A Defense Automation Process Orchestration Method Based on SOAR

By adopting the SOAR-based defense automation process orchestration method and open set transfer learning algorithm in power grid network security protection, we automatically analyze and judge network attack behavior and build an attack chain model, solving the problems of low response efficiency and high cost in power grid network security protection, and achieving efficient and automated network attack response.

CN115442133BActive Publication Date: 2025-06-03STATE GRID ZHEJIANG ELECTRIC POWER CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211069187.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-02
Publication Date
2025-06-03
Estimated Expiration
2042-09-02

AI Technical Summary

Technical Problem

The existing power grid network security protection relies on manual response, resulting in low response efficiency, high cost and subjective risks, making it difficult to effectively deal with high-risk and high-threat security equipment alarm events in massive alarms.

Method used

The defense automation process orchestration method based on SOAR is adopted, and the open set transfer learning algorithm is used to automatically analyze and judge network attack behavior, and an attack chain model is built, and the SOAR network attack response automatic orchestration technology is used to realize automated response and disposal.

Benefits of technology

It improves the efficiency of response to cyber attack behavior, reduces the threat brought by cyber attacks, reduces the labor cost of network security operations, and achieves a timely and automated response to high-risk alarm events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115442133B_ABST
    Figure CN115442133B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for orchestrating defense automation processes based on SOAR, including: automated analysis, research, and evidence collection of network attack behaviors based on an open-set transfer learning algorithm; automated orchestration technology for network attack responses based on SOAR; and an orchestration script for defense automation processes based on SOAR. The present invention deeply studies the automated response processes for events of different threat levels in various security scenarios, designs an orchestration script for defense automation processes based on SOAR, and performs automated response handling for security device alarms of different risk levels, solving the problem of difficult timely discovery and automated response handling of high-risk and high-threat security device alarm events in a large number of alarms, achieving the purpose of improving the efficiency of network attack behavior responses, effectively reducing the threats brought by network attacks, assisting the power grid in improving the network security protection system, and significantly reducing the labor costs of network security operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power system security protection, and specifically to a defense automation process orchestration method based on SOAR. Background Art

[0002] The proportion of new energy in primary energy consumption is increasing continuously, which will accelerate the replacement of fossil energy. At present, the installed capacity of power sources in China will maintain a stable and relatively rapid growth. Therefore, to build a new power system in the form of an energy Internet, a large number of distributed power equipment and Internet of Things devices need to be networked to form a new generation of power system with renewable energy as the main energy supply source. With the continuous acceleration of the construction of the new power system, a large number of power terminals will be connected to the power grid on a large scale, and new equipment and new technologies are widely applied in various systems, which strongly improves the service ability of the power grid.

[0003] Due to the characteristics of the new power system such as huge scale, complex structure, heterogeneous and large number of terminals, during the construction and operation process, the coverage area of security equipment expands, the number of security protection objects increases, the types of security protection objects become rich, and the network attack surface in the power network system is also constantly expanding.

[0004] The network security protection of the power grid mainly relies on the network security protection system deployed at the boundary to intercept simple attack behaviors through boundary protection, and only generate alarms for relatively complex network attack behaviors. Therefore, the current network protection work of the power grid still relies on a large amount of manual work to screen, confirm and conduct correlation analysis on a large amount of data sources, and security experts conduct network attack analysis and formulate response handling measures, and finally achieve a response closed-loop through manual operation.

[0005] Currently, the response time for network security incidents cannot break through the limit of manual response efficiency, and it is difficult to improve the response efficiency; the response strategy depends on the experience and judgment ability of security experts, so it has strong subjectivity, and there is a risk of instability in the decision-making and handling ability for network security incidents; network security operation and maintenance personnel need to do a large amount of manual repetitive work to obtain effective information from a large amount of clues, resulting in a large amount of labor costs being arranged in the basic investigation work, so the total labor cost is relatively high, and the error rate of manual screening cannot be completely avoided, which is likely to cause network security risks. Summary of the Invention

[0006] (I) Technical Problems to be Solved

[0007] In view of the deficiencies of the prior art, the present invention provides a defense automation process orchestration method based on SOAR, deeply studies the automated response processes for events of different threat levels in various security scenarios, designs a defense automation process orchestration script based on SOAR, and conducts automated response handling for security device alarms of different risk levels, solving the problem of difficult timely discovery and automated response handling of high-risk and high-threat security device alarm events in a large number of alarms, achieving the purpose of improving the efficiency of network attack behavior response, effectively reducing the threats brought by network attacks, assisting the power grid to improve the network security protection system, and significantly reducing the labor costs of network security operations.

