Asset identification method, apparatus, device, and computer-readable storage medium
By performing multi-dimensional feature extraction and operating system detection on network alarm information, and combining the aggregation degree analysis of historical attack source addresses, multi-dimensional fingerprint information of attackers is constructed, which solves the problem of low identification accuracy in existing technologies and achieves efficient asset identification of attackers.
Patent Information
- Application Number
- CN202110220048.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-02-26
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2041-02-26
AI Technical Summary
When faced with intelligent attacks, especially when the source IP is constantly changing and the attack speed is slowing down, existing network security technologies have low accuracy in identifying rule-based detection methods and find it difficult to effectively identify the attacker's asset identity.
By performing multi-dimensional information clustering and feature extraction on current network alarm information, combined with operating system detection and identification, the aggregation degree of the current asset feature set and historical attack source addresses is calculated, and multi-dimensional fingerprint information of attackers is constructed to achieve asset identity recognition.
It improves the accuracy of asset identification, enabling accurate identification of assets involved in attacks even when attackers change their IP addresses, thus enhancing network security identification capabilities.
Smart Images

Figure CN114972827B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to an asset identification method and device, equipment and a computer readable storage medium. BACKGROUND
[0002] With the popularity of the Internet of Everything, network security problems are increasingly serious, and the means of network attacks are increasingly diverse and concealed. The current mainstream network security means mainly block or relatively corresponding flow limiting processing of attack source IP by focusing on the threat level of attack events. However, for intelligent attack scenarios such as constantly changing source IP and slowing down attack speed, the current mainstream rule-based detection means has low identification accuracy. SUMMARY
[0003] The embodiments of the present application provide an asset identification method, device, equipment and computer readable storage medium, which can improve the accuracy of asset identification.
[0004] The technical scheme of the embodiments of the present application is implemented as follows:
[0005] The embodiments of the present application provide an asset identification method, comprising:
[0006] obtaining current network alarm information of a current attack event, and performing information clustering and feature extraction of at least one dimension on the current network alarm information to obtain at least one current attack feature;
[0007] performing operating system detection and identification on original flow data corresponding to the current network alarm information to obtain a current attack host system; the current attack host system is an operating system deployed on a current asset initiating the current attack event;
[0008] obtaining a current asset feature set according to the at least one current attack feature and the current attack host system, calculating an aggregation degree of the current asset feature set and at least one preset attack asset feature set, and then realizing identity recognition of the current asset based on the aggregation degree; the at least one preset attack asset feature set is obtained by performing hierarchical clustering of feature dimensions on a historical asset feature set corresponding to a historical attack source address, and is used to represent identity information of at least one attack initiator.
[0009] The embodiments of the present application provide an asset identification device, comprising:
[0010] The feature extraction module is configured to obtain current network alarm information of a current attack event, and perform information clustering and feature extraction of at least one dimension on the current network alarm information to obtain at least one current attack feature;
[0011] An operating system recognition module is configured to perform operating system detection and recognition on the original traffic data corresponding to the current network alarm information, to obtain a current attack host system; the current attack host system is an operating system deployed on a current asset that initiates the current attack event;
[0012] An aggregation recognition module is configured to obtain a current asset feature set according to the at least one current attack feature and the current attack host system, to calculate an aggregation degree of the current asset feature set and at least one preset attack asset feature set, and to further realize identity recognition of the current asset based on the aggregation degree; the at least one preset attack asset feature set is obtained by performing hierarchical clustering of feature dimensions on a historical asset feature set corresponding to a historical attack source address, and is used to represent identity information of at least one attack initiator.
[0013] In the above device, the asset recognition device further includes a feature aggregation module, which is configured to, before calculating the aggregation degree of the current asset feature set and the at least one preset attack asset feature set, obtain at least one historical network alarm information corresponding to at least one historical attack event, each historical network alarm information in the at least one historical network alarm information containing a historical attack source address; perform information clustering and feature extraction of the at least one dimension on each historical alarm information, and perform operating system recognition on historical original traffic data corresponding to each historical alarm information, to obtain an initial historical asset feature set corresponding to each historical alarm information; merge initial historical asset feature sets of the same historical attack source address to obtain at least one historical asset feature set; calculate the similarity between the at least one historical asset feature set in the feature dimension, cluster and merge asset feature sets with a similarity greater than a preset similarity threshold, and take historical asset feature sets in the same cluster as a preset attack asset feature set, to further obtain the at least one preset attack asset feature set.
[0014] In the above device, the current network alarm information is alarm information output by a preset intrusion detection platform according to the attack event, and the at least one current attack feature includes at least one of the following: an attack tool, an attack type, an attack time, and a geographic location.
[0015] In the apparatus, the operating system identification module is further configured to extract data content of at least one preset field from the original traffic data as the operating system correlation data, the at least one preset field including at least one of the following: attack source network address header length, window size, packet survival time, whether fragmentation, maximum message length, TCP option, and user agent information; perform classification and identification on the operating system correlation data by using a preset classification and identification model to obtain the current attack host system; the preset classification and identification model is obtained by performing network training on an initial classification and identification model; and the initial classification and identification model is generated according to a preset correspondence between a preset operating system and preset operating system correlation data.
[0016] In the apparatus, the initial historical asset feature set includes at least one historical attack feature and a historical attack host system, and the feature aggregation module is further configured to: in at least one initial historical asset feature set corresponding to a same historical attack source address, merge at least one historical attack feature in the at least one initial historical asset feature set; and in the at least one initial historical asset feature set, take a historical attack host system with the highest occurrence frequency as a historical attack host system corresponding to the same historical attack source address, to obtain a historical asset feature set corresponding to the same historical attack source address, and further obtain the at least one historical asset feature set.
[0017] In the apparatus, the aggregation identification module is further configured to: calculate an aggregation degree of the current asset feature set and each preset attack asset feature set in the at least one preset attack asset feature set; each preset attack asset feature set corresponds to a preset asset identifier; take a preset attack asset feature set corresponding to an aggregation degree higher than a preset aggregation degree threshold as a target attack asset feature set, and take a preset asset identifier corresponding to the target attack asset feature set as an asset identifier of the current attack source address, to realize asset identification of the current attack source address.
[0018] In the apparatus, the asset identification apparatus further includes an updating module, configured to update the target preset attack asset feature set by using the current asset feature set.
[0019] Embodiments of the present application provide an electronic device, including:
[0020] a memory configured to store executable instructions;
[0021] a processor configured to execute the executable instructions stored in the memory to implement the asset identification method provided in the embodiments of the present application.
[0022] The embodiment of the application provides a computer readable storage medium, which stores executable instructions, and is used for causing a processor to execute the asset identification method provided by the embodiment of the application.
