Method, apparatus, storage medium, and electronic device for determining malicious compromise indicators
By grouping and scoring the loss indicators of network communication behavior, the problem of inability to determine other communication loss indicators except detection samples in the prior art is solved, and the accurate identification and determination of malicious communication behavior is achieved.
Patent Information
- Application Number
- CN202211372304.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-03
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-11-03
AI Technical Summary
The prior art cannot effectively determine the determination results of other communication breakdown indicators other than the detection sample itself, especially when facing a large number of network attacks, sandbox detection cannot provide a complete IOC judgment.
By obtaining the sample detection report of the target detection sample, grouping multiple destruction indicators according to preset rules, determining suspicious communication packets, and calculating the destruction score based on the malicious judgment indicators, and determining the suspicious destruction indicator with scores exceeding the threshold as a malicious destruction indicator.
It realizes accurate judgment of other communication failure indicators except detection samples, improves the accuracy and efficiency of network threat detection, and can identify potential malicious communication behaviors.
Smart Images

Figure CN115776388B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular, to a method, apparatus, storage medium, and electronic device for determining malicious compromise indicators. Background Art
[0002] In recent years, with the continuous increase in the number of mining viruses, ransomware, and APT attack incidents, network attack means have developed with the diversification of scenarios, resulting in the continuous upgrading of threat detection methods. Threat intelligence is an efficient way to discover network threats. Since any threat comes from a sample, it is an effective and accurate way to find malicious IOCs from the sample and use them as threat intelligence.
[0003] Currently, the extraction of dynamic and static behaviors from samples is generally carried out through two methods: manual analysis and sandbox detection. Manual analysis is more flexible than sandbox detection but has low efficiency and cannot handle large-scale sample analysis. Therefore, it is necessary to use a sandbox to meet the needs of analyzing a large number of detection samples. However, the sandbox can only detect the judgment results and dynamic and static behavior information of the samples, and cannot give the judgment results of other communication compromise indicators IOCs (domain names, IPs, URLs) except the detected samples themselves.
[0004] In view of the problem in the related art that the judgment results of other communication compromise indicators except the detected samples themselves cannot be determined, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a method, apparatus, storage medium, and electronic device for determining malicious compromise indicators, so as to at least solve the technical problem in the related art that the judgment results of other communication compromise indicators except the detected samples themselves cannot be determined.
[0006] According to an embodiment of the embodiments of the present invention, a method for determining malicious compromise indicators is provided, including: obtaining a sample detection report of a target detection sample, where the sample detection report includes: a plurality of compromise indicators for indicating network communication behaviors; grouping the plurality of compromise indicators according to a preset rule to obtain a plurality of communication groups, where any one compromise indicator is only divided into one communication group among the plurality of communication groups; determining the group types of the plurality of communication groups, and determining a first communication group with a group type of a suspicious communication group from the plurality of communication groups, where all the compromise indicators in the first communication group are suspicious compromise indicators; determining the compromise scores of the suspicious compromise indicators included in all the first communication groups according to malicious judgment indicators, and determining the suspicious compromise indicators with compromise scores greater than a first preset threshold as malicious compromise indicators.
[0007] According to another embodiment of the embodiments of the present invention, there is also provided a device for determining malicious compromise indicators, including: an acquisition module, configured to acquire a sample detection report of a target detection sample, where the sample detection report includes: a plurality of compromise indicators for indicating network communication behaviors; a grouping module, configured to group the plurality of compromise indicators according to a preset rule to obtain a plurality of communication groups; a first determination module, configured to determine the group types of the plurality of communication groups, and determine a first communication group with a group type of a suspicious communication group from the plurality of communication groups, where all the compromise indicators in the first communication group are suspicious compromise indicators; a second determination module, configured to determine the compromise scores of the suspicious compromise indicators included in all the first communication groups according to malicious determination indicators, and determine the suspicious compromise indicators with compromise scores greater than a first preset threshold as malicious compromise indicators.
