Network security threat assessment method, device and equipment and readable storage medium
By constructing a cybersecurity knowledge graph and a security reasoning model, threat assessment reports are automatically generated, solving the problem of low efficiency in cybersecurity threat assessment and achieving efficient and accurate cybersecurity threat assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE GROUP ZHEJIANG
- Filing Date
- 2021-08-31
- Publication Date
- 2026-04-28
AI Technical Summary
Cybersecurity threat assessment is inefficient, requires a large amount of manual analysis, and is very difficult. Existing technologies are insufficient for efficient cybersecurity threat assessment.
A knowledge graph is constructed based on a cybersecurity knowledge system. By combining network asset information and alarm information, a cybersecurity threat knowledge graph is generated. Threat assessment is performed using a security reasoning model, and a threat assessment report is automatically generated.
It reduces manual operation costs, improves the efficiency and accuracy of threat assessment reports, and achieves automation and comprehensiveness in cybersecurity threat assessment.
Smart Images

Figure CN115733646B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a network security threat assessment method, apparatus, device, and readable storage medium. Background Technology
[0002] With the rapid development of network technology, the internet is widely used in people's lives and work. Network security maintenance is an important component of network technology, providing users with a safe and stable network environment and serving as a crucial guarantee for the smooth operation of various network-based activities.
[0003] Currently, mature threat detection solutions and systems have been developed for known cybersecurity threats, covering multiple aspects. Cybersecurity threat assessment primarily utilizes the detection results (including identified network attacks and corresponding alerts) to perform tasks such as alert information screening, network asset correlation analysis, and threat assessment by security personnel. However, with the ever-increasing number of network assets and the growing number and types of threats, the workload and difficulty of manual analysis and assessment are increasing, leading to low efficiency in cybersecurity threat assessment.
[0004] The above content is only used to help understand the technical solution of the present invention and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main objective of this invention is to provide a method, apparatus, device, and readable storage medium for network security threat assessment, aiming to solve the technical problem of low efficiency in network security threat assessment.
[0006] To achieve the above objectives, the present invention provides a network security threat assessment method, which includes the following steps:
[0007] A cybersecurity knowledge graph is determined based on a cybersecurity knowledge system, wherein the cybersecurity knowledge graph includes cybersecurity threat entities, the relationships between cybersecurity threat entities, and the attribute information of cybersecurity threat entities;
[0008] Obtain network asset information corresponding to the existing network asset management system, obtain the IP address or port information of each network asset in the network asset information, determine the first access relationship between network assets based on the IP address or port information, network security domain information and firewall policy configuration rules, and determine the first connection relationship between network assets based on the calling relationship and ownership relationship between network assets in the network asset information.
[0009] Based on the attribute information of the network assets, the first accessibility relationship, and the first connection relationship in the network asset information, a network asset topology map is determined;
[0010] Obtain alarm information corresponding to network security threats, generate a network security threat knowledge graph based on the alarm information, the network security knowledge graph, and the network asset topology graph, and determine the threat assessment report corresponding to the network security threat knowledge graph.
[0011] Furthermore, the step of determining the threat assessment report corresponding to the network security threat knowledge graph includes:
[0012] Based on a security reasoning model and a historical network security threat knowledge graph set, a network security threat assessment is performed on the network security threat knowledge graph to obtain a threat assessment report corresponding to the network security threat knowledge graph. The threat assessment report includes attack routes, predicted attack routes, and risk values of threat attacks.
[0013] Furthermore, the step of conducting a cybersecurity threat assessment on the cybersecurity threat knowledge graph based on the security reasoning model and the historical cybersecurity threat knowledge graph set, and obtaining a threat assessment report corresponding to the cybersecurity threat knowledge graph, includes:
[0014] Obtain the target node in the network security threat knowledge graph, and determine the attack route corresponding to the target node based on the security reasoning model and the historical network security threat knowledge graph set;
[0015] Based on the attack route and the network security threat knowledge graph, a predicted attack route is obtained.
[0016] Based on the attack routes, the security inference model of the predicted attack routes, and the historical network security threat knowledge graph set, the risk value of the threat attack corresponding to each attack route is determined.
[0017] A threat assessment report is generated based on the attack route, the predicted attack route, and the risk value of the threat attack.
[0018] Furthermore, the step of generating a network security threat knowledge graph based on the alarm information, the network security knowledge graph, and the network asset topology graph includes:
[0019] Based on the network security knowledge graph, the threat attack entities, network asset entities and connection relationships corresponding to the alarm information are determined, and an initial network security threat knowledge graph is determined based on the threat attack entities, network asset entities and connection relationships.
[0020] In the network asset topology graph, obtain the associated network assets corresponding to each network asset entity. Based on the network asset entity and the associated network assets, determine the asset subgraph corresponding to each network asset entity, wherein the root node of the asset subgraph is the network asset entity.
[0021] For each asset subgraph, the asset subgraph is traversed. When the attribute information of the threat attack entity matches the attribute information of the currently traversed network asset, a child node of the network asset entity corresponding to the asset subgraph is added to the initial network security threat knowledge graph based on the currently traversed network asset. The connection relationship between the threat attack entity and the currently traversed network asset is set in the initial network security threat knowledge graph, and the currently traversed network asset is added to the threat-related asset set.
