Attack path tracing and attack source detection method based on machine learning
By building a directed network attack map and using technical means such as depth-first traversal algorithms and particle swarm optimization algorithms, problems such as tracking errors and excessive resource consumption in the existing technology have been solved, and more efficient and accurate attack source detection have been achieved.
Patent Information
- Application Number
- CN202211014967.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-23
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-08-23
AI Technical Summary
The prior art has large tracking errors in attack source detection, is not suitable for high-dimensional data, excessive resource consumption, low efficiency and low solution quality.
By constructing a large network directed attack graph, the depth-first traversal algorithm and the two-dimensional adjacency matrix are used to find all reachable paths between the source host and the target host, and combined the time parameters of the event occurrence and the particle swarm optimization algorithm to optimize the path weight, thereby calculating the source probability of the attack.
It greatly improves the efficiency and accuracy of attack source detection, and can discover multiple nodes closely related to attack events in large networks, providing higher defense guarantees.
Smart Images

Figure CN115412328B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of machine learning and network security technology, and in particular to an attack path tracing and attack source detection method based on machine learning. Background Art
[0002] With the rapid development of network technology represented by 5G technology, the Internet has been widely used in various fields such as industry, finance, and education. While information networks have become an important guarantee for social development, due to the diversity, unevenness, and openness of network forms, computers are easily vulnerable to network attacks during application, resulting in information data leakage and destruction. Relevant data show that in the decade from 2015 to 2025, the global potential economic losses caused by cyber attacks may be as high as 294 billion US dollars. The escalation of network risks has made governments, enterprises, and individuals pay more attention to this risk. In large networks, Windows-based authentication events can be represented as attack graphs. Through the attack graph, it can be analyzed that when a host is breached, which computer is the most likely source of the attack, so that the source of the attack can be traced to help the defender better analyze and make decisions.
[0003] At present, there are many methods for attack source detection, including detection algorithms based on dynamic Bayesian attack graphs, dynamic reachability model detection, traffic monitoring based on feature information and abnormal behavior, etc. However, these methods all have their limitations. The Bayesian network attack detection model combined with the connection tree algorithm to track the attack path ignores that not all Bayesian network nodes are relatively independent, which makes this method have a large tracking error. The isolation forest algorithm is not suitable for high-dimensional data when performing attack detection, and is sensitive to global sparse points, which leads to low accuracy of attack detection. The method of finding a path in a specified solution space with the help of a binary particle swarm optimization algorithm is limited to the case where the number of hosts in the solution space is small. If the solution space is too large, it will consume more resources. When using the incremental piecewise linear classification algorithm for malicious attack identification, there will be inefficiency and excessive resource consumption. The attack path tracing method based on the genetic algorithm will not have a high quality solution because there is no rigorous and scientific calculation method definition for the parameters related to the crossover rate and mutation rate in the genetic algorithm. Summary of the invention
[0004] In view of the various defects in the prior art, the present invention provides an attack path tracing and attack source detection method based on machine learning, aiming to solve the defects in the prior art.
[0005] The technical solution provided by the present invention is:
[0006] A method for attack path tracing and attack source detection based on machine learning, comprising the following steps:
[0007] Construct a large network directed attack graph, uniformly number different source hosts and target hosts, store the reachability between adjacent hosts as a two-dimensional adjacency matrix, and use the depth-first traversal algorithm and the two-dimensional adjacency matrix to find all reachable paths between the source host and the target host;
[0008] By introducing the time parameter of event occurrence and combining it with recursion, the actual feasible path that complies with the time sequence of events can be selected from all reachable paths;
[0009] Initialize the weights of the actual feasible paths, use the path sorting algorithm to calculate the probability of the attack source, and select the one with the largest probability value as the attack source;
[0010] The particle swarm optimization algorithm is used to continuously iterate the path weights in the process of calculating the attack source probability, thereby obtaining the optimal path weight value.