[0008] According to yet another embodiment of the embodiments of the present application, there is provided a computer-readable storage medium, characterized in that the computer-readable storage medium includes a stored program, where the program, when running, executes the method for determining malicious compromise indicators as described above.
[0009] According to yet another embodiment of the embodiments of the present invention, there is also provided an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the method for determining malicious compromise indicators through the computer program.
[0010] In the embodiments of the present invention, by acquiring a sample detection report of a target detection sample; grouping the plurality of compromise indicators in the sample detection report according to a preset rule to obtain a plurality of communication groups; determining the group types of the plurality of communication groups, and determining a first communication group with a group type of a suspicious communication group from the plurality of communication groups; determining the compromise scores of the suspicious compromise indicators included in all the first communication groups according to malicious determination indicators, and determining the suspicious compromise indicators with compromise scores greater than a first preset threshold as malicious compromise indicators, the technical problem in the related art that the determination results of other communication compromise indicators except the detection sample itself cannot be determined is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0012] Figure 1 is a hardware structure block diagram of a computer terminal for an optional method for determining malicious compromise indicators according to an embodiment of the present invention;
[0013] Figure 2It is a flowchart of an optional method for determining malicious compromise indicators according to an embodiment of the present invention;
[0014] Figure 3 It is a schematic diagram of an optional method for determining malicious compromise indicators according to an embodiment of the present invention;
[0015] Figure 4 It is a schematic diagram of a sample test report of an optional detection sample according to an embodiment of the present invention;
[0016] Figure 5 It is a schematic diagram (one) of grouping of optional malicious compromise indicators according to an embodiment of the present invention;
[0017] Figure 6 It is a schematic diagram (two) of grouping of optional malicious compromise indicators according to an embodiment of the present invention;
[0018] Figure 7 It is a schematic diagram (three) of grouping of optional malicious compromise indicators according to an embodiment of the present invention;
[0019] Figure 8 It is a schematic diagram of the structure of an optional device for determining malicious compromise indicators according to an embodiment of the present invention. Detailed implementation manners
[0020] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0021] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0022] The method embodiments provided by the embodiments of the present application can be executed on a computer terminal or a similar computing device. Taking the operation on a computer terminal as an example, Figure 1 is a hardware structure block diagram of a computer terminal for a method of determining malicious compromise indicators according to an embodiment of the present application. As Figure 1 shown, the computer terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. In an exemplary embodiment, the above computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above computer terminal. For example, the computer terminal may further include more or fewer components than Figure 1 shown in the figure, or have the same functions as Figure 1 shown in the figure or different configurations with more functions than Figure 1 shown in the figure.
[0023] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the method of determining malicious compromise indicators in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely provided with respect to the processor 102, and these remote memories can be connected to the computer terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0024] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the computer terminal. In one instance, the transmission device 106 includes a network adapter (abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (abbreviated as RF) module, which is used to communicate with the Internet wirelessly.
[0025] In this embodiment, a method for determining malicious compromise indicators is provided, which is applied to the above computer terminal.Figure 2 It is a flowchart of an optional method for determining malicious compromise indicators according to an embodiment of the present invention. The process includes the following steps:
[0026] Step S202, obtain a sample detection report of a target detection sample, where the sample detection report includes: a plurality of compromise indicators for indicating network communication behaviors;
[0027] It should be noted that the above sample detection report may also include, but is not limited to: sample static information and sample dynamic information. Among them, the sample static information includes: sample hash value, sample core behavior, sample determination result; the sample dynamic information includes: file operations, registry operations, process operations, service operations.
[0028] Step S204, group the plurality of compromise indicators according to a preset rule to obtain a plurality of communication groups, where any one compromise indicator is only classified into one communication group among the plurality of communication groups;
[0029] Step S206, determine the group types of the plurality of communication groups, and determine a first communication group with a group type of a suspicious communication group from the plurality of communication groups, where all the compromise indicators in the first communication group are suspicious compromise indicators;
[0030] It should be noted that all the compromise indicators in the communication group with a group type of an invalid communication group are invalid compromise indicators; all the compromise indicators in the communication group with a group type of a trusted communication group are trusted compromise indicators.