[0023] The embodiment of the application has the following beneficial effects:
[0024] By performing multi-dimensional extraction on current network alarm information and increasing feature recognition of the operating system dimension, the current asset feature set obtained can describe the identity information of the attack initiator of the current attack event from multiple dimensions, thereby guaranteeing the accuracy of asset identity recognition based on the current asset feature set; and by performing hierarchical clustering on the feature dimension of the historical asset feature set corresponding to the historical attack source address, at least one preset asset feature set is obtained, multi-dimensional fingerprint information of the attacker can be constructed, so that in an attack scene with a certain dimension change, such as when an attacker changes an IP for attack, the asset identity of the current attack event can still be identified through the aggregation degree of the overall features, thereby further improving the accuracy of asset identification. BRIEF DESCRIPTION OF DRAWINGS
[0025] Figure 1 is an optional structural schematic diagram of an asset identification system architecture provided by the embodiment of the application;
[0026] Figure 2 is an optional structural schematic diagram of a server provided by the embodiment of the application;
[0027] Figure 3 is an optional flow schematic diagram of an asset identification method provided by the embodiment of the application;
[0028] Figure 4 is an optional content format schematic diagram of Snort alarm information provided by the embodiment of the application;
[0029] Figure 5 is an optional content format schematic diagram of a preset address library provided by the embodiment of the application;
[0030] Figure 6 is an optional flow schematic diagram of an asset identification method provided by the embodiment of the application;
[0031] Figure 7 is an optional flow schematic diagram of an asset identification method provided by the embodiment of the application;
[0032] Figure 8 is an optional flow schematic diagram of an asset identification method provided by the embodiment of the application;
[0033] Figure 9is a system architecture schematic diagram of an asset identification system based on snort passive flow analysis provided by an embodiment of the present application;
[0034] Figure 10 is a basic module schematic diagram of a Snort flow analysis engine provided by an embodiment of the present application;
[0035] Figure 11 is an optional process schematic diagram of generating at least one preset attack asset feature set provided by an embodiment of the present application;
[0036] Figure 12 is a schematic diagram of at least one first historical alarm information corresponding to the source IP of the asset host 1 provided by an embodiment of the present application;
[0037] Figure 13 is a schematic diagram of querying the event id of the first historical attack event from the database of the Snort flow analysis engine provided by an embodiment of the present application;
[0038] Figure 14 is a schematic diagram of the original data flow corresponding to the event id of the first attack event provided by an embodiment of the present application;
[0039] Figure 15 is a schematic diagram of the clustering result of the first historical network alarm information provided by an embodiment of the present application. DETAILED DESCRIPTION
[0040] In order to make the purpose, technical scheme and advantages of the present application clearer, the present application will be described in further detail below with reference to the drawings, and the described embodiments should not be regarded as limiting the present application. All other embodiments obtained by those skilled in the art without making creative efforts fall within the scope of protection of the present application.
[0041] In the following description, “some embodiments” are described, which describe a subset of all possible embodiments, but it can be understood that “some embodiments” can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.
[0042] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0043] In the present application, the relevant data collection and processing should be strictly in accordance with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the personal information subject, and within the scope of authorization of laws and regulations and the personal information subject, carry out subsequent data use and processing.
[0044] Before the embodiments of the present application are further described, the terms and names involved in the embodiments of the present application are explained, and the terms and names involved in the embodiments of the present application are applicable to the following explanations.
[0045] 1) Remote Procedure Call (RPC) attack: RPC is a remote procedure call protocol used by Windows operating system. RPC provides inter-process communication mechanism, allowing seamless execution of code on a remote system for a program running on a computer. Remote attackers can exploit vulnerabilities in the RPC protocol to execute arbitrary instructions on the system with local system privileges, known as RPC attack.
[0046] 2) Snort: Network intrusion detection / prevention system with multi-platform, real-time traffic analysis, network IP packet recording and other features. Snort can capture and analyze packets on the network, respond and process according to defined rules. Snort can analyze traffic for known attacks and obtain traffic characteristics, and then set specific rules based on traffic characteristics. In this way, when traffic data corresponding to attack characteristics is detected, the corresponding alarm information can be generated according to the preset specific rules.
[0047] 3) Nmap: Network connection port scanning software used to scan the network connection ports opened by computer devices in the network, determine which services run on which connection ports, and infer the operating system running on the computer device.
[0048] 4) masscan: Fast Internet port scanner.
[0049] Currently, common asset identification technologies mainly include the following: 1. Identifying the operating system category through the TCP / IP information of passive traffic. Method 1 mainly extracts the window size, time to live and other characteristic information from the TCP / IP packet header, compares them with the pre-established operating system characteristic classification, and identifies the operating system category of the host, such as windows or linux and the like. This method is mainly used to filter false positives from the alarm information of the intrusion detection system by identifying the operating system type. For example, the linux system will not be attacked by RPC, so the RPC attack associated with the linux system in the alarm information can be confirmed as a false positive. 2. Detecting asset information through active scanning. Method 2 can use network asset detection tools such as Nmap and masscan to send SYN packets or other data packets to the target asset, and then compare the characteristics of the response packets returned by the target asset with the existing characteristic information to obtain asset information such as the survival of the target system, port openness, port service and operating system. 3. Collecting asset information through non-intrusive detection of search engines. Method 3 mainly uses search engines such as fofa, Shodan and ZoomEye to query asset information in the existing asset library by searching for known characteristics of the asset.
[0050] For the above method 1, due to the wide variety of operating systems used by the detection target, the characteristic dimensions extracted from the TCP / IP traffic data are usually less, and the operating system types classified are relatively simple, so the accuracy of asset identification is not high. For the above method 2, because the active scanning software has a strong packet sending feature and the number of packets sent is too large, such scanning often triggers the security alarm strategy of the security protection device of the scanned asset, and is then blocked; and the scanning of port services and operating systems has a time effectiveness, and is also easily affected by network fluctuations, thereby reducing the accuracy of asset identification. For the above method 3, it mainly relies on the large data asset library of the third-party search engine, but the information of the search engine usually has a time effectiveness, such as domain name invalidation or port closure and the like, thereby reducing the accuracy of asset identification.
[0051] The embodiments of the present application provide an asset identification method, device, equipment and computer readable storage medium, which can improve the accuracy of asset identification. The following describes an exemplary application of the electronic device provided by the embodiments of the present application. The device provided by the embodiments of the present application can be implemented as a router, a switch, a service gateway or other operator equipment or a network security device, and a smart home gateway or other network node device; or as a server. The following describes an exemplary application when the device is implemented as a server.
[0052] Referring to Figure 1 , Figure 1 is an optional architecture diagram of the asset identification system 100 provided by the embodiments of the present application. The terminals 600 (exemplarily shown as terminal 600-1 to terminal 600n) are assets in the network 300. The terminals 600 can be various types of user terminals such as notebook computers, tablet computers, desktop computers, set-top boxes, mobile devices (e.g., mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable game devices), etc. The network nodes 400 (exemplarily shown as network node 400-1 and network node 400-2) can be network nodes with more traffic aggregation in the network, such as core gateways. The network 300 can be a wide area network or a local area network, or a combination of both. The server 200 can be deployed in the network 300 and connected with the terminals 400 through the network 300, or deployed outside the network 300 and connected with the terminals 400 through other networks. Figure 1 An example in which the server 200 is deployed outside the network 300 is shown.
[0053] The network node 400 is configured with a traffic collection module and a traffic analysis engine, which are used to collect traffic data in the network 300 in real time, analyze the real-time collected traffic data through the traffic analysis engine, output a network alarm log containing an attack event, and send the network alarm log to the server 200. The server 200 is used to merge at least one network alarm log sent by the network node 400, obtain current network alarm information of a current attack event in at least one attack event contained in the merged network alarm log, and perform information clustering and feature extraction of at least one dimension on the current network alarm information to obtain at least one current attack feature; performing operating system detection and identification on the original traffic data corresponding to the current network alarm information to obtain a current attack host system; obtaining a current asset feature set according to the at least one current attack feature and the current attack host system, calculating the aggregation degree of the current asset feature set and at least one preset attack asset feature set, and then identifying the asset source of the current attack event based on the aggregation degree; the at least one preset attack asset feature set is obtained by performing hierarchical clustering on the feature dimension of a historical asset feature set corresponding to a historical attack source address, and is used to represent the identity information of at least one attack initiator. The server can determine the corresponding target terminal from the terminal 600-1 to the terminal 600-n according to the source IP or source port number in the current alarm information, identify the identity information of the attack initiator as the identity information of the target terminal, and mark the identity information of the target terminal. The server 200 can process each attack event in the at least one attack event in the same way to identify the asset identity of each attack event, so as to mark the identity of the corresponding target terminal in the terminal 600-1 to the terminal 600-n. Further, in some embodiments, the server can also update the corresponding preset attack asset feature set in the database 500 using the current asset feature set, so that the preset attack asset feature set can be continuously updated with the latest traffic features in the network 300.
