A method for tracing the source of network attacks

By obtaining threat intelligence and alarm information for traceability analysis, the problem that traditional network protection methods are difficult to detect APT is solved, efficient traceability of network attacks and accurate strategy formulation is achieved, and network security response capabilities are improved.

CN111490970BActive Publication Date: 2025-08-12XIAN JIAODA JIEPU NETWORK SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010101374.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-02-19
Publication Date
2025-08-12
Estimated Expiration
2040-02-19

AI Technical Summary

Technical Problem

Traditional network protection methods are difficult to effectively detect and defend against advanced persistent threat attacks (APTs), especially due to their complexity and diversity, which makes it difficult to accurately trace the origin analysis of network security situation awareness, affecting policy formulation and rectification measures.

Method used

By obtaining threat intelligence, combining alarm information and asset information, conducting alarm association and attack stage judgment, determining the source of the attack and restoring the attack process, evaluating the scope of impact, and using the network security situation awareness system for traceability analysis.

Benefits of technology

It realizes efficient traceability analysis of network attacks, provides accurate traceability results, helps network operation and maintenance personnel formulate effective security strategies, and reduces the losses caused by attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111490970B_ABST
    Figure CN111490970B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for tracing the source of network attacks, including: obtaining threat intelligence of a specified type and caching it in a local threat intelligence database; obtaining current alarm information and the local threat intelligence to determine the attack source of the alarm; correlating the alarms based on the device identifiers of the attack source and / or the attack target, determining the attack stage of the device and determining the device vulnerability level based on the attack stage; obtaining the asset information of the device and determining the impact range of the attack based on the alarm correlation results. This method achieves effective tracing and analysis of network attacks, obtains multiple tracing results, and updates the tracing data each time the tracing is performed, which provides a basis for network operation and maintenance personnel to handle problems and strengthen security policies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and data analysis, and in particular relates to a method for tracing and analyzing the source of network attacks. Background Art

[0002] With technological advancements, the internet has penetrated every aspect of society, and attacks are increasing year by year, making network security a growing concern. The attack techniques and methods used by cyber attackers are also evolving. Traditional protection methods, such as firewalls and other security tools at network boundaries to isolate internal and external networks, are effective against common, easily detected attacks, such as attacks from a single node against other nodes, attacks targeting system vulnerabilities, and protection against Trojan horse programs.

[0003] However, as cyberattack methods continue to emerge, they are not only diverse but also rapidly evolving towards highly integrated and automated approaches. With the increasing complexity of networks, security threats are also becoming more diverse. Faced with a large number of logs and alerts in various formats and forms, this is particularly true for Advanced Persistent Threat (APT) attacks, where the tools and malicious programs used are often targeted and difficult to detect. These attacks also utilize zero-day vulnerabilities and are persistent, requiring long periods of observation, reconnaissance, information collection, and social engineering before gradually infiltrating, transmitting information back, and controlling communications. Traditional approaches have long been overwhelmed, leading to the emergence of network security situational awareness.

[0004] Network security situational awareness is a proactive network defense measure. It collects extensive log data from firewalls, security audits, antivirus software, and other hardware and software. Based on this data processing, it provides a timely assessment and reflection of the current network status and predicts future trends. It not only reflects the current network security situation but also predicts potential attacks within the network, enabling proactive defenses. This gives managers a comprehensive understanding of the network's security status and evolving trends, enabling rapid responses to complex and evolving security threats, thereby alleviating the burden of both understanding and responding. Network attack source tracing is a key component of situational awareness. Based on known security threat events, it traces the threat path, process, attack methods, and aliasing, quickly identifying the source IP address, physical location, and other valuable information. This provides network operations personnel with a basis for addressing issues and strengthening security policies. The efficiency of source tracing analysis and the accuracy of its results are directly related to subsequent policy formulation and corrective measures. Summary of the Invention

[0005] In view of the above, the present invention provides a method for tracing and analyzing the source of network attacks. The method determines the source of the attack based on the attack stage of the alarm, the time when the alarm occurred, the source IP address and destination IP address in the alarm, combined with the asset business library, threat intelligence library, etc.; performs process deduction on the attack chain, restores the timeline of the attack process, and evaluates the scope of the attack impact. The technical solution is shown below.