[0011] The attack path tracing and attack source detection method based on machine learning proposed in the present invention has the following beneficial effects:
[0012] The detection method provided by the present invention combines the advantages of the PRA algorithm, the depth-first traversal algorithm and the particle swarm optimization algorithm in the process of attack path tracing and attack source detection, and optimizes the path weight through the particle swarm optimization algorithm, which can greatly improve the efficiency and accuracy of attack source detection, and can find multiple nodes closely related to the attack event in the entire large network, which can find a breakthrough for the defender, so that the accuracy of attack path tracing and attack source detection is greatly improved, which provides a guarantee for the defender's defense work and the rapid establishment of the attack source. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings in the following description are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0014] Figure 1 A flow chart of a method for attack path tracing and attack source detection based on machine learning provided in an embodiment of the present invention;
[0015] Figure 2 A schematic diagram of a process flow of a method for finding a reachable path through a depth-first traversal algorithm provided in an embodiment of the present invention;
[0016] Figure 3A schematic diagram of the probability of a node being the attack source of another node based on the PRA algorithm provided in an embodiment of the present invention;
[0017] Figure 4 A schematic diagram of determining path weights in a PRA algorithm using a particle swarm optimization algorithm provided in an embodiment of the present invention;
[0018] Figure 5 Some source detection probability diagrams listed in the experimental simulation provided by the embodiment of the present invention;
[0019] Figure 6 A graph of the number of feasible paths between some nodes enumerated in the experimental simulation provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0020] The specific embodiments of the present invention are further described below in conjunction with the accompanying drawings. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0021] Example:
[0022] See also Figure 1 , the flow chart of the attack path tracing and attack source detection method based on machine learning provided by the embodiment of the present invention includes the following steps:
[0023] S101. Construct a large network directed attack graph, uniformly number different source hosts and target hosts, store the reachability between adjacent hosts as a two-dimensional adjacency matrix, and use the depth-first traversal algorithm and the two-dimensional adjacency matrix to find all reachable paths between the source host and the target host.
[0024] Based on Windows authentication event data, a large network directed attack graph is constructed according to the access direction between hosts. Different hosts are numbered, and the host numbers are stored in a one-dimensional array. The reachability between adjacent hosts is stored as a two-dimensional adjacency matrix.
[0025] Then, by using a depth-first traversal algorithm, all reachable paths between the source host and the target host are enumerated (here, a reachable path means that all intermediate paths are not zero on the adjacency matrix, indicating that the path is reachable). The present invention saves all reachable paths between two nodes into a two-dimensional array.
[0026] See also Figure 2 A flow chart of a method for finding a reachable path by using a depth-first traversal algorithm as shown in the embodiment;
[0027] Find a reachable path through the depth-first traversal algorithm, including:
[0028] Step 1: When accessing a vertex V through the depth-first convenience algorithm, take the vertex as the current vertex and access the next unvisited adjacent point of the current vertex;
[0029] Step 2: If there are unvisited adjacent points among all adjacent points of the current vertex, then visit the unvisited adjacent points and perform the operation in step 1 on the unvisited adjacent points;
[0030] Step 3: If all adjacent points of the current vertex have been visited, determine whether all vertices have been visited. If so, it means that all reachable paths have been obtained. Otherwise, go back along the search path and continue to step 1.
[0031] The actual feasible attack path is screened out through the depth-first traversal algorithm combined with time parameters and recursion, thus avoiding the impact of non-feasible paths on attack source detection.
[0032] S102: introducing a time parameter of event occurrence and combining it with a recursive method, to select an actual feasible path that complies with the time sequence of events from all reachable paths.
[0033] Next, we introduce the time parameter of the event occurrence and use recursion to filter out the actual effective feasible paths from all the enumerated reachable paths (here we will filter out all the effective paths that meet the time increasing relationship of the intermediate paths). i To Host C j The feasible relationship path P needs to satisfy all intermediate paths T pm Arranged in chronological order, only the rules that conform to the following formula are considered to be practical and effective feasible paths.
[0034]
[0035] S103: Initialize the weights of the actual feasible paths, calculate the probability of the attack source using the path sorting algorithm, and select the one with the largest probability value as the attack source.
[0036] See also Figure 3 Schematic diagram of calculating the probability that a certain node is the attack source of another node based on the PRA algorithm shown in the embodiment;
[0037] For the probability score(i; j) that a host is the source of an attack on another host using the PRA algorithm, first initialize the path weights at different levels, such as path C 1 →C 2 →C 3 →C 4 and path C 1 →C 5 →C6 →C 3 →C 4 , where C 1 →C 2 It is a first-level path with a path weight of W. 1 , C 3 →C 4 It is a three-level path with path weight W 3 , however, for path C 1 →C 5 →C 6 →C 3 →C 4 For C 3 →C 4 It is a four-level path with a path weight of W 4 In the method of the present invention, the types of weights are directly defined as 8 categories, which represent 8 levels of path weights respectively. Path weights exceeding 8 levels are also recorded as W 8 In addition, we need to understand how to calculate the probability value θ of the adjacent host path. p to C q The path probability θ pq Meet C p Out-degree related relational expressions:
[0038]
[0039] On the computing host C i When the probability score(i; j) is the attack source of host Cj, the present invention calculates the probability score(i; j) of each reachable path P ij The path probabilities of all adjacent intermediate paths passed by are multiplied by the path weights to obtain the single path probability score (one P ij ), and finally the sum of the single path probabilities of all reachable paths is taken as the final attack source probability score(i; j).