[0031] Step S208, determine the compromise scores of the suspicious compromise indicators included in all the first communication groups according to malicious determination indicators, and determine the suspicious compromise indicators with compromise scores greater than a first preset threshold as malicious compromise indicators.
[0032] In the embodiment of the present invention, by obtaining a sample detection report of a target detection sample; grouping a plurality of compromise indicators in the sample detection report according to a preset rule to obtain a plurality of communication groups; determining the group types of the plurality of communication groups, and determining a first communication group with a group type of a suspicious communication group from the plurality of communication groups; determining the compromise scores of the suspicious compromise indicators included in all the first communication groups according to malicious determination indicators, and determining the suspicious compromise indicators with compromise scores greater than a first preset threshold as malicious compromise indicators, the technical problem in the related art that the determination results of other communication compromise indicators except the detection sample itself cannot be determined is solved; and thus, the technical effect of accurately determining whether a compromise indicator is a malicious compromise indicator can be achieved.
[0033] Optionally, in this embodiment, the method for determining the malicious compromise indicators described above can be but is not limited to being applied in Internet security technology, network security monitoring technology, sample analysis technology, and threat intelligence production.
[0034] In an exemplary embodiment of the present invention, in order to better understand how to group the multiple compromise indicators in step S204 to obtain multiple communication groups, the following method can be used. Specifically: Step 1: Divide the compromise indicators with domain name intersections among the multiple compromise indicators into at least one second communication group, divide the compromise indicators with IP address intersections among the multiple remaining compromise indicators into at least one third communication group, and divide the compromise indicators without domain name intersections and IP address intersections into at least one fourth communication group, where the remaining compromise indicators are used to indicate the compromise indicators other than the compromise indicators in the second communication group among the multiple compromise indicators; Step 2: Determine whether there is a communication group with an IP address intersection between the IP addresses in the at least one second communication group and the at least one third communication group; Step 3: If there is, merge the second communication group and the third communication group into a seventh communication group, where the multiple communication groups include: the fourth communication group, the seventh communication group.
[0035] It should be noted that taking the IP address 1: 200.0.0.2 resolved from domain name 1: a.test.com, IP address 2: 200.0.0.3 resolved from domain name 2: xx.b.test.com, IP address 3: 200.0.0.4 resolved from domain name 3: e.test.com, IP address 4: 200.0.0.4 resolved from domain name 4: c.com, and IP address 5: 200.0.0.4 resolved from domain name 5: d.com as an example, the domain names 1, 2, 3 with domain name intersections (test.com) and their corresponding IP addresses are divided into the second communication group; the IP addresses 4, 5 with IP address intersections (200.0.0.4) and their corresponding domain names are divided into the third communication group; since there is an IP address intersection (200.0.0.4) between IP address 3 and IP addresses 4, 5 in the second communication group and the third communication group, the second communication group and the third communication group are divided into the seventh communication group.
[0036] Optionally, in an embodiment, all the compromise indicators in any one of the second communication groups have the same domain name intersection; all the compromise indicators in any one of the third communication groups have the same IP address intersection; any two compromise indicators in the seventh communication group may not have the same IP address intersection and / or the same domain name intersection.
[0037] In another exemplary embodiment of the present invention, a method for grouping the multiple compromised indicators to obtain multiple communication groups is also provided. The specific implementation method refers to the above steps 1-3. The implementation method of the embodiment of the present invention is only different from the execution order of the above steps S1-3. The specific execution order is: step 2, step 1, step 3.
[0038] Taking the IP address 1: 200.0.0.2 resolved from the domain name 1: a.test.com, the IP address 2: 200.0.0.3 resolved from the domain name 2: xx.b.test.com, the IP address 3: 200.0.0.4 resolved from the domain name 3: e.test.com, the IP address 4: 200.0.0.4 resolved from the domain name 4: c.com, and the IP address 5: 200.0.0.4 resolved from the domain name 5: d.com as examples, the IP address 3, IP address 4, and IP address 5 with the IP address intersection (200.0.0.4) and the corresponding domain names are divided into the eighth communication group; the domain name 1, domain name 2 with the domain name intersection (test.com) and the corresponding IP addresses are divided into the ninth communication group; since there is a domain name intersection (test.com) between the domain name 3 and the domain name 1, domain name 2 in the second communication group and the third communication group, the second communication group and the third communication group are divided into the same group.