[0022] Based on the network security knowledge graph, obtain the set of associated threat attack entities corresponding to the threat attack entity, and determine the causal relationship between each threat attack entity in the set of associated threat attack entities;
[0023] Identify the threat entities in the set of associated threat entities that are associated with network assets in the set of threat-related assets, and add the nodes corresponding to the threat entities to the initial network security threat knowledge graph to obtain the network security threat knowledge graph.
[0024] Furthermore, the step of obtaining alarm information corresponding to network security threats includes:
[0025] Obtain network security threat alert information, perform filtering operations on the network security threat alert information, and obtain filtered network security threat alert information;
[0026] Identify the actual threats and attacks in the filtered network security threat alerts, and use these actual threats and attacks as the alert information.
[0027] Furthermore, the cybersecurity threat assessment method also includes:
[0028] Periodically obtain asset change information corresponding to the network asset information based on the network asset management system;
[0029] Obtain the second accessibility and second connection relationship of the network assets corresponding to the asset change information;
[0030] The network asset topology is updated based on the attribute information of the network assets, the second accessibility relationship, and the second connection relationship in the asset change information.
[0031] Furthermore, the cybersecurity threat assessment method also includes:
[0032] Periodically acquire cybersecurity threat intelligence data sources and obtain threat intelligence data from the cybersecurity threat intelligence data sources;
[0033] The threat intelligence data is filtered based on a cybersecurity knowledge dictionary to obtain filtered threat intelligence data;
[0034] The first threat intelligence data is processed based on the preset attribute mapping relationship to obtain the first data, wherein the first threat intelligence data is the structured data in the filtered threat intelligence data;
[0035] Supervised learning is performed on the first threat intelligence data to obtain the second data, wherein the second threat intelligence data consists of semi-structured data and unstructured data from the filtered threat intelligence data;
[0036] The cybersecurity knowledge graph is updated based on the first data and the second data.
[0037] Furthermore, to achieve the above objectives, the present invention also provides a network security threat assessment device, the network security threat assessment device comprising:
[0038] The first determining module is used to determine a network security knowledge graph based on a network security knowledge system, wherein the network security knowledge graph includes network security threat entities, the relationships between network security threat entities, and the attribute information of network security threat entities;
[0039] The acquisition module is used to acquire network asset information corresponding to the existing network asset management system, acquire the IP address or port information of each network asset in the network asset information, determine the first access relationship between network assets based on the IP address or port information, network security domain information and firewall policy configuration rules, and determine the first connection relationship between network assets based on the calling relationship and ownership relationship between network assets in the network asset information.
[0040] The second determining module is used to determine the network asset topology based on the attribute information of the network assets in the network asset information, the first accessibility relationship, and the first connection relationship;
[0041] The assessment module is used to obtain alarm information corresponding to network security threats, generate a network security threat knowledge graph based on the alarm information, the network security knowledge graph, and the network asset topology graph, and determine the threat assessment report corresponding to the network security threat knowledge graph.
[0042] In addition, to achieve the above objectives, the present invention also provides a network security threat assessment device, which includes: a memory, a processor, and a network security threat assessment program stored in the memory and executable on the processor. When the network security threat assessment program is executed by the processor, it implements the steps of the aforementioned network security threat assessment method.
[0043] In addition, to achieve the above objectives, the present invention also provides a readable storage medium storing a network security threat assessment program, which, when executed by a processor, implements the steps of the aforementioned network security threat assessment method.
[0044] This invention establishes a network security knowledge graph based on a network security knowledge system. This knowledge graph includes network security threat entities, relationships between these entities, and attribute information of the threat entities. Next, it acquires network asset information from an existing network asset management system, obtaining the IP addresses or port information of each network asset. Based on these IP addresses or port information, network security domain information, and firewall policy configuration rules, it determines the first accessibility relationship between network assets and the first connection relationship based on the calling and attribution relationships between them. Then, based on the attribute information of the network assets, the first accessibility relationship, and the first connection relationship, it determines a network asset topology. Finally, it acquires alarm information corresponding to network security threats. Based on the alarm information, the network security knowledge graph, and the network asset topology, it generates a network security threat knowledge graph and determines the corresponding threat assessment report. This achieves automatic generation of threat assessment reports, significantly reducing manual operation costs and improving the efficiency of outputting threat assessment reports. Furthermore, by using the network security knowledge graph and network asset topology for threat assessment, it improves the accuracy and comprehensiveness of network security assessments. Attached Figure Description
[0045] Figure 1 This is a schematic diagram of the structure of a network security threat assessment device in the hardware operating environment involved in the embodiments of the present invention;
[0046] Figure 2 This is a flowchart illustrating the first embodiment of the network security threat assessment method of the present invention;
[0047] Figure 3 This is a functional module diagram of an embodiment of the network security threat assessment device of the present invention.
[0048] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0049] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0050] like Figure 1 As shown, Figure 1 This is a schematic diagram of the structure of a network security threat assessment device in the hardware operating environment involved in the embodiments of the present invention.
[0051] In this embodiment of the invention, the network security threat assessment device can be a PC. For example... Figure 1 As shown, the network security threat assessment device may include: a processor 1001, such as a CPU; a network interface 1004; a user interface 1003; a memory 1005; and a communication bus 1002. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen or an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as a disk drive. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0052] Optionally, cybersecurity threat assessment equipment may also include cameras, RF (Radio Frequency) circuits, sensors, audio circuits, WiFi modules, and so on. Of course, cybersecurity threat assessment equipment may also be equipped with other sensors such as barometers, hygrometers, thermometers, and infrared sensors, which will not be elaborated upon here.