[0054] In some embodiments, the server 200 can be a standalone physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDNs, and basic cloud computing services such as big data and artificial intelligence platforms. The terminal 400 can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal and the server can be connected directly or indirectly through wired or wireless communication, which is not limited in the embodiments of the present application.
[0055] Referring to Figure 2 , Figure 2Fig. 1 is a schematic diagram of a server 200 according to an embodiment of the present application, Figure 2 The server 200 shown includes at least one processor 410, a memory 450, at least one network interface 420, and a user interface 430. The various components of the server 200 are coupled together by a bus system 440, which is configured to facilitate the communication of information between each of the components. The bus system 440 can be implemented with one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus. In one embodiment, the various buses are constructed using both proprietary and open standards. Figure 2 The various buses are represented collectively as the bus system 440 for clarity.
[0056] The processor 410 can be an integrated circuit chip with signal processing capabilities, such as a general purpose processor, a Digital Signal Processor (DSP), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or the like. The general purpose processor can be a microprocessor, or any conventional processor, etc.
[0057] The user interface 430 includes one or more output devices 431 that enable presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 430 also includes one or more input devices 432 that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.
[0058] The memory 450 can be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard drives, optical drives, and the like. The memory 450 optionally includes one or more storage devices remotely located from the processor 410 in physical location.
[0059] The memory 450 includes volatile memory or non-volatile memory, or both. Non-volatile memory can be read only memory (ROM), volatile memory can be random access memory (RAM). The memory 450 described herein is intended to include any suitable type of memory.
[0060] In some embodiments, the memory 450 is capable of storing data to support various operations, examples of which include programs, modules, and data structures or subsets or superset thereof, which are described illustratively below.
[0061] The operating system 451 includes system programs for processing various basic system services and performing hardware-related tasks, such as a framework layer, a core library layer, a driver layer, and the like, for implementing various basic services and processing hardware-based tasks;
[0062] The network communication module 452 is configured to communicate with other computing devices via one or more (wired or wireless) network interfaces 420, exemplary network interfaces 420 including Bluetooth, wireless fidelity (WiFi), and universal serial bus (USB), and the like;
[0063] The presentation module 453 is configured to enable presentation of information via one or more output devices 431 (e.g., a display screen, a speaker, and the like) associated with the user interface 430 (e.g., a user interface for operating peripheral devices and displaying content and information);
[0064] The input processing module 454 is configured to detect and interpret one or more user inputs or interactions from one or more input devices 432.
[0065] In some embodiments, the apparatus provided by the embodiments of the present application can be implemented in software, Figure 2 An asset identification apparatus 455 stored in the memory 450 is shown, which can be in the form of software such as programs and plug-ins, including the following software modules: a feature extraction module 4551, an operating system identification module 4552, and an aggregation identification module 4553. These modules are logical, and thus can be combined or further split according to the implemented functions.
[0066] The functions of the various modules will be described below.
[0067] In some embodiments, the apparatus provided by the embodiments of the present application can be implemented in software, As an example, the apparatus provided by the embodiments of the present application can be a processor in the form of a hardware decoding processor programmed to perform the asset identification method provided by the embodiments of the present application. For example, the processor in the form of a hardware decoding processor can be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), or other electronic elements.
[0068] In some embodiments, the feature extraction module 4551 and the operating system identification module 4552 can also be deployed on the network node 400 to extract at least one current attack feature from the current network alarm information and identify the current attack host system, obtain a current asset feature set, and then send the current asset feature set to the server 200 through the terminal 400 for calculation of the aggregation degree and asset identification on the server 200. The specific selection is based on the actual situation, and the embodiments of the present application are not limited. Figure 1
[0069] In some embodiments, the server 200 can perform hierarchical clustering of the feature dimension of the historical asset feature set corresponding to the historical attack source address before accessing the network 300, realize offline modeling of at least one preset attack asset feature set, and then access the network 300 after obtaining the at least one preset attack asset feature set. Real-time modeling of the at least one preset attack asset feature set can also be performed after accessing the network 300. The specific selection is based on the actual situation, and the embodiments of the present application are not limited.
[0070] In some embodiments, the asset identification method or device disclosed in the present application can be composed of a block chain through a plurality of servers, and the server is a node on the block chain.
[0071] The exemplary application and implementation of the server provided by the embodiments of the present application will be described in the asset identification method provided by the embodiments of the present application.
[0072] Referring to Figure 3 , Figure 3 is an optional flowchart of the asset identification method provided by the embodiments of the present application, which will be described in combination with the steps shown in Figure 3 .
[0073] S101, obtain current network alarm information of a current attack event, and perform information clustering and feature extraction of at least one dimension on the current network alarm information to obtain at least one current attack feature.
[0074] The method of the embodiments of the present application can be applied to asset inspection scenarios of a local area network. The local area network can be a network segment of a company or other organization, or the entire network, i.e., asset inspection of the entire network. Asset inspection is to mark assets at various levels through the traffic characteristics of the assets, such as botnets, black production, system types, and open services, taking IP or domain name as an identifier. Asset inspection can actively build the characteristics of attackers, rather than waiting for serious attack behavior to occur for prevention.
[0075] In the embodiments of the present application, the server can obtain log files from various network devices, security devices, and key hosts distributed in the network, such as IDS alerts, firewall access logs, access logs of subordinate servers, scan result reports of vulnerability scanners, and the like. The server can preprocess and analyze the collected logs, locate attack-type events from the logs according to event types recorded in the logs, and take the corresponding event content of the current attack event in the logs as the current network alert information.
[0076] In some embodiments, the current network alert information is preset intrusion detection platform, such as the alert information output by the intrusion detection system Snort system according to the attack event. Exemplarily, the Snort alert information can include a Package and an Event, as shown in the following table: Figure 4 The Package mainly shows the brief content of the attack packet, and the Event mainly records the parameter information related to the alert. The Snort alert information can include the following information fields: alert time (event second / packet second), attack feature number (sig id), attack type (classification), alert priority (priority), protocol (protocol), source IP address (ip source), source port (src port), destination IP address (ip destination), and destination port (dest port). The server can take the content of the above information fields corresponding to the current attack event in the alert log as the current network alert information. Alternatively, the intrusion detection system can also be other types of intrusion detection systems or firewalls, and the like, and the specific type is determined according to the actual situation, which is not limited in the embodiments of the present application.
[0077] In some embodiments, the current alert information can include at least one alert description sentence for describing at least one attack behavior corresponding to the current attack event. The server can remove duplicates from the at least one alert description sentence, remove numbers and special symbols, and establish a mapping from words to numbers, so as to map the alert description sentence to a multi-dimensional vector, and obtain at least one multi-dimensional vector. The server can cluster the at least one multi-dimensional vector from at least one dimension, and obtain a vector cluster corresponding to each dimension. The server can extract a feature corresponding to the clustering dimension from each vector cluster, as a current attack feature corresponding to the vector cluster, thereby obtaining at least one current attack feature. Alternatively, the server can also extract an initial feature from the vector cluster, and perform further information mining and analysis based on the initial feature, thereby obtaining at least one current attack feature.