[0039] It should be noted that according to a large amount of data analysis, when any domain name containing the parent domain name should have problems, multiple other different domain names containing the parent domain name should also have problems. Conversely, when any domain name containing the parent domain name has no problems, multiple other different domain names containing the parent domain name should also have no problems, and when the IP address has no problems, other IP addresses containing the IP address intersection should also have no problems; since the determination result of the IOC mainly depends on the IOC whitelist, when it is determined that any domain name or IP address containing the parent domain name has no problems, the communication group containing any domain name or IP address is a trusted communication group, and further determining that all the compromised indicators in the communication group have no problems can further reduce the calculation amount.
[0040] Optionally, in one embodiment, determining the packet types of the multiple communication packets includes at least one of the following: when there is a compromise indicator in each communication packet that is consistent with the compromise indicators in the whitelist, determining the packet type of each communication packet as a trusted communication packet, where the whitelist stores multiple trusted compromise indicators; when there is no compromise indicator in each communication packet that is consistent with the compromise indicators in the whitelist, determining the packet type of each communication packet as a suspicious communication packet; when any compromise indicator in each communication packet has an IP address for invalid communication, determining the packet type of each communication packet as an invalid communication packet; when all compromise indicators in each communication packet have non-Internet-valid IP addresses, determining the packet type of each communication packet as an invalid communication packet.
[0041] That is, when there is one or more compromise indicators in each communication packet that are consistent with the compromise indicators in the whitelist, determining the packet type of the communication packet as a trusted communication packet; when there is no compromise indicator in each communication packet that is consistent with the compromise indicators in the whitelist, determining the packet type of the communication packet as a suspicious communication packet; it should be noted that a non-Internet-valid IP address can be understood as an IP address without a corresponding URL address and domain name.
[0042] Optionally, in order to better eliminate false alarms of malicious compromise indicators, in one embodiment, determining the packet types of the multiple communication packets further includes: when the number of communication packets with the packet types of invalid communication packets and suspicious communication packets is greater than an eighth preset threshold, determining that the packet types of all communication packets with the packet type of suspicious communication packets are changed to invalid communication packets.
[0043] It should be noted that when the number of communication packets with the packet types of invalid communication packets and suspicious communication packets exceeds the eighth preset threshold among the multiple communication packets, it indicates that the coverage rate of the whitelist is too low, and it is impossible to determine that the communication packets with the packet types of invalid communication packets and suspicious communication packets have malicious compromise indicators. Therefore, when the number of communication packets with the packet types of invalid communication packets and suspicious communication packets exceeds the eighth preset threshold among the multiple communication packets, the packet type of the suspicious communication packets is adjusted to an invalid communication packet, thereby eliminating false alarms.
[0044] In an exemplary embodiment of the present invention, in order to better understand how to determine the compromise scores of the suspicious compromise indicators included in all the first communication packets according to the malicious determination indicators in step S208, a technical solution is proposed, and the specific steps include:
[0045] Step 1: Determine multiple first detection samples associated with each suspicious compromise indicator, and determine black detection samples and white detection samples among the multiple first detection samples. Among them, the multiple first sample detection reports of the multiple first detection samples all include: a first compromise indicator consistent with each suspicious compromise indicator; there is a malicious compromise indicator in the sample detection report of the black detection sample, and there is no malicious compromise indicator in the sample detection report of the white detection sample;
[0046] Optionally, determine whether the first detection sample is a black detection sample or a white detection sample according to the sample static information in the first sample detection report of the first detection sample.