[0053] Those skilled in the art will understand that Figure 1 The terminal structure shown does not constitute a limitation on cybersecurity threat assessment equipment and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0054] like Figure 1 As shown, the memory 1005, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a network security threat assessment program.
[0055] exist Figure 1In the terminal shown, the network interface 1004 is mainly used to connect to the backend server and communicate with the backend server; the user interface 1003 is mainly used to connect to the client (user terminal) and communicate with the client; and the processor 1001 can be used to call the network security threat assessment program stored in the memory 1005.
[0056] In this embodiment, the network security threat assessment device includes: a memory 1005, a processor 1001, and a network security threat assessment program stored in the memory 1005 and executable on the processor 1001. When the processor 1001 calls the network security threat assessment program stored in the memory 1005, it executes the steps of the network security threat assessment methods in the following embodiments.
[0057] This invention also provides a method for assessing network security threats, referring to... Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the network security threat assessment method of the present invention.
[0058] In this embodiment, the network security threat assessment method includes the following steps:
[0059] Step S101: Determine a network security knowledge graph based on the network security knowledge system, wherein the network security knowledge graph includes network security threat entities, the relationships between network security threat entities, and the attribute information of network security threat entities;
[0060] In this embodiment, a cybersecurity knowledge graph is determined based on a cybersecurity knowledge system. Specifically, based on the cybersecurity knowledge system and the knowledge of security domain experts, a top-down approach is used to construct the cybersecurity knowledge graph, which is then stored in a database. The database stores cybersecurity threat entities, their attribute information, and the relationships between them. Cybersecurity threat entities are mainly divided into two categories: threat attacks and network assets.
[0061] Threat attacks can be categorized by attack type into vulnerability exploitation, weak password attacks, botnets / worms, DDoS attacks, cryptojacking, command injection, ransomware, and more. Different types of threat attacks can be further subdivided based on attack codenames or versions. Threat attack entities primarily include attributes such as attack target, attack cause, attack pattern, relevant cases, impact, preventative measures, and incident response.
[0062] Network assets are mainly classified according to types such as systems, ports, services, and applications. Network assets include attribute information such as operating system type and version, port number, service name, application name and version, domain name, and IP address.
[0063] The relationships between cybersecurity threat entities can be mainly divided into two categories: one is the relationship between threat attacks and network assets, where network assets are the targets of threat events and the two are related; the other is the relationship between different threat attacks, where different threat events have a causal relationship of attack sequence.
[0064] Step S102: Obtain network asset information corresponding to the existing network asset management system, obtain the IP address or port information of each network asset in the network asset information, determine the first accessibility relationship between network assets based on the IP address or port information, network security domain information and firewall policy configuration rules, and determine the first connection relationship between network assets based on the calling relationship and ownership relationship between network assets in the network asset information.
[0065] In this embodiment, network asset information is first obtained based on the existing network asset management system. Network assets in this information are mainly categorized into terminals, applications, and services. Applications and services run on terminals. Terminals mainly include networked hosts, servers, and devices. Applications mainly include system-provided programs and user-installed programs, such as database software, office software, and antivirus software. Services include web services, FTP, remote desktop, VNC, and API interface services. The attribute information corresponding to a terminal mainly includes its name, system type, system version, patch information, IP address, IP group, firewall rules, running status, responsible person, affiliation, running services, and installed programs. The attribute information corresponding to an application mainly includes its application name, version number, called services / components, port, running status, responsible person, and affiliation. The attribute information corresponding to a service mainly includes its service name, type, version, running status, port number, domain name, responsible person, affiliation, and called services.
[0066] Next, the IP address or port information of each network asset in the network asset information is obtained. Based on the IP address or port information, network security domain information, and firewall policy configuration rules, the first accessibility relationship between network assets is determined. This first accessibility relationship includes data transmission relationships between network assets. Then, based on the calling and attribution relationships between network assets in the network asset information, the first connection relationship between network assets is determined. This first connection relationship includes the calling and attribution relationships between network assets; for example, an application on terminal A may belong to a service provided by terminal B.
[0067] Step S103: Based on the attribute information of the network assets in the network asset information, the first accessibility relationship, and the first connection relationship, determine the network asset topology map;
[0068] In this embodiment, when the first connection relationship and the first access relationship are obtained, a network asset topology map is determined based on the attribute information of the network assets, the first access relationship, and the first connection relationship. Specifically, the nodes of the network asset topology map are each network asset, the attribute information of the nodes is the attribute information of the network assets, and each node in the network asset topology map is connected through the first access relationship and the first connection relationship.
[0069] Step S104: Obtain alarm information corresponding to network security threats; generate a network security threat knowledge graph based on the alarm information, the network security knowledge graph, and the network asset topology graph; and determine the threat assessment report corresponding to the network security threat knowledge graph.
[0070] In this embodiment, alarm information corresponding to network security threats is first obtained. Specifically, alarm information sent by all network security detection systems and other channels is collected, and the collected information is processed to obtain alarm information corresponding to network security threats.