[0078] In the embodiments of the present application, the at least one dimension can be information represented by an information field in the current alarm information, which has a higher correlation with the attack behavior and can be used to reflect the characteristics of the attack behavior. In some embodiments, the at least one current attack feature extracted according to the at least one dimension includes at least one of the following: attack tool, attack type, attack time and geographic location. Exemplarily, for the Snort alarm log, the server can take the attack alarm time, attack feature number, attack type and source IP address as the at least one dimension, cluster the current alarm information, obtain information class clusters corresponding to the attack alarm time, attack feature number, attack name, attack type and source IP address respectively, and then extract features from the information class cluster corresponding to the attack alarm time to obtain the attack time in the at least one current attack feature; extract features from the information class cluster corresponding to the attack type to obtain the attack type in the at least one current attack feature, and then obtain the attack tool corresponding to the attack type according to the preset correspondence between the attack type and the attack tool; and extract features from the information class cluster corresponding to the source IP address to obtain the attack source address feature, and use the attack source address feature to query the preset address library to obtain the geographic location in the at least one current attack feature.
[0079] In some embodiments, the content format of the preset address library can be as shown in Figure 5 , containing at least one line of IP data information, each line of IP data information being composed of an IP segment and data, including: address start IP, address end IP, country, region, province, city and operator.
[0080] In some embodiments, the server can also perform information clustering and feature extraction on the current network alarm information according to the dimensions of the original information content in the current network alarm information corresponding to other firewalls or intrusion detection systems, to obtain at least one current attack feature. The specific selection is made according to actual conditions, which is not limited in the embodiments of the present application.
[0081] S102, performing operating system detection and identification on the original traffic data corresponding to the current network alarm information to obtain a current attack host system; the current attack host system is an operating system deployed on a current asset initiating the current attack event.
[0082] In the embodiments of the present application, the identification of the operating system mainly depends on the original traffic. The server can obtain the original traffic data corresponding to the current network alarm information, perform operating system detection and identification according to the field content with operating system features in the original traffic data, identify the operating system running on the host initiating the current attack event as the current attack host system.
[0083] In some embodiments, the Snort intrusion detection system records the original traffic data triggering the alarm as a file in a specific format when performing intrusion detection and generating an alarm log. Through the source IP, source port information in the current network alarm information, as well as the destination IP, port protocol and alarm time, the original traffic data corresponding to the current network alarm information can be found in the file.
[0084] In the embodiments of the present application, the operating system features in the original traffic mainly exist in the header of the data packet and part of the application layer data packet. In some embodiments, S102 can be implemented by S1021-S1022, which will be described in combination with each step.
[0085] S1021, from the original traffic data, extracts the data content of at least one preset field as operating system associated data, the at least one preset field including at least one of the following: attack source network address header length, window size, data packet survival time, whether fragmented, maximum message length, TCP option, user agent information.
[0086] In the embodiments of the present application, the server can extract the operating system associated data from the data content of at least one of the following preset fields in the original traffic data: total length (LEN) of the IP header, window size (WIN), data packet survival time (TTL), whether fragmented (DF), maximum message length (MSS), TCP option (OPT), and user agent information (User-Agent, UA). At least one of the preset fields can also include other fields according to actual application or network data packet format, which is selected according to actual situation, and the embodiments of the present application are not limited.
[0087] In some embodiments, the correspondence between the above operating system associated data and the preset operating system classification can be as shown in Table 1 and Table 2.
[0088] WIN TTL DF MSS OPT Operating System 32736 64 0 1414 M Linux 2.0 5792 64 1 1460 MSTNW Linux 2.6 8192 128 1 1460 MNWST Windows 7 32768 64 1 1460 MNWNNTSNN NETB SD 4.0.1 33304 64 1 1460 MNWNNT MACOS 10.3
[0089] Table 1
[0090] UA Operating System Windows NT 5.1 Windows XP Windows NT 6.0 Windows Server 2008 Windows NT 10.0 Windows 10 Linux Linux
[0091] Table 2
[0092] In the embodiments of the present application, the server can extract the operating system associated data from the original traffic data, determine the operating system corresponding to the operating system associated data based on Table 1 and Table 2, and take the operating system as the current attack host system.
[0093] S1022, the operation system associated data is classified and identified by the preset classification identification model, and a current attack host system is obtained; the preset classification identification model is obtained by network training of an initial decision tree; and the initial decision tree is generated according to a preset corresponding relationship between a preset operation system and preset operation system associated data.
[0094] In the embodiment of the application, the server can extract the association relationship data between the traffic data features and the operation system types in advance by a known operation system or a third-party tool with a fingerprint library, and then can generate an initial decision tree as an initial classification identification model by taking the association relationship data as a feature dimension. The initial decision tree is trained by a large amount of training data to obtain a preset classification identification model that can identify the operation system.
[0095] In this way, the server can identify the operation system of the operation system associated data extracted in real time by using the trained preset classification identification model, and infer the operation system type corresponding to the operation system associated data as the current attack host system.
[0096] S103, a current asset feature set is obtained according to at least one current attack feature and the current attack host system, the aggregation degree of the current asset feature set and at least one preset attack asset feature set is calculated, and then the identity of the asset of the current attack event is identified based on the aggregation degree; the at least one preset attack asset feature set is obtained by hierarchical clustering of feature dimensions of a historical asset feature set corresponding to a historical attack source address, and is used to represent the identity information of at least one attack initiator.
[0097] In the embodiment of the application, the server can combine at least one current attack feature and the current attack host system, that is, add an operation system dimension in at least one dimension to obtain a current asset feature set, or the server can also combine at least one current attack feature, the current attack host system and feature data of other dimensions to obtain a current asset feature set. The selection is made according to actual conditions, and the embodiment of the application is not limited.
[0098] In the embodiments of the present application, the server can pre-acquire at least one historical network alarm information corresponding to at least one historical attack event in the network, perform information clustering and feature extraction on each historical network alarm information in the at least one historical network alarm information in the same process, and perform operating system detection and identification on the original traffic data corresponding to each historical network alarm information to obtain at least one historical asset feature set corresponding to the at least one historical network alarm information. The at least one historical asset feature set corresponds to historical attack events from different historical attack source addresses, and each historical attack source address can represent an attack asset of an attacker in the network. In order to obtain the asset range of the attacker, that is, multiple source IP addresses, commonly used attack tools, the geographical location range corresponding to the IP, etc., the server can perform hierarchical clustering on the at least one historical asset feature set from the feature dimension, thereby removing the IP difference of the at least one historical asset feature set and aggregating all dimension attack features to describe the portrait of the attacker to obtain at least one preset attack asset feature set.
[0099] In the embodiments of the present application, each preset attack asset set in the at least one preset attack asset feature set can contain one or more historical asset feature sets, and each preset attack asset set can be used to represent the characteristics of an attacker, that is, the identity information of the attack initiator, so that the identity information of at least one attack initiator can be represented through the at least one preset attack asset feature set.
[0100] In some embodiments, each preset attack asset set can be associated with a corresponding preset identity identifier according to the characteristics presented by different attack feature clusters, such as botnets, black production, system types, open services, etc. The server can calculate the aggregation degree between the current asset feature set and each preset attack asset feature set in the at least one preset attack asset feature set, and then take the preset attack asset feature set with an aggregation degree greater than a preset aggregation degree threshold as a target preset attack asset feature set, take the preset identity identifier corresponding to the target preset attack asset feature set as a target identity identifier, and associate and mark the host identifier information such as the source IP address or the source port address in the current network alarm information corresponding to the current asset feature set, thereby realizing the identification of the asset identity of the current attack event.