[0006] A method for tracing and analyzing a network attack, comprising:

[0007] Obtain threat intelligence of a specified type and cache it in the local threat intelligence database;

[0008] Obtain the current alarm information and the local threat intelligence to determine the attack source of the alarm;

[0009] According to the device identifiers of the attack source and / or the attack target, alarm correlation is performed to determine the attack stage of the device and the device vulnerability level according to the attack stage;

[0010] Obtain asset information of the device and determine the impact range of the attack based on the alarm correlation results.

[0011] First, determine the attack source of the alarm, query threat intelligence based on the source IP of the alarm, and determine whether the attack source is intranet or extranet.

[0012] The second aspect is to restore the attack process, including alarm association, attack stage determination, loss level determination and alarm time series correction.

[0013] The first step is to correlate alarms, specifically:

[0014] According to the specified conditions, obtain all alarms that are consistent with the source IP or destination IP of this alarm;

[0015] If the source IP is consistent with the destination IP of this alarm: If the source ports and destination ports of the two alarms are consistent, the two alarms are merged; if the source ports of the two alarms are inconsistent but the destination ports are consistent, the two alarms are considered to be associated alarms;

[0016] If the destination IP is the same as the source IP of this alarm: When the destination port of another alarm is the same as the source port of this alarm, the two alarms are considered to be correlated alarms;

[0017] If the source IP and destination IP are consistent with the source IP and destination IP of this alarm respectively: When the source port and destination port of the two alarms are consistent, the two alarms are merged.

[0018] Secondly, determine the attack stage that the IP is in, query all alarms based on the IP, obtain all alarm records experienced by the IP, extract the attack behavior characteristics in the alarm information, and determine the attack stage of each alarm based on the preset correspondence between the attack behavior characteristics and the attack stage; take the highest attack stage in the alarm as the current attack stage of the IP; and include the attack stage in the alarm tracing record.

[0019] Thirdly, determine the compromise level based on the attack stage the IP is in, including: determining the correspondence between the attack stage and the compromise level, and determining the compromise level as low suspicious, high suspicious, or compromised based on the attack stage the IP is in; and including the compromise level in the alarm tracing record.

[0020] Finally, the time sequence of the alarms is corrected: according to the above attack stages, the related alarms are divided and the alarms in each attack stage are sorted by time to obtain the attack stage sequence of the alarms;

[0021] Sort the alarms according to their occurrence time to obtain the initial time sequence of the alarms;

[0022] Compare the attack phase sequence of the alarm with the initial time sequence of the alarm, and remove the alarms with inconsistent sequences; remove the alarms whose attack source is the intranet and is in the reconnaissance, tracking and payload delivery stages;

[0023] According to the corrected alarm time series, the attack propagation path is obtained.

[0024] Third, based on the aforementioned attack process, determine the IP affected by the attack; obtain the IP's asset information to determine the business scope affected by the attack. The asset information includes the asset's attributes, vulnerabilities, risks, business status, and operating status; the asset attributes include region, department, and person in charge.

[0025] The source tracing analysis method described above first determines the attack source as either an external or internal network by querying a threat intelligence database, and further determines the nature of the attack source based on the intelligence. It then sequentially performs alert correlation, identifies the attack phase, determines the compromise level, and corrects the alarm time series to reconstruct the attack process and propagation path. Finally, it assesses the impact of the attack based on asset information. This method effectively traces and analyzes network attacks, generating multiple tracing results. Each traceback update provides valuable insights for network operations personnel, providing a basis for addressing issues and strengthening security policies. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 This is a schematic diagram of the overall process of an embodiment of the network attack source tracing analysis method of the present invention;

[0027] Figure 2 for Figure 1Schematic diagram of the alarm association process in;

[0028] Figure 3 for Figure 1 Schematic diagram of attack source analysis process in [1];

[0029] Figure 4 for Figure 1 Schematic diagram of the attack process analysis flow in . DETAILED DESCRIPTION

[0030] The technical solutions of the present invention are described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0031] In order to facilitate understanding of the embodiments of the present invention, relevant technical terms involved are first introduced briefly.