[0071] Then, based on the alarm information, the network security knowledge graph, and the network asset topology map, a network security threat knowledge graph is generated, and a threat assessment report is determined based on the network security threat knowledge graph. This can automatically generate threat assessment reports, greatly reducing manual operation costs and improving the efficiency of outputting threat assessment reports.
[0072] Further, in one embodiment, step S104 includes:
[0073] Based on a security reasoning model and a historical network security threat knowledge graph set, a network security threat assessment is performed on the network security threat knowledge graph to obtain a threat assessment report corresponding to the network security threat knowledge graph. The threat assessment report includes attack routes, predicted attack routes, and risk values of threat attacks.
[0074] In this embodiment, a set of historical cybersecurity threat knowledge graphs and a security reasoning model (security expert reasoning model) are first obtained. A cybersecurity threat assessment model is then constructed based on the security reasoning model. The cybersecurity threat assessment model is trained based on the set of historical cybersecurity threat knowledge graphs to obtain a target model. The cybersecurity threat knowledge graph is then input into the target model for model training to obtain a threat assessment report corresponding to the cybersecurity threat knowledge graph. Finally, the model is used to perform threat assessment on the cybersecurity threat knowledge graph, thereby further improving the efficiency of cybersecurity assessment.
[0075] The network security threat assessment method proposed in this embodiment determines a network security knowledge graph based on a network security knowledge system. This knowledge graph includes network security threat entities, relationships between these entities, and attribute information of the threat entities. Next, it acquires network asset information corresponding to an existing network asset management system, obtaining the IP addresses or port information of each network asset. Based on the IP addresses or port information, network security domain information, and firewall policy configuration rules, it determines the first accessibility relationship between network assets and the first connection relationship based on the calling and attribution relationships between network assets. Then, based on the attribute information of the network assets, the first accessibility relationship, and the first connection relationship, it determines a network asset topology. Finally, it acquires alarm information corresponding to network security threats. Based on the alarm information, the network security knowledge graph, and the network asset topology, it generates a network security threat knowledge graph and determines the corresponding threat assessment report. This achieves automatic generation of threat assessment reports, significantly reducing manual operation costs and improving the efficiency of outputting threat assessment reports. Furthermore, by using the network security knowledge graph and network asset topology for threat assessment, it improves the accuracy and comprehensiveness of network security assessments.
[0076] Based on the first embodiment, a second embodiment of the network security threat assessment method of the present invention is proposed. In this embodiment, step S104 includes:
[0077] Step S201: Obtain the target node in the network security threat knowledge graph, determine the attack route corresponding to the target node based on the security reasoning model and the historical network security threat knowledge graph set, and determine the source tracing attack route map based on the attack route.
[0078] Step S202: Based on the attack route and the network security threat knowledge graph, a prediction is made to obtain the predicted attack route;
[0079] Step S203: Based on the attack route, the security reasoning model of the predicted attack route, and the historical network security threat knowledge graph set, determine the risk value of the threat attack corresponding to each attack route;
[0080] Step S204: Generate a threat assessment report based on the attack route, the predicted attack route, and the risk value of the threat attack.
[0081] In this embodiment, a historical network security threat knowledge graph set and a security inference model (security expert inference model) are first acquired. A network security threat assessment model is then constructed based on the security inference model. This model is trained using the historical network security threat knowledge graph set to obtain a target model. The network security threat knowledge graph is input into the target model for training. The target model acquires target nodes and the causal relationships between nodes within the network security threat knowledge graph. These target nodes include affected network asset nodes and threat attack nodes. The target model determines the possible attack routes (all possible attack routes) corresponding to the target nodes based on the target nodes and the causal relationships between them, and calculates the confidence level of each possible attack route. The attack route is then determined based on the confidence level; for example, routes with a confidence level greater than a preset value are selected as attack routes. Simultaneously, a source tracing attack route map can be determined based on the attack routes. The attack route map allows for the rapid location of all network assets affected by threat attacks, listing the reasons for the attacks, the responsible parties, and the necessary emergency measures.
[0082] Upon obtaining the attack path, the target model makes predictions based on the attack path and the network security threat knowledge graph. Specifically, the target model traces backward along the attack path, analyzes all possible subsequent attack paths, and determines the predicted attack path based on the confidence level of each possible subsequent attack path. Based on the predicted attack path, it locates potentially affected network assets and lists the reasons for the impact, the likelihood of impact, the responsible party, and defensive measures.
[0083] Next, based on the attack routes, the security inference model of the predicted attack routes, and the historical network security threat knowledge graph set, the risk value of the threat attack corresponding to each attack route is determined. Specifically, the template model analyzes and evaluates the importance, severity of impact, threat level, threat spread range, losses already caused, and potential impact of network assets involved in the entire threat attack chain (attack routes and predicted attack routes), outputs the evaluation results for each item, and performs a weighted summation based on the evaluation results of each item to obtain the risk value of the threat attack. At the same time, the security event can also be classified based on the risk value.
[0084] Finally, based on the attack routes, the predicted attack routes, and the risk values of the threats, a threat assessment report is generated. According to the attack routes in the threat assessment report, security personnel can promptly notify relevant personnel to take emergency response measures, truly achieving comprehensive threat elimination. According to the predicted attack routes in the threat assessment report, security personnel can promptly notify relevant personnel to initiate preventative measures, curbing the further spread of threats.