[0101] In the embodiments of the present application, hierarchical clustering is to calculate the similarity between feature vectors, that is, the aggregation degree, and the part with an aggregation degree greater than the preset aggregation degree threshold can be aggregated. The server can use hierarchical clustering to model at least one preset attack asset feature set by using labeled experimental data, such as at least one historical asset feature set with preset identity annotation information, and performing feature dimension clustering and merging on the historical asset feature set with an initial aggregation degree greater than the initial aggregation degree threshold. The server can determine whether the initial aggregation degree threshold setting is reasonable by analyzing whether the identity annotation information of the historical asset feature set contained in each preset attack asset feature set in the at least one preset attack asset feature set is consistent, and obtain the preset aggregation degree threshold by adjusting or confirming the initial aggregation degree threshold.
[0102] In this way, when the aggregation degree of the current asset feature set and the preset attack asset feature set is greater than the preset aggregation degree threshold, it indicates that the current asset feature set can be aggregated with the preset attack asset feature set, and belongs to the attack feature range of the same attacker, and the preset identity corresponding to the preset attack asset feature set can be used as the identity information corresponding to the current asset feature set, that is, the asset identity corresponding to the current attack event.
[0103] It can be understood that in the embodiments of the present application, the current asset feature set obtained by extracting the current network alarm information in multiple dimensions and increasing the feature recognition of the operating system dimension can describe the identity information of the attack initiator of the current attack event from multiple dimensions, ensuring the accuracy of subsequent asset identity recognition based on the current asset feature set; and at least one preset asset feature set can be obtained by performing hierarchical clustering on the feature dimension of the historical asset feature set corresponding to the historical attack source address, the multi-dimensional fingerprint information of the attacker can be constructed, so that in the attack scene with certain dimension changes, such as IP replacement attack by the same attacker, the asset identity of the current attack event can still be identified through the aggregation degree of the overall feature, thereby further improving the accuracy of asset identification.
[0104] In some embodiments, referring to Figure 6 , Figure 6 is an optional flowchart of the asset identification method provided by the embodiments of the present application, based on Figure 3 Before S103 of "calculating the aggregation degree of the current asset feature set and the at least one preset attack asset feature set", S001-S004 can also be performed, which will be described in combination with each step.
[0105] S001, obtaining at least one historical network alarm information corresponding to at least one historical attack event, each historical network alarm information in the at least one historical network alarm information containing a historical attack source address.
[0106] In the embodiments of the present application, the server can obtain at least one historical network alarm information corresponding to at least one historical attack event, wherein each historical network alarm information contains a historical attack source address, and the historical attack source addresses in each historical network alarm information can be the same or different.
[0107] S002, information clustering and feature extraction of at least one dimension are performed on each historical alarm information, and operating system recognition is performed on the historical original traffic data corresponding to each historical alarm information, to obtain an initial historical asset feature set corresponding to each historical alarm information.
[0108] In the embodiments of the present application, the server can perform information clustering and feature extraction of at least one dimension on each historical alarm information to obtain at least one historical attack feature corresponding to each historical alarm information. Here, the process of performing information clustering and feature extraction of at least one dimension on each historical alarm information by the server is consistent with that described in S101, and will not be repeated here.
[0109] In the embodiments of the present application, for a historical attack source address contained in a historical alarm information, the server can divide a time window according to the number of traffic of the same historical attack source address in a certain time period, for example, 100, and extract all traffic data of the same historical attack source address in the time window as the historical original traffic data corresponding to the historical alarm information, to further obtain the historical original traffic data corresponding to each historical alarm information. The server performs operating system recognition on the historical original traffic data corresponding to each historical alarm information to obtain a historical attack host system corresponding to each historical alarm information. Here, the process of performing operating system recognition on the historical original traffic data corresponding to each historical alarm information by the server is consistent with that described in S102, and will not be repeated here.
[0110] In the embodiments of the present application, the server takes at least one historical attack feature and a historical host attack system corresponding to each historical alarm information as an initial historical asset feature set corresponding to each historical alarm information.
[0111] S003, merging the initial historical asset feature sets of the same historical attack source address to obtain at least one historical asset feature set.
[0112] In the embodiments of the present application, the public IP can be a unique identifier representing an asset in the network space, and the server can merge the initial historical asset feature sets corresponding to the same historical source address in IP units, to prevent complex clustering results formed by directly clustering in a large range in all dimensions, and to avoid leading to an attacker portrait with obvious boundaries.
[0113] In some embodiments, S003 can be implemented by performing S003-1 to S003-2, which will be described in conjunction with the respective steps.
[0114] S003-1, in at least one initial historical asset feature set corresponding to the same historical attack source address, at least one historical attack feature in at least one initial historical asset feature set is merged.
[0115] In the embodiments of the present application, different historical alarm information in at least one historical alarm information may contain the same historical attack source address. The server can merge at least one initial historical attack feature contained in at least one initial historical asset feature set corresponding to the same historical attack source address in at least one historical alarm information containing the same historical attack source address, and can obtain at least one historical attack feature corresponding to each historical attack source address. Here, at least one historical attack feature, the historical attack feature in different initial historical asset feature sets corresponding to the same historical attack source address can coexist in multiple values.
[0116] S003-2, in at least one initial historical asset feature set, the most frequently occurring historical attack host system is taken as the historical attack host system corresponding to the same historical attack source address, thereby obtaining the historical asset feature set corresponding to the same historical attack source address, and further obtaining at least one historical asset feature set.
[0117] The present application has two implementations. If there is a difference between at least one historical attack host system contained in at least one initial historical asset feature set corresponding to the same historical attack source address, the historical attack host system with the highest frequency is taken as the final operating system type. The server can merge all historical attack features after merging and the final historical attack host system after merging as the historical asset feature set corresponding to the historical attack source address, and perform information merging on at least one initial historical asset feature set corresponding to at least one historical alarm information in units of IP, and further obtain at least one historical asset feature set, wherein each historical asset feature set corresponds to a unique historical attack source address.
[0118] S004, calculate the similarity between at least one historical asset feature set in the feature dimension, cluster and merge the asset feature sets with a similarity greater than a preset similarity threshold, and take the historical asset feature sets under the same cluster as a preset attack asset feature set, and further obtain at least one preset attack asset feature set.
[0119] In the embodiments of the present application, the server can ignore the IP difference of the at least one historical asset set, take the feature dimension as the clustering condition, and perform hierarchical clustering on the at least one historical asset feature set, so that the feature vectors in the historical asset feature sets with similar degrees, such as the historical asset feature sets with aggregation degrees higher than a preset aggregation degree threshold, in the at least one historical asset feature set can be aggregated to obtain a preset attack asset feature set for representing the characteristics of an attacker, i.e., the identity information. The server can obtain at least one preset attack asset feature set by clustering the at least one historical asset feature set. It can be understood that the number of the at least one preset attack asset feature set is less than or equal to the number of the at least one historical asset feature set.
[0120] It can be understood that, in the embodiments of the present application, the historical asset feature set is obtained through the historical alarm information, and the historical asset feature sets corresponding to different historical attack source addresses are clustered in the feature dimension according to the aggregation degree, so as to remove the IP difference between different historical asset feature sets, mine the correlation between different attack events, and further construct more rich features of the attacker in multiple dimensions as the preset attack asset feature set. In this way, even if the current asset corresponding to the current asset feature set does not currently exhibit serious attack behavior, it can be determined whether it is an attack asset of the same attacker by comparing the aggregation degree with the preset attack asset feature set, and the future use of the attacker can be prevented instead of having to wait for serious attack behavior to occur.
[0121] In some embodiments, referring to Figure 7 , Figure 7 is an optional flowchart of the asset identification method provided by the embodiments of the present application, Figure 3 S103 shown in the figure can be implemented by S1031 to S1032, which will be described in combination with each step.
[0122] S1031, calculate the aggregation degree of the current asset feature set and each preset attack asset feature set in the at least one preset attack asset feature set; each preset attack asset feature set corresponds to a preset asset identifier.