[0008] (2) Technical solutions

[0009] To achieve the above object, the present invention provides the following technical solutions. A defense automation process orchestration method based on SOAR includes the following steps:

[0010] S1, automated analysis, research, and evidence collection of network attack behaviors based on the open set transfer learning algorithm;

[0011] S2, automated orchestration technology for network attack responses based on SOAR;

[0012] S3, defense automation process orchestration script based on SOAR.

[0013] Preferably, for the automated analysis, research, and evidence collection of network attack behaviors based on the open set transfer learning algorithm, online analytical processing is used to conduct automated analysis around the attacked object, and online analysis of the basic data sources is carried out with information such as the security device logs and threat intelligence of the system, and evidence collection of associated events is carried out for the target IP and its associated IPs of key network attack events;

[0014] Utilize the ability of the open set transfer algorithm to separate unknown samples from known samples in the target domain, and combine the evidence points related to key events extracted from the research and evidence collection to complete the construction of the attack chain model;

[0015] Based on the time axis, the attack behaviors around key events are used to string together the clues obtained from the evidence collection, and after establishing a chronological relationship model of the clues, effective clues of key attack events are obtained.

[0016] Preferably, the online analysis and processing of the basic data sources includes a data collection layer, a data storage layer, a data analysis layer, and a data presentation layer;

[0017] The data collection layer mainly collects power security device alarm data through methods such as syslog log transmission and API data interfaces;

[0018] The data storage layer is responsible for storing the preprocessed security device alarm data with a unified specification into MYSQL;

[0019] The data analysis layer designs a data analysis solution based on the idea of online analytical processing, dividing the network attack behavior warning data set into three dimensions, namely the time dimension, the object dimension, and the behavior dimension; the time dimension has three dimension levels: year, month, and day; the object dimension has two dimension levels: the attack object and the target object, and the behavior dimension has only one dimension level, that is, the security device warning attack behavior.

[0020] The data presentation layer mainly integrates functional components such as statistical query, auxiliary decision-making, and quick screening, which can provide relatively accurate analysis and judgment decision support for enterprise management. At the same time, it also provides an early warning function for various security device monitoring warning data and all-round monitoring of power security device warning data.

[0021] Preferably, an open-set transfer learning algorithm is used to build an attack chain model. First, the source data set and the target data set are extracted and analyzed. The source data set is the existing known network attack behavior labels, while the target data set is not completely the same as the source data set label content. The target data set will add new and unknown attack behaviors that appear in the future;

[0022] The categories in the target data set that exceed those in the source data set will include two parts: one part is the attack behavior types of newly connected devices; the other part is the newly added attack behavior types not included in the existing source data set, and this part belongs to the relevant categories not included in the source data.

[0023] Preferably, the open-set transfer learning algorithm, x ct used to identify whether the t-th attack behavior type in the target data set is marked as category c, x ct ∈{0, 1}. At the same time, since the attack behavior type data set mentioned above belongs to the open set, a parameter o is introduced t to mark whether the t-th sample is an unknown attack behavior type. Then o t ∈{0, 1}, and according to the open-set learning transfer algorithm, the constraint function is obtained:

[0024]

[0025]

[0026]

[0027]

[0028] There are two constraint conditions in the constraint function:

[0029] The first constraint: for any attack behavior type sample in the target data set, either x ct = 1, or ot = 1, for samples in the target dataset, there are only two cases. One is that the sample belongs to a known attack behavior type in the source dataset, or the sample belongs to an unknown attack behavior type.