[0032] Threats are potential causes of unwanted incidents that may lead to harm to a system or organization.

[0033] Information security risk refers to the degree of impact on an organization caused by a security incident caused by a threat exploiting vulnerabilities in the information system.

[0034] Vulnerability is a weakness in an asset or assets that can be exploited by a threat.

[0035] Network traffic is a collection of data packets generated by devices connected to the network (including various network devices, security devices, servers, etc.).

[0036] Alarm data is information generated by security devices or security platforms based on analysis of network traffic, logs, scan and probe return information, or based on machine learning, engine-type devices, tools, and component correlation analysis, describing abnormal network conditions, abnormal system access, or system vulnerabilities.

[0037] A cybersecurity incident is a situation where, due to human error or inherent software or hardware defects or failures, it poses a potential threat to information systems and even affects the normal provision of services. Cybersecurity incidents typically have a negative impact on society and are confirmed to require specific action.

[0038] Correlation analysis involves defining rules based on the actual environment to correlate various security events (log information, alarm information, etc.) in terms of occurrence sequence and subsequent impact. This allows for preventative responses based on known scenarios. Examples of correlation analysis rules include: Using partial content from a single log entry as an alarm, such as login, startup, and shutdown events in a log, all serving as alarms; Based on the frequency of specific events within a unit of time, such as three incorrect user passwords within a minute in a log, this could be considered a brute force attack; and Correlation analysis between logs from multiple devices, such as multiple logs with the same target IP address but different source IP addresses, could indicate a DDOS attack.

[0039] Threat intelligence is a type of evidence-based knowledge that includes context, attack mechanisms, attack indicators, implications, and actionable recommendations. Threat intelligence describes existing or impending threats or dangers to assets and can be used to inform entities to take certain responses to the relevant threats or dangers. Threat intelligence aims to provide comprehensive, accurate, relevant, and actionable knowledge and information to asset entities facing threats (usually the enterprise or organization to which the assets belong). In a narrow sense, threat intelligence mainly consists of compromise identifiers used to identify and detect threats, such as file hashes, IP addresses, domain names, program execution paths, registry entries, etc., as well as related attribution tags.

[0040] Network situation, the current state and changing trends of the entire network composed of factors such as the operating status of various network devices, network behavior, and user behavior.

[0041] A network security situational awareness system collects, extracts, and integrates data on network environment factors that may influence changes in network security status and trends (such as assets, network traffic, operational status, device alerts, vulnerabilities, security incidents, and threat intelligence). Leveraging analytical techniques like data mining, it analyzes network security status and predicts trends, thereby assisting in emergency response and security decision-making. Traditional heterogeneous security defenses, primarily based on single-point defenses like IDS, firewalls, and VDS, effectively divide network security into isolated, interconnected security islands. A situational awareness system, on the other hand, focuses on viewing the network as a whole. It integrates various attack detection, location, and tracking methods from traditional network security theory to provide comprehensive, centralized network security management and intelligent, integrated analysis. It integrates diverse security components into a seamless security system, creating a comprehensive network security management system that analyzes security status and identifies future trends. This system provides users with an intuitive overview of network status, providing a reliable basis for accurate operations and minimizing the risks and losses associated with network security issues.

[0042] Advanced Persistent Threat (APT) attacks, which aim to steal information assets, are typically targeted attacks using unknown threats and consist of multiple stages. For example, one method for dividing the attack stages (links) is as follows:

[0043] ① Reconnaissance and Tracking: Attackers use social networks and social engineering to learn about the target organization's personnel, IT architecture, and defense measures. This process is the pre-attack "reconnaissance" phase. Common behavioral signatures include port scanning, network scanning, system scanning, vulnerability scanning, and SSH scanning. Commonly used system vulnerability scanning tools include Nessus, SSS, ISS, X-scan, and Retha. Scanning tools for service ports include Nmap, Super Scan, and Amap. Scanning tools for web services include SQL scanners, PHP scanners, and upload vulnerability scanners. Website scanning tools include Appscan, Acunetix Web Vulnerability Scanner, and Jsky. Database scanning tools include Shadow Database Scanner, NGSSQuirreL, and SQL weak password scanners.