[0085] The cybersecurity threat assessment method proposed in this embodiment obtains target nodes in a cybersecurity threat knowledge graph, determines the attack routes corresponding to the target nodes based on the security inference model and a historical cybersecurity threat knowledge graph set, and determines a source tracing attack route map based on the attack routes. Then, based on the attack routes and the cybersecurity threat knowledge graph, a predicted attack route is obtained. Next, based on the attack routes, the predicted attack routes, the security inference model, and the historical cybersecurity threat knowledge graph set, the risk value of the threat attack corresponding to each attack route is determined. Finally, based on the attack routes, the predicted attack routes, and the risk values of the threat attacks, a threat assessment report is generated. This method can accurately identify the latest cybersecurity threat attack sources, improving the accuracy of cybersecurity threat identification. Based on the attack routes in the threat assessment report, security personnel can promptly notify relevant personnel to take emergency response measures, truly achieving comprehensive threat attack elimination. Based on the predicted attack routes in the threat assessment report, security personnel can promptly notify relevant personnel to initiate preventative measures to curb the further spread of threat attacks.
[0086] Based on the first embodiment, a third embodiment of the network security threat assessment method of the present invention is proposed. In this embodiment, step S104 includes:
[0087] Step S301: Based on the network security knowledge graph, determine the threat attack entities, network asset entities and connection relationships corresponding to the alarm information, and determine the initial network security threat knowledge graph based on the threat attack entities, network asset entities and connection relationships;
[0088] Step S302: Obtain the associated network assets corresponding to each network asset entity in the network asset topology map, and determine the asset sub-graph corresponding to each network asset entity based on the network asset entity and the associated network assets.
[0089] Step S303: For each asset subgraph, traverse the asset subgraph. When the attribute information of the threat attack entity matches the attribute information of the currently traversed network asset, add the child node of the network asset entity corresponding to the asset subgraph to the initial network security threat knowledge graph based on the currently traversed network asset. Set the connection relationship between the threat attack entity and the currently traversed network asset in the initial network security threat knowledge graph, and add the currently traversed network asset to the threat-related asset set.
[0090] Step S304: Based on the network security knowledge graph, obtain the set of associated threat attack entities corresponding to the threat attack entity, and determine the causal relationship between each threat attack entity in the set of associated threat attack entities;
[0091] Step S305: Identify the threat attack entities in the associated threat attack entity set that are associated with network assets in the threat-related asset set, and add the nodes corresponding to the threat attack entities to the initial network security threat knowledge graph to obtain the network security threat knowledge graph.
[0092] In this embodiment, based on the network security knowledge graph, the threat attack entities, network asset entities, and connection relationships corresponding to the alarm information are determined, and an initial network security threat knowledge graph is determined based on the threat attack entities, network asset entities, and connection relationships. Specifically, alarm feature information of the alarm information is obtained, and based on the network security knowledge graph, threat attack entities, network asset entities, and connection relationships matching the feature information are queried. Simultaneously, the node attributes of each node in the initial network security threat knowledge graph can be updated according to the alarm feature information. Specifically, based on the alarm feature information, it is determined whether a node has been affected by an attack; in the initial network security threat knowledge graph, the `isAttacked` attribute of nodes affected by an attack is marked as 1, otherwise marked as 0.
[0093] When the initial network security threat knowledge graph is obtained, the associated network assets corresponding to each network asset entity in the initial network security threat knowledge graph are obtained in the network asset topology graph. Based on the network asset entities and associated network assets, the asset subgraphs corresponding to each network asset entity are determined. The number of asset subgraphs is consistent with the number of network asset entities in the initial network security threat knowledge graph.
[0094] Next, for each asset subgraph, the asset subgraph is traversed to obtain the currently traversed network assets in the asset subgraph. When the attribute information of the threat attack entity matches the attribute information of the currently traversed network assets, a child node of the network asset entity corresponding to the asset subgraph is added to the initial network security threat knowledge graph based on the currently traversed network assets. The currently traversed network assets are used as child nodes of the network asset entities, and a connection relationship between the threat attack entity and the currently traversed network assets is set in the initial network security threat knowledge graph. The currently traversed network assets are then added to the threat-related asset set.
[0095] Once the asset subgraph has been traversed and all asset subgraphs have been traversed, the updated initial cybersecurity threat knowledge graph and the set of each threat-related asset are obtained.
[0096] Based on the network security knowledge graph, obtain the set of associated threat attack entities corresponding to the threat attack entity, and determine the causal relationship between each threat attack entity in the set of associated threat attack entities; determine the threat attack entities in the set of associated threat attack entities that are associated with network assets in the set of threat-related assets, and add the nodes corresponding to the threat attack entities in the initial network security threat knowledge graph to obtain the network security threat knowledge graph. Specifically, add the nodes corresponding to the threat attack entities in the updated initial network security threat knowledge graph to obtain the network security threat knowledge graph.
