abnormality score for the abnormal segment based on the degree of deviation of the abnormal segment from the behavioral baseline.

[0061] Specifically, an anomaly score is generated based on the degree of deviation of the anomaly segment. The anomaly score is used to measure the strength of the deviation of the anomaly segment from the behavioral baseline. When it is necessary to characterize continuous behavior, a sequence model can be used to characterize continuous behavior. The continuous behavior representation can be written as h_t=LSTM(x_t,h_(t-1)), where h_t represents the behavior state representation at the current time, x_t represents the input behavior feature at the current time, h_(t-1) represents the behavior state representation at the previous time, and LSTM represents the sequence model used to characterize temporal dependencies. Subsequently, the degree of temporal anomaly can be measured by reconstruction error, prediction error, or comparative distance, and the measurement result is used as the basis for the anomaly score.

[0062] In one embodiment, step S40, which involves correlating upstream and downstream evidence of the anomalous fragment and reconstructing the attack path to obtain the attack chain evaluation result, includes: S41: Determine the upstream and downstream relationships between multiple anomalous fragments based on the correlation of anomalous fragments in the structured security view and the occurrence order of anomalous fragments recorded in multi-source data.

[0063] Specifically, based on the entities, entity pairs, interaction relationships, and order of occurrence involved in the abnormal segments, the structured security view is used to search for whether there are access acceptance, authentication acceptance, process acceptance, communication acceptance, or file operation acceptance relationships between the abnormal segments. The upstream and downstream relationships between abnormal segments are determined by combining the order of occurrence recorded in multi-source data, so that the previous abnormal segment can serve as the triggering condition, preparatory behavior, or contextual evidence for the next abnormal segment.

[0064] S42: Based on upstream and downstream relationships, multiple abnormal segments are linked to form a chain of evidence.

[0065] Specifically, multiple abnormal fragments with upstream and downstream relationships are combined according to entity association, time sequence, relationship direction and evidence source. The original messages, log records, entity relationship diagrams, vulnerability hit records and asset association records corresponding to fragments such as abnormal login, abnormal process creation, abnormal lateral access, abnormal external connection and abnormal resource access are used as evidence sources to form an evidence chain that can explain whether multiple abnormal events can be combined into a continuous attack path.

[0066] S43: Reconstruct the attack path based on the chain of evidence.

[0067] Specifically, using abnormal fragments in the evidence chain as path nodes and the upstream and downstream relationships between abnormal fragments as path connections, the attack starting point, affected host, abnormal process, access target, external address, and critical asset access behavior are arranged in the order of occurrence and the direction of relationship to reconstruct the attack path from the initial abnormal behavior to the subsequent extended behavior, so that the attack path can express the propagation order, access direction, and scope of impact between abnormal fragments.

[0068] S44: Determine the completeness of the evidence chain and the continuity of the attack phases based on the attack path to obtain the attack chain evaluation results.

[0069] Specifically, the evidence chain is determined based on the attack path to see if it can cover multiple consecutive abnormal events. It is also determined whether there are compound attack stages such as privilege escalation, lateral movement, abnormal external connections, data collection, and batch probing in the attack path. When multiple abnormal fragments can form a continuous path from the initial abnormality to the subsequent expansion in a reasonable order, the integrity of the evidence chain and the continuity of the attack stages are improved. The attack chain evaluation results include the evidence chain integrity chain and the attack stage continuity stage. The chain is used to measure whether multiple abnormal events can be combined into a continuous attack path, and the stage is used to measure whether the attack stages have sequential connection characteristics.

[0070] In one embodiment, in step S50, which involves determining the impact of critical assets and the correlation between vulnerability exploitation based on multi-source data, the anomaly score, attack chain assessment results, impact of critical assets, and correlation between vulnerability exploitation are fused to calculate a threat score. Then, an alert level is output based on the threat score, including: S51: Extract asset criticality from multi-source data and determine the impact of critical assets based on the asset criticality corresponding to the assets involved in the abnormal fragments.