[0030] The second constraint: For any known network attack behavior type, there must be at least one x ct = 1, and there will not be a shared category of a known attack behavior type that cannot be found in the target dataset.

[0031] The overall learning idea is to continuously map and iterate between the existing known attack behavior type dataset and the target dataset until the two datasets converge to a certain value. Then, without adding other security devices, the richness of attack behavior types can be guaranteed. When new attack behavior types introduced after adding new security devices will be learned into the existing dataset, and the network attack behavior types with self-learning characteristics become an important part of building the attack chain model.

[0032] Preferably, a time-series analysis model for network attack behavior clues is constructed, using data from the past period to predict information in the future period, including continuous prediction and discrete prediction, etc. In the scenario of network security behavior analysis and judgment, it is also possible to predict the subsequent attack actions of attackers based on the existing behaviors of existing attackers.

[0033] Preferably, based on the SOAR-based network attack response automatic orchestration technology, the attack chain stage of the associated event behavior time series is determined through the attack chain model, so as to effectively infer and form a complete attack behavior chain. Based on the attack behavior chain, for the current attack behavior in a certain stage of the attack time series, match the security emergency response measure script that can solve the corresponding problem, and combine them to form a complete response strategy and SOAR automated security orchestration solution.

[0034] Preferably, for the automated response orchestration of network attack behaviors, the automated response process is customized based on the network attack behavior analysis model as the basic data source. The automated response process includes modules related to data source access, security warning, work order management, and security orchestration automation.

[0035] Preferably, the automated orchestration and disposal script for network attack behaviors is jointly implemented by the access of the security warning device sys log, the aggregation of security warning device alarms, the tracking of alarm attack chains, the configuration of SOAR automated response strategies, and the automated response strategy center.

[0036] Beneficial effects

[0037] Compared with the prior art, the present invention provides a defense automated process orchestration method based on SOAR, having the following beneficial effects:

[0038] 1. By researching the automated analysis, judgment, evidence collection technology for network attack behaviors based on the open-set transfer algorithm, the samples of attacker information such as attacker logs using the open-set transfer algorithm for the open attacker information samples are clustered for known samples and separated for unknown samples, improving the filtering accuracy of attacker-related information and the effective extraction efficiency of massive samples in power network security protection work, reducing the subjectivity of judgment in manual handling, and at the same time reducing a large amount of repetitive operation time for manual screening, significantly reducing the labor cost, achieving the all-round automated extraction and analysis of attacker-related information, improving the efficiency of effective information filtering, and reducing the labor cost.

[0039] 2. By researching the automated orchestration technology for network attack responses based on SOAR, after judging the relevant clue samples of network attack events in time series, it realizes matching according to the judgment results with the automated orchestration script and conducts automated defense strategy orchestration. Immediately after the strategy orchestration, it responds with the automated network security event handling measures according to the script, using automated means to replace manual handling, greatly reducing the response time of network security events, significantly improving the response efficiency, achieving automated decision-making and orchestration responses for network attacks, effectively accelerating the response speed, and avoiding greater threats caused by network attacks.

[0040] 3. The research results are fully coordinated with the currently deployed network security protection devices at the edge to realize the automated orchestration of network attack behavior defense work in the new power system, making its screening more accurate, response more convenient, and handling more efficient, building a solid fortress for network security protection in the new power system, reducing the probability of security risks caused by poor response efficiency of network attack behaviors, effectively helping the power grid improve the network security management system, further improving the response efficiency of network security events, and realizing the further strengthening of network security protection management measures. Description of the Drawings

[0041] Figure 1 It is the overall flowchart of the automated analysis, judgment, and evidence collection technology for network attack behaviors based on the open-set transfer learning algorithm;

[0042] Figure 2 It is the online analytical processing flow of the basic data source;

[0043] Figure 3 It is the diagram of the category distribution of the open-set data set;

[0044] Figure 4 It is the overall idea diagram of the response strategy and the SOAR automated security orchestration plan;

[0045] Figure 5 It is the overall idea diagram of the automated response process for network attack behaviors;

[0046] Figure 6 Flowchart for the SOAR automated response strategy center to implement automated monitoring and handling of alarms

[0047] Figure 7 This is the overall flowchart of the present invention. Detailed implementation manners

[0048] To better understand the purpose, structure and function of the present invention, the following further describes in detail a method for orchestrating defense automation processes based on SOAR of the present invention with reference to the accompanying drawings.