[0044] Attackers collect information such as the target network topology, IP distribution, network connection device information, and server distribution through Google Hacking, WHOIS, DNS queries, and network topology scanners (such as Solarwinds).

[0045] ② Payload delivery: Based on the results of target reconnaissance and tracking, malicious code is purchased or written to target existing vulnerabilities and evasion tests are conducted to ensure that the attack can successfully bypass the target organization's existing defense system. Spear phishing attacks are launched through phishing emails, phishing web pages, USB storage devices, etc., to lure the target into clicking and downloading the pre-prepared malicious code.

[0046] Common methods include: DOS possible Memcached DDoS amplification query (set), VOIP REGISTER message Flood UDP, VOIP INVITE message flood UDP, GPL VOIP SIP INVITE message flood, DOS possible Sentinal LM amplification attack (request) inbound, DOS DNS amplification attack inbound, DOS possible NTP DDoS inbound frequent unverified MON_LIST request IMPL 0x03, etc.

[0047] ③ Penetration and exploitation: Malicious code is successfully implanted into the target device and system, and exploits vulnerabilities in the target device and system to obtain higher execution permissions; common methods include: brute force cracking, spear phishing attacks, watering hole attacks, USB flash drive transfers, accessing malicious links, and malicious emails.

[0048] ④Installation and implantation: Using the successfully obtained execution permissions, the target device is controlled to download malware with richer functions, install and launch the software.

[0049] ⑤ Communication control: After the malware is launched, it will actively establish a connection with the attacker's remote command and control (C&C) server and receive control signals sent by the C&C server; common ones include: DNS covert channel detection (legitimate DNS request baseline, frequency and regularity, information entropy, semantic recognition), abnormal privilege escalation, service monitoring, etc.

[0050] ⑥ Penetration and sabotage: The attacker controls the target device through the C&C server to initiate further malicious actions, such as scanning for vulnerabilities in other devices on the intranet, invading new targets, mining valuable data, or transmitting stolen data.

[0051] Common infiltration methods include: TROJAN Windows executable file base64 encoding, INFO suspicious Mozilla user agent - possibly forged (Mozilla / 4.0), MALWARE suspicious user agent, ETPOLICYWin32 / Sogou user agent (SOGOU_UPDATER), MALWARE-CNC Win.Trojan.ZeroAccess outbound connection, etc.

[0052] When the attack's behavioral characteristics meet the last two stages ("communication control" or "penetration and destruction"), the device can be defined as compromised, posing a high threat. Devices meeting the first two stages ("reconnaissance and tracking" or "payload delivery") are relatively less threatening and classified as low-suspicion. Devices meeting the middle two stages ("penetration and exploitation" and "installation") are generally between low-suspicion and compromised, and are defined as high-suspicion. It should be noted that the aforementioned attacking or attacked devices include servers, routers, switches, PCs, and other network-connected devices.

[0053] In order to locate the source of the attack in a timely and accurate manner, understand the status, scope and extent of the attack, and minimize the losses caused by the attack, an embodiment of the present invention provides a method for tracing the source of network attacks. In the application of this embodiment, a network security system or device is deployed inside the system to record all access, traffic, and security logs within the system, monitor whether there are abnormal data or behaviors in the assets, and issue corresponding security alerts.

[0054] like Figure 1 As shown in the overall process, source tracing analysis is based on known security threat events, tracing the threat path, threat process, attack method, and virtual identity, quickly identifying useful information such as the source IP address and physical location of the attack. When correlation analysis or anomaly analysis generates an alarm or discovers suspected attack behavior, the alarm is stored in the alarm database. The source tracing analysis engine obtains the alarm data and conducts detailed analysis. First, the alarm is correlated based on the source IP address, destination IP address, and port number, including merging and removing, to filter out relevant alarm data. Then, attack source analysis is performed based on the locally cached threat intelligence database. Combined with asset business data and vulnerability data, the attack stage and alarm occurrence time of the alarm are analyzed, and the process of deducing the alarm along the attack chain is restored. The timeline of the entire attack process is restored, and the cause of the attack is analyzed to determine the scope and source of the attack. The purpose is to provide a basis for network operations personnel to handle issues and strengthen security policies.