[0071] Specifically, the criticality of assets, business topology information, and asset objects involved in abnormal segments are extracted from multi-source data. The impact of critical assets is determined based on whether the abnormal segments involve critical hosts, critical business areas, important services, sensitive resources, or core business links. The impact of critical assets can be denoted as Asset, which represents the degree to which abnormal segments affect critical assets. When the assets involved in abnormal segments are of high importance in the business topology or are directly related to critical business processes, the impact of critical assets is increased.

[0072] S52: Extract vulnerability information from multi-source data and determine the vulnerability exploitation correlation between abnormal segments and vulnerability exploitation based on the vulnerability information.

[0073] Specifically, vulnerability information, asset correspondence, and behavioral records corresponding to abnormal segments are extracted from multi-source data. Based on the matching between the host, service, port, process, access path, or external behavior involved in the abnormal segment and the vulnerability information, the degree of correlation between the abnormal segment and the known vulnerability exploitation probability is determined. The vulnerability exploitation correlation can be denoted as Vuln, which is used to represent the degree of correlation between abnormal behavior and vulnerability exploitation probability. When the abnormal segment involves an asset with a vulnerability and the behavioral characteristics match the vulnerability exploitation behavior, the vulnerability exploitation correlation is improved.

[0074] S53: The threat score is calculated by integrating the anomaly score, attack chain assessment results, critical asset impact, and vulnerability exploitation relevance.

[0075] Specifically, the anomaly score, attack chain assessment results, critical asset impact, and vulnerability exploitation relevance are input into the comprehensive threat scoring function. The comprehensive threat scoring function can be expressed as Threat = a × Anom + b × Chain + c × Asset + d × Stage + e × Vuln, where Threat represents the threat score, Anom represents the degree of anomaly deviation, used to measure the difference between the anomalous segment and the behavioral baseline, Chain represents the completeness of the evidence chain, used to measure whether multiple anomalous events can be combined into a continuous attack path, Asset represents the critical asset impact, Stage represents the continuity of the attack stage, Vuln represents the degree of correlation between anomalous behavior and vulnerability exploitation probability, and a to e represent configurable weights used to adjust the degree of influence of each scoring factor on the threat score.

[0076] S54: Output the alarm level based on the matching result between the threat score and the classification conditions.

[0077] Specifically, the threat score (Threat) is matched with preset classification conditions, and the corresponding alarm level is output according to the interval in which the threat score falls. Anomalies with high deviation, high evidence chain completeness, high impact on critical assets, high attack phase continuity, and high vulnerability exploitation relevance are classified into higher-level alarms. When the alarm level needs to be further used for coordinated response, the response level can be represented as ActionLevel=f(Threat,Confidence,Policy,AnalystState), where ActionLevel represents the response level, Threat represents the threat score, Confidence represents the confidence level of the threat conclusion, Policy represents the security policy constraint, and AnalystState represents the current analyst confirmation status. When Threat and Confidence are both in a high interval, a predefined handling script can be used. When they are in the middle interval, the analyst can review the data. When they are in a low interval, the data can be kept under observation and the sampling window can be expanded.

[0078] Example 2 like Figure 2 As shown, based on the same inventive concept as the above embodiments, the present invention also provides a method system for detecting unknown network threats with multi-dimensional behavior, comprising: The view building module is used to acquire multi-source data and historical normal behavior data, perform correlation modeling on the multi-source data, and obtain a structured security view; The feature baseline module is used to calculate multi-dimensional behavioral features based on the structured security view and to establish a behavioral baseline based on historical normal behavior data. The deviation analysis module is used to perform abnormal deviation analysis based on multidimensional behavioral characteristics and behavioral baselines to obtain abnormal segments and their abnormality scores. The link evaluation module is used to correlate upstream and downstream evidence of abnormal segments and reconstruct the attack path to obtain the attack chain evaluation result. The scoring and alerting module is used to determine the impact of critical assets and the relevance of vulnerability exploitation based on multi-source data. It integrates the anomaly score, attack chain assessment results, impact of critical assets and relevance of vulnerability exploitation to calculate the threat score, and then outputs the alert level based on the threat score.