[0049] Please refer to Figures 1-6 , a method for orchestrating defense automation processes based on SOAR, including:

[0050] 1. Automated analysis, judgment, forensics technology of network attack behaviors based on the open set transfer learning algorithm

[0051] Accurate automated analysis and judgment capabilities of network attack behaviors are decisive factors for the accuracy of the entire security protection system. Here, online analytical processing is used to conduct automated analysis around the attacked object. Based on information such as the security device logs of the system and threat intelligence, relevant event forensics is carried out on the target IP and its associated IPs of key network attack events. Using the ability of the binary cross-entropy loss function with parameters in the open set transfer algorithm to separate unknown samples from known samples in the target domain, combined with the evidence points related to key events extracted by forensics and judgment, the construction of the attack chain model is completed. Based on the time axis for the attack behaviors around the current key event, the clues obtained from forensics are concatenated. After establishing the chronological relationship model of the clues, effective clues of key attack events are obtained. The overall idea is as Figure 1 shown:

[0052] 1.1. Online analytical processing of basic data sources

[0053] The online analytical processing of basic data sources includes a data collection layer, a data storage layer, a data analysis layer, and a data presentation layer, specifically as follows Figure 2 shown

[0054] The data collection layer mainly collects power security device alarm data through methods such as sys log log transmission and API data interfaces. These data are usually structured data, such as attack IP information, target IP, attack methods, etc. Among the massive alarm data of different security devices, there may be redundant and duplicate alarm log data generated for the same malicious attack behavior. It is necessary to extract high-value data within a short time to form a unified specification.

[0055] The data storage layer is responsible for storing the pre - processed security device alarm data with a unified specification into MySQL. MySQL is mainly used to store the detailed information fields of alarms and manage the metadata of Hive. The tables, fields, and delimiters created by Hive will be stored in MySQL. When performing data operations, it is necessary to start the MySQL engine to verify the existence of metadata.

[0056] The data analysis layer designs a data analysis solution based on the idea of online analytical processing. The network attack behavior alarm data set is divided into three dimensions: the time dimension, the object dimension, and the behavior dimension. The time dimension has three hierarchical levels: year, month, and day. The object dimension has two hierarchical levels: the attacked object and the target object. The behavior dimension has only one hierarchical level, that is, the security device alarm attack behavior. By determining the data pivot dimensions for network attack behavior analysis and storing the predefined dimension information in the data table, data pivoting can be performed according to the predefined dimensions, mining the relationships between the security device attack behavior data, and laying the foundation for the automated analysis and judgment of network attack behavior.

[0057] The data presentation layer mainly integrates functional components such as statistical query, auxiliary decision - making, and quick screening, which can provide relatively accurate decision - making support for network security event analysis and judgment for the enterprise management level. At the same time, it also provides an early warning function for various security device monitoring alarm data, completing the full - range monitoring of the power security device alarm data.

[0058] 1.2. Implement the construction of the attack chain model using the open - set transfer learning algorithm

[0059] An important part of the network attack behavior automated analysis, judgment, and evidence - collection technology is the construction of the network attack behavior model. As Figure 3 shown, the source data set is the existing known network attack behavior labels, while the target data set does not have exactly the same label content as the source data set. The reason is that new unknown attack behaviors that will appear in the future will be added to the subsequent target data set.

[0060] The existing training data is the known attack behavior types in the source data set, and the definition of the attack behavior types of newly connected devices and the new attack behavior types not included in the existing source data set belong to the part of the target data set that exceeds the source data set. The effect finally achieved by relying on the open - set transfer learning algorithm is to iterate the source data and the target data set in turn until the two data sets converge. The newly added attack behavior categories in the target data set can be learned as the source data set and be used in the scenario of constructing the attack chain model.