[0123] In the embodiments of the present application, each preset attack asset feature set corresponds to a preset asset identifier, which is used to identify the corresponding asset identity information. The server can calculate the aggregation degree of the current asset feature set and each preset attack asset feature set in the at least one preset attack asset feature set, and then identify the identity of the current asset based on the aggregation degree and the preset asset identifier.
[0124] S1032, the preset attack asset feature set corresponding to the aggregation degree higher than the preset aggregation degree threshold is taken as a target attack asset feature set, and the preset asset identifier corresponding to the target attack asset feature set is taken as an asset identifier of the current attack source address, so as to realize asset identification of the current attack source address.
[0125] In the embodiment of the application, when the aggregation degree is higher than the preset aggregation degree threshold, it indicates that the similarity of the current asset feature set and the corresponding preset attack asset feature set in the feature dimension is high, and the possibility of belonging to the same attacker is large. The server takes the preset attack asset feature set corresponding to the aggregation degree higher than the preset aggregation degree threshold as the target attack asset feature set, and then takes the preset asset identifier corresponding to the target attack asset feature set as the asset identifier of the current attack source address, so as to realize asset identification of the current attack source address.
[0126] It should be noted that in the embodiment of the application, the preset aggregation degree threshold can be a value equal to the preset similarity threshold, or can be other values according to actual needs. The specific selection is made according to actual conditions, and the embodiment of the application is not limited.
[0127] In some embodiments, referring to Figure 8 , Figure 8 is an optional flow diagram of the asset identification method provided by the embodiment of the application, Figure 7 After S1032 shown in the embodiment of the application, S104 can also be performed, which will be described in combination with each step.
[0128] S104, using the current asset feature set, updating the target preset attack asset feature set.
[0129] In the embodiment of the application, since the current asset feature set represents the latest features of the attack event initiated by the same attacker, the server can use the current asset feature set to update the target preset attack asset feature set through feature merging or hierarchical clustering, so that the target preset attack asset feature set can be updated in real time according to the latest features of the attacker.
[0130] It can be understood that in the embodiment of the application, the server can update the preset asset features in real time according to the activity degree of the asset in the network, further enrich and perfect the preset asset feature information, and improve the accuracy of asset identification.
[0131] In the following, an exemplary application of the embodiment of the application in an actual application scenario will be described.
[0132] The embodiment of the application provides an asset identification system based on snort passive flow analysis, and the overall system architecture diagram can be as shown in Figure 9The flow collection probe in the flow collection device and the network security device can be any device that can mirror and store flow, for collecting and storing flow data of the network core gateway. Alternatively, any open source or purchased software or device that can mirror flow can be used as a flow collection device to collect flow in the network in real time. Since there is no strong correlation between the amount and time of flow data, the flow collection device can quantitatively create a new flow file and store it. For example, when the new flow file reaches 5G, it is forwarded to a host for passive flow analysis for further processing. In the embodiments of the present application, the passive flow analysis host can be distributedly deployed, and the flow data is sent to different passive flow analysis hosts for processing in a distributed manner, and each passive flow analysis host is deployed with the same processing module, such as a Snort flow analysis engine, a feature extraction module, and an operating system recognition module, while the final feature recognition module must be deployed on a host.
[0133] Figure 9 The Snort flow analysis engine is a module that can analyze flow data and generate an alarm log containing part of the dimension information of the asset. Figure 10 is a schematic diagram of the basic module of the Snort flow analysis engine. The flow data is decoded by the decoder, and then various plug-ins in the preprocessor perform packet splicing and encoding operations, and then input to the detection engine for alarm pattern matching. If the matching is successful, an alarm log is generated through the output plug-in, and if the matching fails, it means that the current flow data is a normal packet. The normal packet is discarded, so that the Snort flow analysis engine can filter the corresponding information of the attack event from the flow data.
[0134] Figure 9 The feature extraction module is a secondary processing of the alarm log, including clustering and feature dimension information extraction functions. In the embodiments of the present application, the alarm content generated by an attack event in a certain behavior step often has high similarity. If the alarm content of the same IP is extracted, it is difficult, so the alarm content needs to be clustered first, and then the effective alarm information is extracted to obtain the attack features of the flow data.
[0135] Figure 9 The operating system recognition module analyzes the operating system correlation field of multiple dimensions in the original flow data through a neural network model, such as a multi-target classification recognition model, to identify the operating system type of the asset corresponding to the flow data.
[0136] After the process as above, the feature aggregation module can obtain the asset feature set in IP units, including attack time, geographic location, attack type, attack tool, operating system type and other information. The feature aggregation module first associates and aggregates all collected asset feature sets in IP units to form a unique feature vector set in IP units, and then removes the IP dimension and regards all other feature dimensions as equally important dimensions. The similarity or aggregation degree of different feature vector sets in other feature dimensions is calculated, the attack information features are aggregated, and at least one preset attack asset feature set is obtained. In this way, when new traffic data arrives, it can be determined whether it is the asset of the same attacker by the aggregation degree between the new traffic data and the at least one preset attack asset feature set.
[0137] In some embodiments, based on Figure 9 With Figure 10 At least one preset attack asset feature set can be generated through a process as shown in Figure 11 , including the following stages: obtaining alerts to be clustered, alert quantification, clustering threshold selection and outputting clustering results. In the stage of obtaining alerts to be clustered, the alarm log output by the Snort traffic analysis engine for a plurality of historical attack events can be obtained first. Exemplarily, for the first historical attack event initiated by the asset host 1 in the network using the NMAP tool to perform port service and operating system scanning on an XP host through a Windows host, the alarm log can contain the first historical network alarm information corresponding to the first historical attack event, and can also contain other historical network alarm information corresponding to other historical attack events of other asset hosts in the network. The feature extraction module can take the source IP or destination IP as a filtering condition to count and filter all historical network alarm information in the alarm log to obtain a historical alarm information list, which contains at least one historical alarm information corresponding to each IP address in the filtering condition. At least one first historical alarm information corresponding to the source IP of the asset host 1 can be as shown in Figure 12 , wherein the first column is the attack type and the second column is the attack frequency. For the first historical network alarm information corresponding to the first historical attack event, the feature extraction module can extract the attack type "ET SCAN NMAP OSDetection Probe" according to Figure 12 , and then query the eventid of the first historical attack event from the database of the Snort traffic analysis engine in combination with the attack type and the estimated attack time range, as shown in Figure 13As shown, the cid obtained by the SQL statement query is the event id. The feature extraction module further queries the detailed alarm content of the first attack event, such as the associated raw data flow, attack time, attack type and the like, from the database of the Snort flow analysis engine through the event id, as the first historical network alarm information. As shown, the raw data flow corresponding to the event id of the first attack event can be obtained. Figure 14 The feature extraction module can obtain the corresponding historical network alarm information of each attack event of each source IP by performing the same processing on each attack type corresponding to each source IP, and use the obtained historical network alarm information as the clustering alarm.
[0138] In the alarm quantification stage, the feature extraction module can cluster each historical network alarm information. As an example, in at least one alarm statement contained in the first historical network alarm information, all alarm-containing words are counted, and are de-duplicated, and numbers and special symbols are removed, and a word-to-number mapping is established, which can map each alarm statement into a vector, and all vectors are clustered to obtain the clustering result of the first historical network alarm information as shown in Figure 15 The feature extraction module extracts features from each clustering result in Figure 15 and obtains at least one first historical attack feature of attack time, geographical location, attack type and attack tool. At the same time, the operating system recognition module can use a preset classification recognition model to recognize the field content of at least one preset field extracted from the raw data flow corresponding to the first attack event, to obtain the first historical attack host system corresponding to the asset host 1, and then combine the at least one first historical attack feature and the first historical attack host system to obtain the first historical attack feature set corresponding to the first attack event. The feature extraction module and the operating system recognition module perform clustering feature extraction and operating system recognition on each historical alarm information in the clustering alarm to obtain an initial historical asset feature set corresponding to each historical alarm information.