[0055] The above traceability analysis stores the traceability results of each alarm in the alarm traceability record for comparison in subsequent alarm traceability.

[0056] The technical solution of this embodiment of the present invention primarily involves: acquiring threat intelligence of a specified type and caching it in a local threat intelligence database; obtaining the current alarm information and the local threat intelligence to determine the attack source of the alarm; correlating the alarms based on the device identifiers of the attack source and / or the attack target, determining the attack stage of the device and, based on the attack stage, determining the device's vulnerability level; and obtaining the device's asset information and, based on the alarm correlation results, determining the impact scope of the attack. The specific analysis steps are described in detail with reference to the accompanying figures.

[0057] like Figure 2 As shown in the figure, alarm associations include:

[0058] According to the specified conditions, all alarms that are consistent with the source IP or destination IP of this alarm are obtained. The specified conditions may include alarms within a certain time period, alarms from a certain physical area, or alarms of a certain type of threat or attack.

[0059] Compare the IP addresses involved in other alarms with this alarm, and merge and remove alarms based on correlation rules, specifically:

[0060] If the source IP is consistent with the destination IP of this alarm: If the source ports and destination ports of the two alarms are consistent, the two alarms are merged; if the source ports of the two alarms are inconsistent but the destination ports are consistent, the two alarms are considered to be associated alarms;

[0061] If the destination IP is the same as the source IP of this alarm: When the destination port of another alarm is the same as the source port of this alarm, the two alarms are considered to be correlated alarms;

[0062] If the source IP and destination IP are consistent with the source IP and destination IP of this alarm respectively: When the source port and destination port of the two alarms are consistent, the two alarms are merged.

[0063] After the alarm correlation is completed, the associated alarms are summarized and stored in the database.

[0064] like Figure 3 As shown in the figure, attack source analysis involves obtaining the attack source IP address in the alert and, based on the DNS log and threat intelligence database, determining whether the source IP address belongs to the intranet or the Internet. If it belongs to the Internet, its geographic information is further determined. The specific analysis process distinguishes between intranet attack sources and Internet attack sources:

[0065] If the attack originates from the intranet based on the alarm source IP, query the initial compromise level of the source IP in the alarm tracing record.

[0066] If the source IP is found to be highly suspicious or compromised, the alarm is correlated with the destination IP to determine the attack stage of the destination IP and the compromise level of the destination IP based on the attack stage.

[0067] If the source IP is found to be low-suspicious or no traceability record is found for the source IP, an alarm association is performed based on the source IP and the destination IP to determine the attack stage of the source IP and the destination IP, and the compromise level of the source IP and the destination IP is determined based on the attack stage.

[0068] Update the compromise levels of the source IP and destination IP to the alarm tracing record.

[0069] If the source IP of the alarm is used to determine that the attack originated from the external network,

[0070] Mark the attack source based on the geographic information of local threat intelligence and include the geographic tag in the alarm tracing record; the geographic information includes the correspondence between the domain name, IP address, and country / city information, and the country / city information includes latitude and longitude information;

[0071] Obtain DNS logs and query the attack source IP or domain name in local threat intelligence. If the attack source is malicious, mark the target IP's initial compromise level as high suspicion or compromised. If the attack source is not malicious, mark the target IP's initial compromise level as low suspicion.

[0072] Perform alarm correlation based on the target IP, determine the attack stage of the target IP, and determine the target IP vulnerability level based on the attack stage;

[0073] The compromise level of the destination IP is included in the alarm tracing record.

[0074] The above technical solution for determining the IP attack stage and compromise level will be described in the subsequent attack process analysis.