[0061] The categories in the target dataset that exceed those in the source dataset will consist of two parts. One part is the attack behavior types of newly connected devices. This part belongs to the situation where there are related categories in the source dataset but the naming is not unified enough. It needs to be trained to integrate the target dataset into the source data as expected. Since there are similar categories in the target dataset in the source dataset, the learning of this dataset belongs to semi-supervised domain adaptation learning. The other part is the newly added attack behavior types that are not included in the existing source dataset. This part belongs to the situation where there are no related categories in the source data, and the categories in the target dataset need to be learned and incorporated into the source dataset. Since there are no related categories in the target dataset in the source dataset, the learning of this dataset belongs to unsupervised domain adaptation learning. According to the new situation of dataset categories in the target dataset, an attempt is made to solve the problems existing in the construction of the network attack model by studying unsupervised and semi-supervised open-set transfer learning algorithms.

[0062] In the open-set transfer learning algorithm, x ct is used to identify whether the t-th attack behavior type in the target dataset is labeled as category c, x ct ∈ {0, 1}. At the same time, since the attack behavior type dataset mentioned above belongs to the open set, a parameter o t is introduced to mark whether the t-th sample is an unknown attack behavior type. Then o t ∈ {0, 1}. According to the open-set learning transfer algorithm, the following constraint function can be obtained:

[0063]

[0064]

[0065]

[0066]

[0067] There are two constraint conditions in this constraint function:

[0068] The first constraint: For any attack behavior type sample in the target dataset, either x ct = 1 or o t = 1. Generally speaking, for the samples in the target dataset, there are only two situations. One is that it belongs to the known attack behavior types in the source dataset, or the sample belongs to unknown attack behavior types.

[0069] The second constraint: For any known network attack behavior type, at least one x ct = 1. There will not be a shared category of a known attack behavior type that cannot be found in the target dataset.

[0070] The overall learning idea is to continuously map and iterate between the existing known attack behavior type dataset and the target dataset until the two datasets converge to a certain value. Without adding other security devices, the richness of attack behavior types can be guaranteed. When new security devices are added, the new attack behavior types introduced will be learned into the existing dataset, and the network attack behavior types with self-learning characteristics become an important part of building the attack chain model.

[0071] 1.3. Construct a time series analysis model for network attack behavior clues

[0072] The time series model uses data from a past period to predict information for a future period, including continuous prediction and discrete prediction, etc. In the scenario of network security behavior analysis and judgment, there is also a need to predict the subsequent attack actions of an attacker based on the existing behavior of the existing attacker.

[0073] The feasibility of constructing a time series analysis model for network attack behavior clues lies in the fact that the attack behavior of an attacker is predictable. For example, when an attacker uses a penetration scanning tool to perform a port scan on a target system and the characteristics of the penetration scanning tool are captured by a security device, then the attacker will not only launch a few attack behaviors in a short period of time, but there will be a batch of vulnerability scanning and verification behaviors. Then, security technicians can predict that the attacker will launch a large number of attacks in a short period of time, triggering a security device alarm. Then, rapid disposal can be carried out for this attacker, blocking the attacker's attack attempt path and increasing the attacker's detection cost.

[0074] To construct a time series analysis model, it is first necessary to determine the research object. Network attack behavior analysis generally takes the perspective of the same attack behavior initiator to determine whether a series of attack behaviors initiated by the initiator are malicious behaviors. Then, the object of time series model analysis is also the relevant alarm data of the same attack initiator.

[0075] Secondly, the prediction accuracy of the time series analysis model lies in the correlation between the selected analysis dependent variable and the final prediction result. Then, the selection of the dependent variable of the time series analysis model should follow the judgment criteria for network security against attack behavior analysis and judgment, mainly including dependent variables such as the number of attacks, attack time, attack target, attack IP threat intelligence, attack IP nature, attack IP geographical location, and attack behavior type, and these dependent variables are not related to each other.