[0139] In the clustering threshold selection stage, the feature aggregation module can merge the historical asset feature sets of the same source IP in the plurality of initial historical asset feature sets corresponding to the plurality of historical alarm information to obtain at least one historical asset feature set, and then calculate the similarity between the at least one historical asset feature set, and cluster and merge the historical asset feature sets with a similarity greater than a preset similarity threshold in the feature dimension to obtain at least one preset attack asset feature set.
[0140] It can be understood that the embodiments of the present application can collect traffic data in the network, process based on Snort rules and original traffic analysis, obtain the asset feature information of the attacker, and more accurately and quickly identify the asset. Compared with the existing asset identification method, the feature dimension of the operating system identification is increased, and the intelligent model is used for classification, which is more intelligent and fast; and no data packet needs to be actively sent, so that the network business is not affected, and the false alarm of the intrusion detection system of the asset to be identified is not easy; and the related information of the preset attack asset feature set can be updated in real time according to the activity degree of the asset in the network, so that the information of the preset attack asset feature set will be more abundant with the accumulation of time.
[0141] The following continues to illustrate an exemplary structure of the implementation of the asset identification apparatus 455 provided by the embodiments of the present application as a software module. In some embodiments, as shown in FIG. 4, the software module stored in the asset identification apparatus 455 of the memory 450 can include: Figure 2
[0142] The feature extraction module 4551 is configured to obtain the current network alarm information of the current attack event, and perform information clustering and feature extraction of at least one dimension on the current network alarm information to obtain at least one current attack feature.
[0143] The operating system identification module 4552 is configured to perform operating system detection and identification on the original traffic data corresponding to the current network alarm information to obtain a current attack host system; the current attack host system is an operating system deployed on a current asset initiating the current attack event.
[0144] The aggregation identification module 4553 is configured to obtain a current asset feature set according to the at least one current attack feature and the current attack host system, calculate the aggregation degree of the current asset feature set and at least one preset attack asset feature set, and then realize the identity recognition of the current asset based on the aggregation degree; the at least one preset attack asset feature set is obtained by performing hierarchical clustering of feature dimensions on a historical asset feature set corresponding to a historical attack source address, and is used to represent the identity information of at least one attack initiator.
[0145] In some embodiments, the asset identification apparatus 455 further comprises a feature aggregation module, configured to, before calculating the aggregation degree between the current asset feature set and the at least one preset attack asset feature set, acquire at least one historical network alarm information corresponding to at least one historical attack event, each historical network alarm information in the at least one historical network alarm information comprising a historical attack source address; perform information clustering and feature extraction on the at least one dimension of each historical alarm information, and perform operating system identification on historical raw traffic data corresponding to each historical alarm information to obtain an initial historical asset feature set corresponding to each historical alarm information; merge the initial historical asset feature sets of the same historical attack source address to obtain at least one historical asset feature set; calculate the similarity between the at least one historical asset feature set in the feature dimension, cluster and merge the asset feature sets with a similarity greater than a preset similarity threshold, and take the historical asset feature sets under the same cluster as one preset attack asset feature set, thereby obtaining the at least one preset attack asset feature set.
[0146] In some embodiments, the current network alarm information is alarm information output by a preset intrusion detection platform according to the attack event, and the at least one current attack feature comprises at least one of the following: an attack tool, an attack type, an attack time and a geographic location.
[0147] In some embodiments, the operating system identification module 4552 is further configured to extract data contents of at least one preset field from the raw traffic data as the operating system associated data, the at least one preset field comprising at least one of the following: an attack source network address header length, a window size, a packet survival time, whether to be fragmented, a maximum packet length, a TCP option, and user agent information; and perform classification identification on the operating system associated data by using a preset classification identification model to obtain the current attack host system; the preset classification identification model is obtained by performing network training on an initial classification identification model; and the initial classification identification model is generated according to a preset correspondence relationship between a preset operating system and preset operating system associated data.
[0148] In some embodiments, the initial historical asset feature set includes at least one historical attack feature and a historical attack host system, and the feature aggregation module is further configured to: in at least one initial historical asset feature set corresponding to a same historical attack source address, merge at least one historical attack feature in the at least one initial historical asset feature set; and in the at least one initial historical asset feature set, take a historical attack host system with the highest occurrence frequency as a historical attack host system corresponding to the same historical attack source address, thereby obtaining a historical asset feature set corresponding to the same historical attack source address, and further obtaining the at least one historical asset feature set.
[0149] In some embodiments, the aggregation identification module 4553 is further configured to: calculate an aggregation degree of the current asset feature set and each preset attack asset feature set in the at least one preset attack asset feature set, each preset attack asset feature set corresponding to a preset asset identifier; take a preset attack asset feature set with an aggregation degree higher than a preset aggregation degree threshold as a target attack asset feature set, and take a preset asset identifier corresponding to the target attack asset feature set as an asset identifier of the current attack source address, thereby achieving asset identification of the current attack source address.
[0150] In some embodiments, the asset identification apparatus 455 further includes an updating module configured to update the target preset attack asset feature set using the current asset feature set.
[0151] It should be noted that the above description of the device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects to the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0152] The computer program product or computer program provided in the embodiments of the present application includes computer instructions stored in a computer readable storage medium. The processor of the computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to make the computer device execute the asset identification method described above in the embodiments of the present application.
[0153] The computer readable storage medium provided in the embodiments of the present application stores executable instructions. When the executable instructions are executed by the processor, the processor will execute the method provided in the embodiments of the present application, for example, the method shown in Figure 3 、 Figures 6-8 .
[0154] In some embodiments, the computer-readable storage media can be a memory such as a FRAM, ROM, PROM, EPROM, EEPROM, flash memory, a magnetic disk, an optical disk, or a CD-ROM, etc.; or various devices including one or any combination of the above memories.
[0155] In some embodiments, the executable instructions can be in the form of programs, software, modules, scripts, or code, written in any form of programming language, including compiled or interpreted languages, or declarative or procedural languages, and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
[0156] By way of example, the executable instructions can, but need not, correspond directly with a file in a file system, can be stored as part of a file that holds other programs or data, e.g., as one or more scripts in a Hyper Text Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinated files, e.g., files that store one or more modules, sub programs, or portions of code.
[0157] By way of example, the executable instructions can be deployed to execute on one computer, or on multiple computers that are located at one site, or that are distributed across multiple sites and are interconnected through a communication network.
[0158] To sum up, in the embodiment of the present application, by extracting the current network alarm information in multiple dimensions and increasing the feature recognition of the operating system dimension, the obtained current asset feature set can describe the identity information of the attack initiator of the current attack event from multiple dimensions, ensuring the accuracy of subsequent asset identity recognition based on the current asset feature set. And by performing hierarchical clustering on the feature dimensions of the historical asset feature set corresponding to the historical attack source address, at least one preset asset feature set is obtained, which can construct the multi-dimensional fingerprint information of the attacker, so that in the attack scene where a certain dimension changes, such as when an attacker changes the IP attack, the asset identity of the current attack event can still be identified through the aggregation degree of the overall features, thereby further improving the accuracy of asset identification. The embodiment of the present application can collect traffic data in the network, process rules based on Snort, and analyze raw traffic to obtain asset feature information of the attacker, thereby more accurately and quickly identifying the asset. Compared with the existing asset identification method, the feature dimension of the operating system recognition is increased, and the intelligent model is used for classification, which is more intelligent and fast; and no data packet needs to be actively sent, so that the network business is not affected, and it is not easy to be misreported by the intrusion detection system of the asset to be identified; and the related information of the preset attack asset feature set can be updated in real time according to the activity level of the asset in the network, so that with the accumulation of time, the information of the preset attack asset feature set will be more abundant.