[0097] The network security threat assessment method proposed in this embodiment determines the threat attack entity, network asset entity, and connection relationship corresponding to the alarm information based on the network security knowledge graph, and determines an initial network security threat knowledge graph based on the threat attack entity, network asset entity, and connection relationship. Then, it obtains the associated network assets corresponding to each network asset entity in the network asset topology graph, and determines the asset subgraph corresponding to each network asset entity based on the network asset entity and associated network assets. For each asset subgraph, it traverses the asset subgraph, and when the attribute information of the threat attack entity matches the attribute information of the currently traversed network asset, it adds a child node of the network asset entity corresponding to the asset subgraph to the initial network security threat knowledge graph based on the currently traversed network asset. Finally, it sets the threat attack entity and the current... The process involves iterating through the connections between network assets and adding the currently traversed network assets to the threat-related asset set. Then, based on the network security knowledge graph, it obtains the associated threat entity set corresponding to the threat entity and determines the causal relationships between each threat entity in the associated threat entity set. Finally, it identifies the threat entities in the associated threat entity set that are associated with network assets in the threat-related asset set, and adds the corresponding nodes to the initial network security threat knowledge graph to obtain the network security threat knowledge graph. This method can accurately obtain the network security threat knowledge graph based on alarm information, the network security knowledge graph, and the network asset topology graph, further improving the efficiency of outputting threat assessment reports. Simultaneously, threat assessment using the network security knowledge graph and the network asset topology graph improves the accuracy and comprehensiveness of network security assessments.
[0098] Based on the first embodiment, a fourth embodiment of the network security threat assessment method of the present invention is proposed. In this embodiment, step S104 includes:
[0099] Step S401: Obtain network security threat alarm information, perform a filtering operation on the network security threat alarm information, and obtain filtered network security threat alarm information;
[0100] Step S402: Determine the real threat attack in the filtered network security threat alarm information, and use the real threat attack as the alarm information.
[0101] In this embodiment, alarm information sent by all network security detection systems and other channels is first collected to obtain network security threat alarm information. The sources of network security threat alarm information are mainly from three aspects: 1) Security alarm information detected by network security devices or network security detection systems. Security monitoring systems include: IDS detection system, webpage tampering detection system, DDoS monitoring system, botnet / worm monitoring system, DNS hijacking monitoring system, NSFOCUS full traffic monitoring system, EDR monitoring system, APT monitoring system, NSFOCUS scanner, Anheng scanner, etc. 2) Security incident information notification. 3) Security incident complaints.
[0102] For security alerts detected by network security devices or network security detection systems in network security threat alert information, a filtering operation is performed on the network security threat alert information. That is, the network security threat alert information is filtered through a preset policy library to obtain filtered network security threat alert information. The real threat attack in the filtered network security threat alert information is determined and the real threat attack is used as the alert information. The alert feature information of the alert information includes: threat elements, asset elements, time series and other information of the alert information.
[0103] Among them, for security incident reports and security incident complaints in network security threat alerts, after manual review and confirmation, information such as threat elements, asset elements, and time series involved in the security incident information is extracted.
[0104] The network security threat assessment method proposed in this embodiment obtains network security threat alarm information, filters the network security threat alarm information to obtain filtered network security threat alarm information, then identifies the real threat attack in the filtered network security threat alarm information, and uses the real threat attack as the alarm information, which can accurately obtain alarm information and further improve the efficiency of network security threat assessment.
[0105] Based on the above embodiments, a fifth embodiment of the network security threat assessment method of the present invention is proposed. In this embodiment, the network security threat assessment method further includes:
[0106] Step S501: Periodically obtain asset change information corresponding to the network asset information based on the network asset management system;
[0107] Step S502: Obtain the second accessibility relationship and the second connection relationship of the network asset corresponding to the asset change information;
[0108] Step S503: Update the network asset topology map based on the attribute information of the network assets, the second accessibility relationship, and the second connection relationship in the asset change information.
[0109] In this embodiment, asset change information from the network asset management system is periodically obtained. The asset change information includes changes, additions, or deletions of network assets, including device attribute information, installed applications and related program information, running services and related service information, etc.
[0110] Next, using the same method as for the first accessibility and first connection relationships, the second accessibility and second connection relationships of the network assets corresponding to the asset change information are obtained. Based on the attribute information of the network assets in the asset change information, the second accessibility and second connection relationships, the network asset topology map is updated. This includes deleting deleted network assets from the network asset topology map, deleting the accessibility and connection relationships between deleted network assets and other network assets in the network asset topology map, adding new network assets, and defining the accessibility and connection relationships between the new network assets and other network assets in the network asset topology map, thereby achieving periodic updates to the network asset topology map.
[0111] The network security threat assessment method proposed in this embodiment obtains asset change information corresponding to the network asset information at regular intervals based on the network asset management system; then, it obtains the second accessibility relationship and the second connection relationship of the network asset corresponding to the asset change information; and then, based on the attribute information of the network asset in the asset change information, the second accessibility relationship and the second connection relationship, it updates the network asset topology map, thereby realizing the regular updating of the network asset topology map and further improving the accuracy and efficiency of network security threat assessment.
[0112] Based on the above embodiments, a sixth embodiment of the network security threat assessment method of the present invention is proposed. In this embodiment, the network security threat assessment method further includes:
[0113] Step S601: Periodically acquire network security threat intelligence data sources and acquire threat intelligence data from the network security threat intelligence data sources, wherein the network security threat intelligence data sources include: online threat intelligence websites, vulnerability databases, and authoritative security threat reporting websites;
[0114] Step S602: Filter the threat intelligence data based on the network security knowledge dictionary to obtain the filtered threat intelligence data;
[0115] Step S603: Process the first threat intelligence data based on the preset attribute mapping relationship to obtain the first data, wherein the first threat intelligence data is the structured data in the filtered threat intelligence data;
[0116] Step S604: Supervised learning is performed on the first threat intelligence data to obtain the second data, wherein the second threat intelligence data consists of semi-structured data and unstructured data from the filtered threat intelligence data.