[0076] After determining the relevant dependent variables, relevant time series analysis algorithms should be selected. Currently, the most basic classification of time series analysis algorithms is the additive model and the multiplicative model. When the periodicity does not change with the trend, the additive model is preferred. When the period changes with the trend, the multiplicative model is preferred. Of course, the multiplicative model and the additive model can be transformed into each other through the log function. When the training data does not show an obvious trend, both models can be considered synchronously, and the model algorithm with a smaller error can be selected. When determining the attack variables in network attack behavior, we found that other dependent variables except the attack time will not affect the cycle and trend changes. In other words, in the time series analysis model, the prediction result is only periodically related to the attack time. Therefore, the additive model is selected for the time series analysis model of network attack behavior clues.

[0077] The time series analysis model is trained by importing data, and finally a time series analysis model function that meets the network security behavior analysis and judgment scenario is obtained. The time series analysis model takes the same attacker as the perspective, uses parameters such as the number of attacks, attack time, attack target, attack IP threat intelligence, attack IP nature, attack IP geographical location, and attack behavior as the evaluation criteria, and uses the time series analysis algorithm as the means to finally realize the automated analysis and judgment application of network security attack behavior.

[0078] 2. Network Attack Response Automatic Orchestration Technology Based on SOAR

[0079] Determine the attack chain stage of the associated event behavior time series through the attack chain model, so as to effectively infer and form a complete attack behavior chain. On the basis of the attack behavior chain, match the security emergency response measure scripts that can solve the corresponding problems for the current attack behavior in a certain stage of the attack time series, and combine them to form a complete response strategy and SOAR automated security orchestration plan. The overall idea is as Figure 4 described.

[0080] 2.1 Network Attack Behavior Automatic Response Orchestration

[0081] Customize the automated response process according to the network attack behavior analysis model as the basic data source. The automated response process includes data source access, security alarm, work order management, and security orchestration automation related modules. The overall idea is as Figure 5 described.

[0082] Data source access module: Access the security device alarm data through the sys log log transmission interface and the API data interface, use analysis algorithms such as online analysis, transfer learning, and time series analysis to analyze and process the alarm data, construct an attack chain model, and access it as the basic data source into the automated response process.

[0083] Security Alert Module: Alarm management includes three functions: alarm triage, alarm investigation, and alarm response. Alarm triage can automatically aggregate alarm information on the one hand, reducing the number of alarms that need to be viewed. Alarm investigation refers to the supplementary investigation and analysis of alarm information, eliminating false alarms, and turning vague and low-quality alarms into high-quality and valuable alarms. Through alarm perspective, comprehensive visibility of alarm information is obtained, and the relevant information of this alarm is presented as clearly and accurately as possible to facilitate judgment. The alarm response module interfaces with the security orchestration automation module to achieve alarm response matching.

[0084] Work Order Management Module: Through work order flow and work order handling, it realizes the work order processing of automated response, forming a record of the automated handling process of network attack behaviors, which is convenient for verification and review afterwards.

[0085] Security Orchestration Automation Module: It realizes the editing and maintenance of playbooks, as well as the management of applications and actions. The core of security orchestration and automation is the playbook library and the action library. These libraries can be called at any time by functions such as security analysis, alarm management, and case management. Different playbooks are defined and stored in the playbook library according to the handling methods of existing different attack types. According to the existing security protection measures of the network security protection system, IP blocking actions for Neusoft Firewall, Deep Security Firewall, and Sangfor Firewall are defined.

[0086] 3. Implementation of Automated Orchestration and Disposal Script for Network Attack Behaviors:

[0087] The automated orchestration and disposal script for network attack behaviors is jointly implemented by the security alert device sys log access, security alert device alarm aggregation, alarm attack chain tracking, SOAR automated response strategy configuration, and automated response strategy center

[0088] 3.1 Security Alert Device sys log Access

[0089] It supports defining sys log parsing rules to receive the original sys log log data transmitted by security devices, and processes the original logs using mutate, kv, and grok syntax to sort out and output basic alarm information in a unified format, realizing the unified preprocessing of various log rules.

[0090] It supports customizing multiple sys log access templates, and selects different sys log parsing templates according to the sys log logs of different security devices, realizing the adaptability diversity of data source access.