[0159] The above merely describes the embodiments of the present application, but is not used to limit the protection scope of the present application. Any modification, equivalent replacement and improvement made within the spirit and scope of the present application shall be included in the protection scope of the present application.
Claims
1. An asset identification method, characterized in that, include: Obtain the current network alarm information of the current attack event, and perform information clustering and feature extraction on the current network alarm information in at least one dimension to obtain at least one current attack feature; Extract at least one preset field from the raw traffic data corresponding to the current network alarm information as operating system associated data; the raw traffic data is passive traffic collected by a traffic acquisition device; By using a preset classification and identification model, the operating system-related data is classified and identified to obtain the current attack host system type; the current attack host system type is the operating system deployed on the current asset that initiated the current attack event; A current asset feature set is obtained based on at least one current attack feature and the current attack host system type. The aggregation degree between the current asset feature set and at least one preset attack asset feature set is calculated, and the identity of the current asset is then identified based on the aggregation degree. The at least one preset attack asset feature set is obtained by hierarchical clustering of feature dimensions of historical asset feature sets corresponding to historical attack source addresses, and is used to characterize the identity information of at least one attack initiator. Calculate the similarity between the at least one set of historical asset features on the feature dimension, cluster and merge asset feature sets with similarity greater than a preset similarity threshold, and take the historical asset feature sets under the same cluster as a preset attack asset feature set to remove the differences in the historical attack source addresses of at least one set of historical asset features, and aggregate the attack features of all dimensions.
2. The method according to claim 1, characterized in that, Before calculating the aggregation degree between the current asset feature set and at least one preset attack asset feature set, the method further includes: Obtain at least one historical network alarm message corresponding to at least one historical attack event, wherein each historical network alarm message contains the address of the historical attack source; For each historical alarm message, information clustering and feature extraction are performed in at least one dimension, and data content of at least one preset field is extracted from the historical raw traffic data corresponding to each historical alarm message as historical operating system associated data; the historical raw traffic data is passive traffic collected by the traffic collection device; the historical operating system associated data is classified and identified through the preset classification and identification model to obtain the historical attack host system type and the initial historical asset feature set corresponding to each historical alarm message; The initial sets of historical asset features with the same historical attack source address are merged to obtain at least one set of historical asset features.
3. The method according to claim 1 or 2, characterized in that, The current network alarm information is the alarm information output by the preset intrusion detection platform based on the attack event, and the at least one current attack feature includes at least one of the following: attack tool, attack type, attack time, and geographical location.
4. The method according to claim 1 or 2, characterized in that: The at least one preset field includes at least one of the following: attack source network address header length, window size, packet lifespan, whether to fragment, maximum packet length, TCP options, and user agent information; The preset classification and recognition model is obtained by training the initial classification and recognition model through a network. The initial classification and recognition model is generated based on the preset correspondence between the preset operating system and the preset operating system associated data.
5. The method according to claim 2, characterized in that, The initial historical asset feature set includes at least one historical attack feature and a historical attack host system type. Merging the initial historical asset feature sets with the same historical attack source address yields at least one historical asset feature set, including: In at least one initial historical asset feature set corresponding to the same historical attack source address, at least one historical attack feature in the at least one initial historical asset feature set is merged; In the at least one initial set of historical asset features, the historical attack host system type that appears most frequently is taken as the historical attack host system type corresponding to the same historical attack source address, thereby obtaining the set of historical asset features corresponding to the same historical attack source address, and then obtaining the at least one set of historical asset features.
6. The method according to claim 1, 2, or 5, characterized in that, The calculation of the aggregation degree between the current asset feature set and at least one preset attack asset feature set, and then the identification of the current asset based on the aggregation degree, includes: Calculate the aggregation degree between the current asset feature set and each preset attack asset feature set in the at least one preset attack asset feature set; each preset attack asset feature set corresponds to a preset asset identifier; The preset attack asset feature set corresponding to the aggregation degree higher than the preset aggregation degree threshold is used as the target attack asset feature set, and the preset asset identifier corresponding to the target attack asset feature set is used as the asset identifier of the current attack source address, thereby realizing the asset identification of the current attack source address.
7. The method according to claim 6, characterized in that, After using the preset asset identifier corresponding to the target attack asset feature set as the asset identifier of the current attack source address, the method further includes: The target preset attack asset feature set is updated using the current asset feature set.
8. An asset identification device, characterized in that, include: The feature extraction module is used to obtain the current network alarm information of the current attack event, and to perform information clustering and feature extraction on the current network alarm information in at least one dimension to obtain at least one current attack feature. The operating system identification module is used to extract at least one preset field of data content from the raw traffic data corresponding to the current network alarm information as operating system associated data; the raw traffic data is passive traffic collected by a traffic acquisition device; By using a preset classification and identification model, the operating system-related data is classified and identified to obtain the current attack host system type; the current attack host system type is the operating system deployed on the current asset that initiated the current attack event; An aggregation identification module is used to obtain a current asset feature set based on at least one current attack feature and the current attack host system type, calculate the aggregation degree between the current asset feature set and at least one preset attack asset feature set, and then realize the identity identification of the current asset based on the aggregation degree; wherein, the at least one preset attack asset feature set is obtained by hierarchical clustering of the feature dimensions of the historical asset feature sets corresponding to the historical attack source addresses, and is used to characterize the identity information of at least one attack initiator: calculate the similarity between the at least one historical asset feature set on the feature dimension, cluster and merge asset feature sets with similarity greater than a preset similarity threshold, and take the historical asset feature sets under the same cluster as a preset attack asset feature set, so as to remove the differences in the historical attack source addresses of at least one of the historical asset feature sets, and aggregate the attack asset features of all dimensions.
9. The apparatus according to claim 8, characterized in that, The aggregation and identification module is also used for: Obtain at least one historical network alarm message corresponding to at least one historical attack event, wherein each historical network alarm message contains the address of the historical attack source; For each historical alarm message, information clustering and feature extraction are performed in at least one dimension, and data content of at least one preset field is extracted from the historical raw traffic data corresponding to each historical alarm message as historical operating system associated data; the historical raw traffic data is passive traffic collected through the traffic acquisition device; The historical operating system associated data is classified and identified using the preset classification and identification model to obtain the historical attack host system type and the initial historical asset feature set corresponding to each historical alarm information. The initial sets of historical asset features with the same historical attack source address are merged to obtain at least one set of historical asset features.
10. The apparatus according to claim 9, characterized in that, The initial set of historical asset features includes at least one historical attack feature and a historical attack host system type. The aggregation and identification module is further used for: In at least one initial historical asset feature set corresponding to the same historical attack source address, at least one historical attack feature in the at least one initial historical asset feature set is merged; In the at least one initial set of historical asset features, the historical attack host system type that appears most frequently is taken as the historical attack host system type corresponding to the same historical attack source address, thereby obtaining the set of historical asset features corresponding to the same historical attack source address, and then obtaining the at least one set of historical asset features.
11. An electronic device, characterized in that, include: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the method according to any one of claims 1 to 7.
12. A computer-readable storage medium, characterized in that, It stores executable instructions for implementing the method according to any one of claims 1 to 7 when executed by a processor.
13. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by the processor, they implement the asset identification method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Attacker portrait method and system based on unsupervised learning
CN108924163A
Network attack processing method and device, computer equipment and storage medium
CN111490996A
Network attack identification method and device, computer equipment and storage medium
CN111565205A