[0040]
[0041] In the above formula, although each reachable path P ij The starting point and the end point are the same, but their meanings are different, indicating different paths from the same starting point to the same end point. ij ) There will be many kinds, and the sum of all the single path probabilities is needed to get the true host C i Probably Host C j The probability score(i; j) of the attack source.
[0042] The PRA algorithm is used to multiply the path probability of adjacent node paths in the attack graph by the path weight to obtain the probability of a single path. Finally, the probability of the attack source is calculated by summing up all the single path probabilities. One or more nodes with high probabilities are taken as the attack source. This method can greatly improve the accuracy of attack source detection.
[0043] S104. Continuously iterate and optimize the path weight in the process of calculating the attack source probability through a particle swarm optimization algorithm, so as to obtain the path weight value in the optimal case.
[0044] See also Figure 4 Schematic diagram of determining path weights in a PRA algorithm using a particle swarm optimization algorithm as shown in the embodiment;
[0045] When using the particle swarm optimization algorithm to determine the path weights at each level, first initialize the number of particles to 8, and initialize the initial speed and initial position of the particles (i.e., the initial weights of the paths at 8 levels). It is also necessary to initialize the global optimal and local optimal values (the optimal value is the probability that multiple hosts are the attack source of a certain host). Use the following formula to update the speed and position of a single particle:
[0046]
[0047]
[0048] After the position of a single particle is updated, the position is used as the weight of the corresponding path. The weights of the other paths remain unchanged. Based on the current path weight value, the probability of the host being the attack source of another host is calculated using the attack source probability calculation method described in the previous step. This is used as the local optimal value at this time and compared with the historical optimal value. After the positions of all particles are updated, the probability of the host being the attack source of another host is calculated based on the path weight value at this time using the attack source probability calculation method. This is used as the current global optimal value and compared with the historical global optimal value. If the error between the global optimal value and the actual value is higher than the error between the historical global optimal value and the actual value, the loop iteration process is exited, and the particle position corresponding to the historical optimal situation is used as the final weight of multiple paths. On the contrary, if the error between the global optimal value and the actual value is lower than the error between the historical global optimal value and the actual value, the step of updating the particle speed and position is re-entered, and the historical optimal value is updated to the current global optimal value (which means that more suitable path weights and global optimal values can be found through iteration).
[0049] The particle swarm optimization algorithm is used to continuously iterate and optimize the path weights in the process of calculating the attack source probability, thereby obtaining the optimal path weight value, which improves the efficiency and accuracy of attack source detection.
[0050] See also Figure 5The experimental simulation of the method shown in the figure shows some source detection probability maps, and Figure 6 The graph of the number of feasible paths between some nodes enumerated in the experimental simulation shown;
[0051] In one embodiment, after obtaining the final weights of multiple paths, the method needs to be verified for effectiveness:
[0052] The present invention uses the above method to conduct a simulation experiment based on the identity authentication event data of Windows-based desktop computers, servers and active directory servers collected by Los Alamos National Laboratory (LANL). The data contains a total of 1 billion identity authentication events over 58 days, and the experiment of the present invention actually uses the first 15 minutes of the 8th day. The field identifiers of each data include time, source user domain, target user domain, source computer, target computer, identity authentication type, login type, identity authentication direction and verification result. The actual 15-minute data feature statistics are as follows: Figure 6 The present invention uses 15 minutes of data to construct an attack graph containing 10143 nodes and 273279 edges.
[0053] Through simulation experiments, the attack source detection results and attack path tracing results of the present invention are very similar to the actual data results. A high accuracy rate is obtained through experimental simulation using the method of the present invention. For the target host C586, when it is attacked, the attack source is most likely to come from host C1843. When hosts C529, C612, C457, C467 and host C1065 are compromised, the corresponding attack sources are also most likely to come from host C1843. In contrast, the attack sources corresponding to host C625 and host C528 are host C18436 and host C10494, respectively. It is concluded that host C1843 played a crucial role in the attack incident.
[0054] The above embodiment of the present invention combines the advantages of the PRA algorithm, the depth-first traversal algorithm and the particle swarm optimization algorithm in the process of attack path tracing and attack source detection. By optimizing the path weight through the particle swarm optimization algorithm, the efficiency and accuracy of attack source detection can be greatly improved, and multiple nodes closely related to the attack event can be found in the entire large network, which can find a breakthrough for the defender.