[0091] 3.2 Security Alert Device Alarm Aggregation

[0092] Support the data merging and display of the data processed by the sys log access template. The displayed data is the associated aggregation analysis data. The data aggregation dimension is the security alert IP. Display the key technical analysis information of the security alert, such as: attack time, earliest attack time, alert source, destination IP, attack type, number of attacks, etc. Through the associated aggregation analysis of security alerts, solve the problems of messy security devices and scattered security alerts.

[0093] 3.3. Alarm Attack Chain Tracking

[0094] Through the log merging of different security alert devices, realize the network attack chain analysis model from the perspective of the same attack IP, analyze and judge different types of attack behaviors generated by different security devices, and analyze the attacker's attack intention and attack method from the perspective of the overall network attack behavior, and construct the entire attack chain of the attacker.

[0095] 3.4. SOAR Automated Response Strategy Configuration

[0096] Support custom response strategy configuration. Analyze the dependent variable content of the attack chain model such as the number of attacks, attack time, attack target, threat intelligence of the attack IP, nature of the attack IP, geographical location of the attack IP, and type of attack behavior, judge the threat level of the attack behavior, and customize the network attack IP ban disposal duration according to the threat level.

[0097] 3.5. SOAR Automated Response Strategy Center

[0098] Support the start / stop and priority configuration of custom automated response strategies, and flexibly respond to automated disposal scenarios under different network attack behaviors through the combination of different scripts.

[0099] 4. Generalized Script Instances of Network Attack Behaviors

[0100] The following is the automated monitoring and disposal process of the alarm by the SOAR automated response strategy center. The security alert center plays the role of "supervisor", the strategy center plays the role of "decision maker", and the security device access control action plays the role of "executor". The security alert center inputs the processed alarm log, and the strategy center will make the following judgments:

[0101] Whether the threat alert IP is in the internal business whitelist. If so, end the matching. If not, match the highest priority policy script;

[0102] The highest priority policy match will match the user-defined conditions one by one. For example, whether the threat alert IP is an overseas IP. If so, continue to match the next condition. If not, match the next priority policy script;

[0103] If the alarm IP is an overseas IP, then determine whether the number of alarms in the attack chain model of the IP exceeds 10 times within ten minutes. If so, the highest priority policy script is met, and the action library is called to perform the IP ban for 30 minutes (the duration is customizable), and the match ends. If not, the next priority policy script is matched;

[0104] When the highest priority policy is not met, the second priority policy script is matched. The policy center determines whether the threat alarm IP satisfies the threat intelligence and is malicious. If the IP intelligence is malicious, the next condition is determined. If not, the next priority policy script is matched.

[0105] If the alarm IP threat intelligence is malicious, determine whether the IP has ever launched a command execution attack in the attack chain model of the IP. If there is an attack record, the second priority policy script is met, and the action library is called to perform the IP ban for 10 minutes (the duration is customizable), and the matching ends. If it is not met, the next priority policy script is matched;

[0106] And so on..., such as Figure 6 shown.

[0107] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention, rather than to limit the scope of protection of the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the essence and scope of the technical solution of the present invention.