[0079] Optionally, the view building modules include: The data acquisition submodule is used to acquire network traffic metadata, host and terminal logs, process events, authentication behavior and business topology information from multi-source data. The entity determination submodule is used to determine users, hosts, sessions, processes, IP addresses, domain names, and file objects as entities from network traffic metadata, host and terminal logs, process events, authentication behavior, and business topology information. The relationship modeling submodule is used to perform association modeling based on access relationships, authentication relationships, execution relationships, communication relationships, and file operation relationships between entities to obtain a structured security view.

[0080] Optionally, the feature baseline module includes: The object determination submodule is used to determine the entities and entity pairs to be analyzed based on the structured security view; The feature calculation submodule is used to calculate statistical features, time series features, graph relationship features, access frequency features, failure rate features, path length features, and asset criticality features for entities and entity pairs, thereby obtaining multidimensional behavioral features. The baseline establishment submodule is used to determine the normal behavior distribution of entities and entity pairs based on historical normal behavior data, and then establish a behavior baseline based on the normal behavior distribution.

[0081] Optionally, the baseline establishment submodule includes: The statistical extraction unit is used to extract the statistical mean and fluctuation range from the normal behavior distribution to characterize the steady state of behavior; The graph pattern extraction unit is used to extract normal relationship graph patterns based on the relationship representation of normal behavior distribution in the structured security view; The baseline combination unit is used to combine statistical mean, fluctuation range and normal relationship diagram pattern to form a behavioral baseline that characterizes entities and their behavior in response to normal behavioral states.

[0082] Optional, the deviation analysis module includes: The feature comparison submodule is used to compare the currently obtained multidimensional behavioral features with the behavioral baseline to determine the deviation of the multidimensional behavioral features from the behavioral baseline. The segment recognition submodule is used to identify behavioral segments that deviate from the behavioral baseline based on the deviation situation; The segment integration submodule is used to determine the persistence of behavioral segments and to integrate behavioral segments that meet the persistence condition to obtain abnormal segments. The score generation submodule is used to generate anomaly scores for abnormal segments based on the degree of deviation of the abnormal segments from the behavioral baseline.

[0083] Optionally, the link evaluation module includes: The upstream and downstream submodules are used to determine the upstream and downstream relationships between multiple abnormal segments based on the association relationships of abnormal segments in the structured security view and the occurrence order of abnormal segments recorded in multi-source data. The evidence association submodule is used to associate multiple abnormal fragments based on upstream and downstream relationships to form an evidence chain; The path reconstruction submodule is used to reconstruct the attack path based on the chain of evidence; The chain evaluation submodule is used to determine the completeness of the evidence chain and the continuity of the attack phases based on the attack path, and obtain the attack chain evaluation result.

[0084] Optional, the scoring and alarm module includes: The asset valuation submodule is used to extract asset criticality from multi-source data and determine the impact of critical assets based on the asset criticality corresponding to the assets involved in the abnormal fragments. The vulnerability assessment submodule is used to extract vulnerability information from multi-source data and determine the vulnerability exploitation correlation between abnormal fragments and vulnerability exploitation based on the vulnerability information. The threat scoring submodule is used to integrate anomaly scores, attack chain assessment results, critical asset impact, and vulnerability exploitation relevance to calculate a threat score. The alarm level output submodule is used to output the alarm level based on the matching result between the threat score and the grading conditions.

[0085] Example 3 like Figure 3 As shown, the present invention also provides an electronic device 100 for implementing a method for detecting unknown network threats with multidimensional behavior; The electronic device 100 includes a memory 101, at least one processor 102, a computer program 103 stored in the memory 101 and executable on at least one processor 102, and at least one communication bus 104.