[0117] Step S605: Update the cybersecurity knowledge graph based on the first data and the second data.
[0118] In this embodiment, network security threat intelligence data sources are acquired periodically. These data sources include online threat intelligence websites, vulnerability databases, and authoritative security threat reporting websites. The time interval for acquiring network security threat intelligence data sources can be reasonably set, for example, the time interval can be set to one week, half a month, or one month.
[0119] When a cybersecurity threat intelligence data source is obtained, threat intelligence data is retrieved from that source, specifically using existing web scraping techniques. Then, the threat intelligence data is filtered based on a cybersecurity knowledge dictionary to remove irrelevant threat intelligence, resulting in the filtered threat intelligence data.
[0120] Next, the first threat intelligence data is processed based on the preset attribute mapping relationship, that is, the first threat intelligence data is matched according to the preset attribute mapping relationship to obtain the first data, which is the structured data in the filtered threat intelligence data.
[0121] Simultaneously, supervised learning is performed on the first threat intelligence data to obtain the second data. Specifically, NLP parsing is used to extract entity pairs from the second data, and entity features are extracted from the entities to obtain entity features. Based on the entity features, database data is associated with entity pairs to generate a variable table. Based on the variable table and the entity feature table, the relationship between cybersecurity threat entities in the second data is deduced.
[0122] Then, the cybersecurity knowledge graph is updated based on the first data and the second data to obtain a new cybersecurity knowledge graph.
[0123] The cybersecurity threat assessment method proposed in this embodiment acquires cybersecurity threat intelligence data sources periodically, and then filters the threat intelligence data based on a cybersecurity knowledge dictionary to obtain filtered threat intelligence data. Next, it processes the first threat intelligence data based on a preset attribute mapping relationship to obtain first data, and then performs supervised learning on the first threat intelligence data to obtain second data. Finally, it updates the cybersecurity knowledge graph based on the first and second data, achieving regular updates to the cybersecurity knowledge graph and further improving the accuracy and efficiency of cybersecurity threat assessment.
[0124] The present invention also provides a network security threat assessment device, with reference to Figure 3 The network security threat assessment device includes:
[0125] The first determining module 10 is used to determine a network security knowledge graph based on a network security knowledge system, wherein the network security knowledge graph includes network security threat entities, the relationships between network security threat entities, and the attribute information of network security threat entities;
[0126] The acquisition module 20 is used to acquire network asset information corresponding to the existing network asset management system, acquire the IP address or port information of each network asset in the network asset information, determine the first access relationship between network assets based on the IP address or port information, network security domain information and firewall policy configuration rules, and determine the first connection relationship between network assets based on the calling relationship and ownership relationship between network assets in the network asset information.
[0127] The second determining module 30 is used to determine the network asset topology based on the attribute information of the network assets in the network asset information, the first accessibility relationship, and the first connection relationship;
[0128] The assessment module 40 is used to obtain alarm information corresponding to network security threats, generate a network security threat knowledge graph based on the alarm information, the network security knowledge graph and the network asset topology graph, and determine the threat assessment report corresponding to the network security threat knowledge graph.
[0129] The methods executed by the above-mentioned program units can be referred to in the various embodiments of the network security threat assessment method of the present invention, and will not be repeated here.
[0130] The present invention also provides a readable storage medium.
[0131] The present invention stores a network security threat assessment program on a readable storage medium, which, when executed by a processor, implements the steps of the network security threat assessment method as described above.
[0132] The method implemented when the network security threat assessment program running on the processor is executed can be referred to in various embodiments of the network security threat assessment method of the present invention, and will not be repeated here.
[0133] Furthermore, this invention also proposes a computer program product that includes a network security threat assessment program, which, when executed by a processor, implements the steps of the network security threat assessment method as described above.
[0134] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.
[0135] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0136] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0137] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. A method for assessing cybersecurity threats, characterized in that, The cybersecurity threat assessment method includes the following steps: A cybersecurity knowledge graph is determined based on a cybersecurity knowledge system, wherein the cybersecurity knowledge graph includes cybersecurity threat entities, the relationships between cybersecurity threat entities, and the attribute information of cybersecurity threat entities; Obtain network asset information corresponding to the existing network asset management system, obtain the IP address or port information of each network asset in the network asset information, determine the first access relationship between network assets based on the IP address or port information, network security domain information and firewall policy configuration rules, and determine the first connection relationship between network assets based on the calling relationship and ownership relationship between network assets in the network asset information. Based on the attribute information of the network assets, the first accessibility relationship, and the first connection relationship in the network asset information, a network asset topology map is determined; Obtain alarm information corresponding to network security threats, generate a network security threat knowledge graph based on the alarm information, the network security knowledge graph, and the network asset topology graph, and determine the threat assessment report corresponding to the network security threat knowledge graph.
2. The network security threat assessment method as described in claim 1, characterized in that, The steps for determining the threat assessment report corresponding to the cybersecurity threat knowledge graph include: Based on a security reasoning model and a historical network security threat knowledge graph set, a network security threat assessment is performed on the network security threat knowledge graph to obtain a threat assessment report corresponding to the network security threat knowledge graph. The threat assessment report includes attack routes, predicted attack routes, and risk values of threat attacks.