[0075] like Figure 4 As shown, the attack process analysis includes the determination of attack stages and compromise levels:

[0076] Determine the attack stage that the IP is in, specifically including: querying the alarm database according to the IP, obtaining all alarm records experienced by the IP, and then obtaining all alarms related to the IP.

[0077] Extract attack behavior features from all alarm information, and determine the attack stage of each alarm based on the preset correspondence between attack behavior features and attack stages (such as the common attack features in each attack stage mentioned above).

[0078] From the attack stages of all alarms, take the highest attack stage as the current attack stage of the aforementioned queried IP (actually corresponding to the Internet access device on the external network or internal network, the device on the internal network can also be called an asset); the obtained attack stage is included in the alarm tracing record table.

[0079] Furthermore, the compromise level is determined based on the attack stage that the IP is in, including: when it is in the reconnaissance, tracking and payload delivery stage, the compromise level is determined to be low suspicion; when it is in the penetration, utilization and installation and implantation stage, the compromise level is determined to be high suspicion; when it is in the communication control and penetration and destruction stage, the compromise level is determined to be compromised; similarly, the compromise level result is included in the alarm tracing record.

[0080] Furthermore, based on the alarm correlation results, the time series of the alarms is corrected to obtain the attack process, including:

[0081] According to the attack stages determined above, the associated alarms are divided and the alarms in each attack stage are sorted by time to obtain the attack stage sequence of the alarms;

[0082] Based on data such as traffic logs, security logs, and audit logs, obtain the alarm occurrence time, sort the alarms, and obtain the initial time series of the alarms;

[0083] Comparing the attack phase sequence of the alarm with the initial time sequence of the alarm, alarms from different sources will have a certain proportion of false positives, so alarms with inconsistent sequences are removed. Suspicious intranet alarms with low threat levels require further security monitoring to confirm. To avoid false positives affecting business operations, alarms whose attack source is the intranet and are in the reconnaissance, tracking, and payload delivery stages are removed.

[0084] According to the corrected alarm time series, the attack propagation path is obtained, and the IP addresses and vulnerability levels affected by the attack are determined.

[0085] As a preferred implementation, the business scope affected by the attack is determined based on asset information (including asset attributes, vulnerabilities, risks, business status, and operating status; the asset attributes include region, department, and person in charge) and alarm time series.

[0086] Let's take an example to illustrate: After alarm correlation, four alarm events A, B, C, and D are obtained. According to the attack analysis process, A is in the second stage of payload delivery, B and C are in the fourth stage of device installation, and D is in the sixth stage of penetration and destruction. In the fourth stage, B and C are ordered by occurrence time, with B first and C last. Therefore, the attack phase sequence of these four correlated alarms is ABCD. However, according to log data analysis, the initial time sequence of the alarm occurrence is BACD. This shows that the attack phase sequence of A and B is inconsistent with their initial time sequence. Therefore, these two alarms may be false alarms of a security device or system, requiring further determination. This embodiment of the present invention does not address this issue. To avoid taking corresponding measures for false alarms and affecting subsequent services, in this embodiment of the present invention, A and B are excluded. After the above process, it can be determined that the occurrence sequence of the correlated alarms is CD, and the propagation path is C's source IP and destination IP, and D's source IP and destination IP. These IPs are all within the scope of the attack. The vulnerability level of each IP is further determined according to the aforementioned vulnerability level determination method.

[0087] As a preferred implementation method, when making security disposal recommendations, first extract alarms from the alarm library through the asset IP, then traverse all alarms of the asset to find out the type and source distribution of threats, and finally determine the problem locations, including system security, application security, data security, network security, configuration security, equipment security and other security levels. Finally, give reasonable security protection recommendations based on the asset's vulnerability information.

[0088] Those skilled in the art will understand that the steps or components in the above embodiments can be implemented by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc.