[0086] The memory 101 can be used to store computer program 103. The processor 102 implements the steps of the method of the multi-dimensional behavior unknown network threat detection method of Embodiment 1 by running or executing the computer program stored in the memory 101 and calling the data stored in the memory 101.

[0087] The memory 101 may primarily include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created based on the use of the electronic device 100 (such as audio data), etc. In addition, the memory 101 may include non-volatile memory, such as hard disk, RAM, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other non-volatile solid-state storage device.

[0088] At least one processor 102 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 102 may be a microprocessor or any conventional processor. Processor 102 is the control center of electronic device 100, connecting various parts of electronic device 100 via various interfaces and lines.

[0089] The memory 101 in the electronic device 100 stores multiple instructions to implement a method for detecting unknown network threats with multi-dimensional behavior, and the processor 102 can execute multiple instructions to achieve the following: Acquire multi-source data and historical normal behavior data, perform correlation modeling on the multi-source data, and obtain a structured security view; Multidimensional behavioral characteristics are calculated based on a structured security view, and a behavioral baseline is established based on historical normal behavior data. Anomaly deviation analysis was performed based on multidimensional behavioral characteristics and behavioral baseline to obtain abnormal segments and their anomality scores. By correlating upstream and downstream evidence of the abnormal fragments and reconstructing the attack path, the attack chain evaluation results are obtained. Based on multi-source data, the impact of critical assets and the correlation of vulnerability exploitation are determined. The anomaly score, attack chain assessment results, impact of critical assets and correlation of vulnerability exploitation are integrated to calculate the threat score, and then the alarm level is output according to the threat score.

[0090] Example 4 If the modules / units integrated in the electronic device 100 are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or system capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, and read-only memory (ROM).

[0091] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0092] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A system that specifies functions in one or more boxes.

[0093] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including an instruction set implemented in a process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0094] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0095] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A method for detecting unknown network threats based on multidimensional behavior, characterized in that, The method includes: Acquire multi-source data and historical normal behavior data, perform correlation modeling on the multi-source data, and obtain a structured security view; Multidimensional behavioral characteristics are calculated based on the structured security view, and a behavioral baseline is established based on the historical normal behavior data; Anomaly deviation analysis is performed based on the multidimensional behavioral characteristics and the behavioral baseline to obtain abnormal segments and their anomality scores. The upstream and downstream evidence of the abnormal fragments are correlated and the attack path is reconstructed to obtain the attack chain evaluation result. Based on the multi-source data, the impact of critical assets and the correlation of vulnerability exploitation are determined. The anomaly score, the attack chain assessment result, the impact of critical assets and the correlation of vulnerability exploitation are fused to calculate a threat score, and then an alert level is output based on the threat score.

2. The method for detecting unknown network threats based on multidimensional behavior according to claim 1, characterized in that, The process of performing correlation modeling on the multi-source data to obtain a structured security view includes: Obtain network traffic metadata, host and terminal logs, process events, authentication behavior, and service topology information from the multi-source data; From the network traffic metadata, the host and terminal logs, the process events, the authentication behavior, and the service topology information, determine users, hosts, sessions, processes, IP addresses, domain names, and file objects as entities; The structured security view is obtained by performing association modeling based on the access relationships, authentication relationships, execution relationships, communication relationships, and file operation relationships between the entities.

3. The method for detecting unknown network threats based on multidimensional behavior according to claim 1, characterized in that, The calculation of multidimensional behavioral features based on the structured security view and the establishment of a behavioral baseline based on the historical normal behavior data include: The entities and entity pairs to be analyzed are determined based on the structured security view. Calculate statistical characteristics, time series characteristics, graph relationship characteristics, access frequency characteristics, failure rate characteristics, path length characteristics, and asset criticality characteristics for the entity and the entity pair to obtain the multidimensional behavioral characteristics; Based on the historical normal behavior data, the normal behavior distribution of the entity and the entity pair is determined, and then the behavior baseline is established based on the normal behavior distribution.