3. The network security threat assessment method as described in claim 2, characterized in that, The steps of performing a cybersecurity threat assessment on the cybersecurity threat knowledge graph based on a security inference model and a historical cybersecurity threat knowledge graph set, and obtaining a threat assessment report corresponding to the cybersecurity threat knowledge graph, include: Obtain the target node in the network security threat knowledge graph, and determine the attack route corresponding to the target node based on the security reasoning model and the historical network security threat knowledge graph set; Based on the attack route and the network security threat knowledge graph, a predicted attack route is obtained. Based on the attack routes, the security inference model of the predicted attack routes, and the historical network security threat knowledge graph set, the risk value of the threat attack corresponding to each attack route is determined. A threat assessment report is generated based on the attack route, the predicted attack route, and the risk value of the threat attack.
4. The network security threat assessment method as described in claim 1, characterized in that, The step of generating a network security threat knowledge graph based on the alarm information, the network security knowledge graph, and the network asset topology graph includes: Based on the network security knowledge graph, the threat attack entities, network asset entities and connection relationships corresponding to the alarm information are determined, and an initial network security threat knowledge graph is determined based on the threat attack entities, network asset entities and connection relationships. In the network asset topology graph, obtain the associated network assets corresponding to each network asset entity. Based on the network asset entity and the associated network assets, determine the asset subgraph corresponding to each network asset entity, wherein the root node of the asset subgraph is the network asset entity. For each asset subgraph, the asset subgraph is traversed. When the attribute information of the threat attack entity matches the attribute information of the currently traversed network asset, a child node of the network asset entity corresponding to the asset subgraph is added to the initial network security threat knowledge graph based on the currently traversed network asset. The connection relationship between the threat attack entity and the currently traversed network asset is set in the initial network security threat knowledge graph, and the currently traversed network asset is added to the threat-related asset set. Based on the network security knowledge graph, obtain the set of associated threat attack entities corresponding to the threat attack entity, and determine the causal relationship between each threat attack entity in the set of associated threat attack entities; Identify the threat entities in the set of associated threat entities that are associated with network assets in the set of threat-related assets, and add the nodes corresponding to the threat entities to the initial network security threat knowledge graph to obtain the network security threat knowledge graph.
5. The network security threat assessment method as described in claim 1, characterized in that, The steps for obtaining alarm information corresponding to network security threats include: Obtain network security threat alert information, perform filtering operations on the network security threat alert information, and obtain filtered network security threat alert information; Identify the actual threats and attacks in the filtered network security threat alerts, and use these actual threats and attacks as the alert information.
6. The network security threat assessment method as described in any one of claims 1 to 5, characterized in that, The cybersecurity threat assessment method also includes: Periodically obtain asset change information corresponding to the network asset information based on the network asset management system; Obtain the second accessibility and second connection relationship of the network assets corresponding to the asset change information; The network asset topology is updated based on the attribute information of the network assets, the second accessibility relationship, and the second connection relationship in the asset change information.
7. The network security threat assessment method as described in any one of claims 1 to 5, characterized in that, The cybersecurity threat assessment method also includes: Periodically acquire cybersecurity threat intelligence data sources and obtain threat intelligence data from the cybersecurity threat intelligence data sources; The threat intelligence data is filtered based on a cybersecurity knowledge dictionary to obtain filtered threat intelligence data; The first threat intelligence data is processed based on the preset attribute mapping relationship to obtain the first data, wherein the first threat intelligence data is the structured data in the filtered threat intelligence data; Supervised learning is performed on the first threat intelligence data to obtain the second data, wherein the second threat intelligence data consists of semi-structured data and unstructured data from the filtered threat intelligence data; The cybersecurity knowledge graph is updated based on the first data and the second data.
8. A network security threat assessment device, characterized in that, The cybersecurity threat assessment device includes: The first determining module is used to determine a network security knowledge graph based on a network security knowledge system, wherein the network security knowledge graph includes network security threat entities, the relationships between network security threat entities, and the attribute information of network security threat entities; The acquisition module is used to acquire network asset information corresponding to the existing network asset management system, acquire the IP address or port information of each network asset in the network asset information, determine the first access relationship between network assets based on the IP address or port information, network security domain information and firewall policy configuration rules, and determine the first connection relationship between network assets based on the calling relationship and ownership relationship between network assets in the network asset information. The second determining module is used to determine the network asset topology based on the attribute information of the network assets in the network asset information, the first accessibility relationship, and the first connection relationship; The assessment module is used to obtain alarm information corresponding to network security threats, generate a network security threat knowledge graph based on the alarm information, the network security knowledge graph, and the network asset topology graph, and determine the threat assessment report corresponding to the network security threat knowledge graph.
9. A network security threat assessment device, characterized in that, The network security threat assessment device includes: a memory, a processor, and a network security threat assessment program stored in the memory and executable on the processor. When the network security threat assessment program is executed by the processor, it implements the steps of the network security threat assessment method as described in any one of claims 1 to 7.
10. A readable storage medium, characterized in that, The readable storage medium stores a network security threat assessment program, which, when executed by a processor, implements the steps of the network security threat assessment method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Big data driven network security situation monitoring and visualization method
CN105681303A
Network asset continuous security monitoring method, system, device and storage medium
CN108449345A