[0055] The embodiments of the present invention are described in detail above with reference to the accompanying drawings, but the present invention is not limited to the described embodiments. For those skilled in the art, various changes, modifications, substitutions and variations of these embodiments are made without departing from the principles and spirit of the present invention, and still fall within the scope of protection of the present invention.
Claims
1. Attack path tracing and attack source detection method based on machine learning, It is characterized in that include: Construct a large network directed attack graph, uniformly number different source hosts and target hosts, store the reachability between adjacent hosts as a two-dimensional adjacency matrix, and use the depth-first traversal algorithm and the two-dimensional adjacency matrix to find all reachable paths between the source host and the target host; By introducing the time parameter of event occurrence and combining it with recursion, the actual feasible path that complies with the time sequence of events can be selected from all reachable paths; The step of selecting from all accessible paths an actual feasible path that complies with the event time sequence includes: Host C i To Host C j The feasible relationship path P needs to satisfy all intermediate paths T pm Arranged in chronological order, the rules that meet the following formula are practical feasible paths: Initialize the weights of the actual feasible paths, use the path sorting algorithm to calculate the probability of the attack source, and select the one with the largest probability value as the attack source; The weights of the actual feasible paths are initialized, including: defining the weight types into 8 categories, representing 8 levels of path weights, and recording the path weights of 8 levels or more as W 8 ; Before calculating the attack source probability by using the path sorting algorithm, the following steps are included: Calculate the adjacent host path probability value, specifically: Two adjacent nodes C p to C q The path probability θ pq Meet C p Out-degree related relational expressions: The method of calculating the attack source probability by using a path sorting algorithm includes: For each reachable path P found ij The path probabilities of all adjacent intermediate paths passed by are multiplied by the path weights to obtain the single path probability score (one P ij ), and finally the sum of the single path probabilities of all reachable paths is taken as the final attack source probability score(i; j): The particle swarm optimization algorithm is used to continuously iterate the path weights in the process of calculating the attack source probability, thereby obtaining the optimal path weight value.
2. The attack path tracing and attack source detection method based on machine learning as claimed in claim 1, It is characterized in that The method of using a depth-first traversal algorithm and a two-dimensional adjacency matrix to find all reachable paths between a source host and a target host includes: Use the depth-first traversal algorithm to find all paths whose intermediate paths are not zero in the two-dimensional adjacency matrix as reachable paths.
3. The attack path tracing and attack source detection method based on machine learning as claimed in claim 1, It is characterized in that The sum of the single path probabilities of all reachable paths is taken as the final attack source probability score(i; j), including: For each reachable path P found ij , whose starting point and end point are the same, since there are different paths from the same starting point to the same end point, the probability score of a single path (one P ij ) There will be many kinds, so the sum of all the single path probabilities is the true host C i Host C j The probability score(i; j) of the attack source.
4. The attack path tracing and attack source detection method based on machine learning as claimed in claim 1, It is characterized in that Before the particle swarm optimization algorithm is used to continuously iterate and optimize the path weights in the process of calculating the attack source probability, it includes: Initialize the specified number of particles to 8, and initialize the initial speed and initial position of the particles, where the initial position is the initial weight value of the path at 8 levels, and then initialize the global optimal and local optimal values, where the optimal value is the probability that multiple hosts are the attack source of a certain host. Update the speed and position of a single particle through the following formula:
5. The attack path tracing and attack source detection method based on machine learning as claimed in claim 4, It is characterized in that After updating the velocity and position of a single instance, including: The updated position of a single particle is used as the weight of the corresponding path, and the weights of the other paths remain unchanged. Based on the current path weight value, the probability of the host being the attack source of another host is calculated using the attack source probability calculation method. This is used as the local optimal value at this time and compared with the historical optimal value. After the positions of all particles are updated, based on the path weight value at this time, the probability of the host being the attack source of another host is calculated using the attack source probability calculation method. This is used as the current global optimal value and compared with the historical global optimal value. If the error between the global optimal value and the actual value is higher than the error between the historical global optimal value and the actual value, the loop iteration process is exited, and the particle position corresponding to the historical optimal case is used as the final weight of multiple paths.
6. The attack path tracing and attack source detection method based on machine learning as claimed in claim 5, It is characterized in that If the error between the global optimal value and the actual value is lower than the error between the historical global optimal value and the actual value, the step of updating the particle speed and position is re-entered, and the historical optimal value is updated to the current global optimal value.
Citation Information
Patent Citations
Depth-first attack drawing generating method
CN101222317A
Network security evaluation device based on attack graph adjacent matrix
CN103368976A
Reliability analysis method and system for dynamic network attack process
CN104539601A