4. The method for detecting unknown network threats based on multidimensional behavior according to claim 3, characterized in that, The step of establishing the behavioral baseline based on the normal behavioral distribution includes: Extract the statistical mean and fluctuation range used to characterize the steady state of behavior from the normal behavior distribution; Based on the relational representation of the normal behavior distribution in the structured security view, extract the normal relational graph pattern; The statistical mean, the fluctuation range, and the normal relationship diagram pattern are combined to form the behavioral baseline that characterizes the entity and the entity's behavior in response to normal behavior.

5. The method for detecting unknown network threats based on multidimensional behavior according to claim 1, characterized in that, The step of performing anomaly deviation analysis based on the multidimensional behavioral features and the behavioral baseline to obtain abnormal segments and their anomaly scores includes: The obtained multidimensional behavioral features are compared with the behavioral baseline to determine the deviation of the multidimensional behavioral features from the behavioral baseline. Identify behavioral segments that deviate from the behavioral baseline based on the deviation; The persistence of the behavior segments is determined, and the behavior segments that meet the persistence condition are associated and integrated to obtain the abnormal segments; An anomalousness score is generated for the anomalous segment based on the degree of deviation of the anomalous segment from the behavioral baseline.

6. The method for detecting unknown network threats based on multidimensional behavior according to claim 1, characterized in that, The process of correlating upstream and downstream evidence of the anomalous fragments and reconstructing the attack path to obtain the attack chain evaluation result includes: Based on the correlation of the abnormal segments in the structured security view and the occurrence order of the abnormal segments recorded in the multi-source data, the upstream and downstream correlation relationships between multiple abnormal segments are determined. Based on the upstream and downstream relationships, evidence is linked among multiple abnormal segments to form an evidence chain; Reconstruct the attack path based on the chain of evidence; Based on the attack path, the completeness of the evidence chain and the continuity of the attack stages are determined, and the attack chain evaluation result is obtained.

7. The method for detecting unknown network threats based on multidimensional behavior according to claim 1, characterized in that, The process of determining the impact of critical assets and the correlation between vulnerability exploitation based on the multi-source data, integrating the anomaly score, the attack chain assessment result, the impact of critical assets, and the correlation between vulnerability exploitation to calculate a threat score, and then outputting an alert level based on the threat score, includes: Extract asset criticality from the multi-source data, and determine the impact of the critical assets based on the asset criticality corresponding to the assets involved in the abnormal fragments; Vulnerability information is extracted from the multi-source data, and the vulnerability exploitation correlation between the abnormal fragment and the vulnerability exploitation is determined based on the vulnerability information; The threat score is calculated by integrating the anomaly score, the attack chain assessment result, the impact of the critical assets, and the vulnerability exploitation correlation. The alarm level is output based on the matching result between the threat score and the classification conditions.

8. A method and system for detecting unknown network threats based on multidimensional behavior, characterized in that, The system includes: The view building module is used to acquire multi-source data and historical normal behavior data, perform correlation modeling on the multi-source data, and obtain a structured security view; The feature baseline module is used to calculate multi-dimensional behavioral features based on the structured security view and to establish a behavioral baseline based on the historical normal behavior data. The deviation analysis module is used to perform abnormal deviation analysis based on the multidimensional behavioral features and the behavioral baseline to obtain abnormal segments and abnormality scores of the abnormal segments. The link evaluation module is used to correlate upstream and downstream evidence of the abnormal segment and reconstruct the attack path to obtain the attack chain evaluation result. The scoring and alerting module is used to determine the impact of critical assets and the correlation of vulnerability exploitation based on the multi-source data, and to integrate the anomaly score, the attack chain assessment result, the impact of critical assets and the correlation of vulnerability exploitation to calculate the threat score, and then output the alert level based on the threat score.

9. An electronic device, characterized in that, It includes a processor and a memory, the processor being used to execute a computer program stored in the memory to implement the method for detecting unknown network threats with multidimensional behavior as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one instruction, which, when executed by a processor, implements the method for detecting unknown network threats with multidimensional behavior as described in any one of claims 1 to 7.