[0089] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for tracing the source of a network attack, characterized in that: include: Obtain threat intelligence of a specified type and cache it in the local threat intelligence database; Obtain the current alarm information and the local threat intelligence to determine the attack source of the alarm; According to the device identifiers of the attack source and / or the attack target, alarm correlation is performed to determine the attack stage of the device and the device vulnerability level according to the attack stage; The asset information of the device is obtained, and the time sequence of the alarm is corrected according to the alarm correlation result to obtain the attack process, specifically including: dividing the associated alarms according to the attack stage, sorting the alarms in each attack stage by time, and obtaining the attack stage sequence of the alarms; sorting the alarms according to the alarm occurrence time to obtain the initial time sequence of the alarms; comparing the attack stage sequence of the alarms with the initial time sequence of the alarms, and removing alarms with inconsistent sequences; removing alarms whose attack source is the intranet and is in the reconnaissance, tracking and payload delivery stages; obtaining the attack propagation path based on the corrected alarm time sequence, and determining the IP addresses and vulnerability levels affected by the attack.

2. The traceability analysis method according to claim 1, characterized in that: The alarm association includes: According to the specified conditions, obtain all alarms that are consistent with the source IP or destination IP of this alarm; If the source IP is consistent with the destination IP of this alarm: If the source ports and destination ports of the two alarms are consistent, the two alarms are merged; if the source ports of the two alarms are inconsistent but the destination ports are consistent, the two alarms are considered to be associated alarms; If the destination IP is the same as the source IP of this alarm: When the destination port of another alarm is the same as the source port of this alarm, the two alarms are considered to be related alarms; If the source IP and destination IP are consistent with the source IP and destination IP of this alarm respectively: When the source port and destination port of the two alarms are consistent, the two alarms are merged.

3. The traceability analysis method according to claim 2, characterized in that: Determining the attack stage that the IP is in specifically includes: querying all alarms based on the IP, obtaining all alarm records experienced by the IP, extracting attack behavior characteristics in the alarm information, and determining the attack stage of each alarm based on the preset correspondence between the attack behavior characteristics and the attack stage; taking the highest attack stage in the alarm as the current attack stage of the IP; and listing the attack stage in the alarm tracing record.

4. The traceability analysis method according to claim 3, characterized in that: Determining the compromise level of an IP according to the attack stage the IP is in includes: determining the corresponding relationship between the attack stage and the compromise level, determining the compromise level as low suspicious, high suspicious, or compromised according to the attack stage the IP is in; and including the compromise level in the alarm tracing record.

5. The traceability analysis method according to claim 4, characterized in that: If the attack originates from the intranet based on the alarm source IP, query the initial compromise level of the source IP in the alarm tracing record. If the source IP is found to be highly suspicious or compromised, the alarm is correlated with the destination IP to determine the attack stage of the destination IP and the compromise level of the destination IP based on the attack stage. If the source IP is found to be low-suspicious or no traceability record is found for the source IP, an alarm association is performed based on the source IP and the destination IP to determine the attack stage of the source IP and the destination IP, and the compromise level of the source IP and the destination IP is determined based on the attack stage. Update the compromise levels of the source IP and destination IP to the alarm tracing record.

6. The traceability analysis method according to claim 4, characterized in that: If the source IP of the alarm is used to determine that the attack originated from the external network, Mark the attack source based on the geographic information of local threat intelligence and include the geographic tag in the alarm tracing record; the geographic information includes the correspondence between the domain name, IP address, and country / city information, and the country / city information includes latitude and longitude information; Obtain DNS logs and query the attack source IP or domain name in local threat intelligence. If the attack source is malicious, mark the initial compromise level of the destination IP as highly suspicious or compromised. If the attack source is not malicious, the initial compromise level of the destination IP is marked as low suspicious; Perform alarm correlation based on the target IP, determine the attack stage of the target IP, and determine the target IP vulnerability level based on the attack stage; The compromise level of the destination IP is included in the alarm tracing record.

7. The traceability analysis method according to claim 1, characterized in that: The asset information of the equipment includes the asset's attributes, vulnerability, risk, business status, and operating status; the asset attributes include region, department, and person in charge.

8. The traceability analysis method according to claim 7, characterized in that: The business scope affected by the attack is determined based on the corrected alarm time series and asset information.

Citation Information

Patent Citations

  • Attack path restoration method and apparatus

    CN108696473A

  • APT intrusion detection method based on attack chain attack rule mining

    CN109951419A