Claims

1. A method for orchestrating defense automation processes based on SOAR, characterized in that: It includes the following steps: s1, Automatically analyze, judge, and obtain evidence of network attack behaviors based on the open set transfer learning algorithm; Carry out automated analysis around the attacked object using online analytical processing, conduct online analysis of the basic data sources with the security device logs of the system and threat intelligence information, and obtain evidence of associated events for the target IP and its associated IPs of key network attack events; Utilize the ability of the open set transfer algorithm to separate unknown samples from known samples in the target domain, and combine with the evidence points related to key events extracted from the judgment and evidence collection to complete the construction of the attack chain model; Based on the time axis, string together the clues obtained from the evidence collection for the attack behaviors around key events, establish a chronological relationship model of the clues, and obtain effective clues for key attack events; The open set transfer learning algorithm is used to identify whether the t-th attack behavior type in the target dataset is labeled as category c , and since the above attack behavior type dataset belongs to the open set, a parameter is introduced to mark whether the t-th sample is an unknown attack behavior type. Then , the constraint function is obtained according to the open set learning transfer algorithm: There are two constraints in the constraint function: The first constraint: For any attack behavior type sample of the target data set, either , or . For the samples of the target data set, there are only two cases. One is that it belongs to the known attack behavior types in the source data set, or the sample belongs to unknown attack behavior types; Second constraint: For any known type of network attack behavior, there must be at least one , and there will not be a shared category of known attack behavior types that cannot be found in the target dataset; The overall learning idea is that the existing known attack behavior type data set and the target data set are continuously mapped and iterated until the two data sets converge to a certain value. Without adding other security devices, the richness of attack behavior types can be guaranteed. When new security devices are added, the new attack behavior types introduced will be learned into the existing data set, and the network attack behavior types with self-learning characteristics become an important part of constructing the attack chain model; s2, The technology of automatically orchestrating network attack responses based on SOAR. Determine the attack chain stages of the associated event behaviors in chronological order through the attack chain model, thereby effectively inferring and forming a complete attack behavior chain. Based on the attack behavior chain, match the security emergency response measure scripts that can solve the corresponding problems for the current attack behavior at a certain stage in the attack time sequence, and combine them to form a complete response strategy and SOAR automated security orchestration plan; s3, The defense automation process orchestration script based on SOAR.

2. The method for orchestrating defense automation processes based on SOAR according to claim 1, characterized in that: The online analysis and processing of the basic data source includes a data collection layer, a data storage layer, a data analysis layer, and a data presentation layer; The data collection layer collects power security device alarm data through syslog log transmission and API data interface methods; The data storage layer is responsible for storing the preprocessed security device alarm data with a unified specification into MYSQL; The data analysis layer designs a data analysis scheme based on the idea of online analytical processing, and divides the network attack behavior alarm data set into three dimensions, namely the time dimension, the object dimension, and the behavior dimension; The time dimension has a total of three dimension levels: year, month, and day; The object dimension has two dimension levels: the attacked object and the target object, and the behavior dimension has only one dimension level, that is, the security device alarm attack behavior; The data presentation layer integrates statistical query, auxiliary decision-making, and quick screening function components, which can provide relatively accurate analysis and judgment decision support for enterprise management. At the same time, it also provides an early warning function for various security device monitoring alarm data, and conducts all-round monitoring of power security device alarm data.

3. The method for orchestrating defense automation processes based on SOAR according to claim 1, characterized in that: An attack chain model is built using an open-set transfer learning algorithm. First, the source dataset and the target dataset are extracted and analyzed. The source dataset is the label of existing known network attack behaviors, while the content of the labels in the target dataset is not exactly the same as that in the source dataset. The target dataset will include newly emerging unknown attack behaviors in the future. The categories in the target dataset that exceed those in the source dataset will include two parts: one part is the attack behavior types of newly connected devices; The other part is the newly added attack behavior types not included in the existing source dataset, and this part belongs to the categories not included in the source data.

4. A defense automation process orchestration method based on SOAR according to claim 1, characterized in that: A temporal analysis model of network attack behavior clues is constructed, and data from a past period is used to predict information in a future period, including continuous prediction and discrete prediction. In the scenario of network security behavior analysis and judgment, the subsequent attack actions of attackers are predicted based on the existing behaviors of existing attackers.

5. A defense automation process orchestration method based on SOAR according to claim 4, characterized in that: Automated response orchestration for network attack behaviors. Based on the network attack behavior analysis model as the basic data source, an automated response process is customized. The automated response process includes modules related to data source access, security alert, work order management, and security orchestration automation.

6. A defense automation process orchestration method based on SOAR according to claim 1, characterized in that: Automated orchestration and disposal script for network attack behaviors is jointly implemented by syslog access of security alert devices, alert aggregation of security alert devices, attack chain tracking of alerts, SOAR automated response policy configuration, and the automated response policy center.

Citation Information

Patent Citations

  • Security arrangement and automatic response method, device and system aiming at APT attack

    CN114070629A

  • Methods and systems for analyzing cybersecurity threats

    US10685293B1