[0047] Step 2: Determine a second compromise indicator whose indicator type in the first compromise indicator is a suspicious compromise indicator and a third compromise indicator whose indicator type is a trusted compromise indicator;
[0048] It should be noted that the first compromise indicator can be multiple compromise indicators corresponding to different detection samples respectively, and the indicator type of the compromise indicator is determined by the grouping type corresponding to the compromise indicator. Therefore, the first compromise indicator may be determined as a compromise indicator with a suspicious compromise indicator type in detection sample 1, but determined as a compromise indicator with a trusted compromise indicator type in detection sample 2.
[0049] Step 3: Determine a fourth compromise indicator corresponding to the black detection sample among the second compromise indicators, and determine a fifth compromise indicator and a sixth compromise indicator among the fourth compromise indicators. Among them, there is only one communication packet in the black detection sample corresponding to the fifth compromise indicator, and the malicious code family information of the black detection sample corresponding to the sixth compromise indicator contains a remote control IP address;
[0050] Step 4: Determine a malicious determination indicator according to the first detection sample, the second compromise indicator, the third compromise indicator, the fourth compromise indicator, the fifth compromise indicator, the sixth compromise indicator, the black detection sample, and the white detection sample;
[0051] Step 5: Determine the compromise score of each suspicious compromise indicator according to the malicious determination indicator.
[0052] Optionally, determining a malicious determination index according to the first detection sample, the second compromise index, the third compromise index, the fourth compromise index, the fifth compromise index, the sixth compromise index, the black detection sample, and the white detection sample includes: determining a first quantity of the first detection sample, a second quantity of the second compromise index, a third quantity of the third compromise index, a fourth quantity of the fourth compromise index, a fifth quantity of the fifth compromise index, a sixth quantity of the sixth compromise index, a seventh quantity of the black detection sample, and an eighth quantity of the white detection sample; determining a full sample detection rate of each suspicious compromise index according to the first quantity and the second quantity, where the full sample detection rate is used to indicate the percentage of the quantity of the second compromise index in the first compromise index; determining a black detection sample detection rate of each suspicious compromise index according to the fourth quantity and the seventh quantity, where the black detection sample detection rate is used to indicate the percentage of the quantity of the fourth compromise index in the black detection sample; determining a remote control malicious code family rate of each suspicious compromise index according to the sixth quantity and the seventh quantity, where the remote control malicious code family rate is used to indicate the percentage of the fifth compromise index in the black detection sample; determining an absolute detection rate of each suspicious compromise index according to the fifth quantity and the seventh quantity, where the absolute detection rate is used to indicate the percentage of the fifth compromise index in the black detection sample.
[0053] Further, the full - sample detection rate is used to indicate the percentage of the suspicious compromise indicators among all the detection samples associated with each suspicious compromise indicator, where the indicator type of the corresponding compromise indicator is a suspicious compromise indicator. It should be noted that the higher the full - sample detection rate, the greater the probability that the suspicious compromise indicator is a malicious compromise indicator; conversely, the lower the full - sample detection rate, the smaller the probability that the suspicious compromise indicator is a malicious compromise indicator. The black - sample detection rate is used to indicate the percentage of the suspicious compromise indicators among all the black - sample detections associated with each suspicious compromise indicator, where the indicator type of the corresponding compromise indicator is a suspicious compromise indicator. It should be noted that the higher the black - sample detection rate, the greater the probability that the suspicious compromise indicator is a malicious compromise indicator; conversely, the lower the black - sample detection rate, the smaller the probability that the suspicious compromise indicator is a malicious compromise indicator. The remote - control malicious - code family rate is used to indicate the percentage of the black - sample detections containing remote - control IP addresses among all the black - sample detections associated with each suspicious compromise indicator. It should be noted that the higher the remote - control malicious - code family rate, the greater the probability that the suspicious compromise indicator is a malicious compromise indicator; conversely, the lower the remote - control malicious - code family rate, the smaller the probability that the suspicious compromise indicator is a malicious compromise indicator. The absolute detection rate is used to indicate the percentage of the black - samples among all the black - sample detections associated with each suspicious compromise indicator, where the indicator type of each suspicious compromise indicator is a suspicious compromise indicator and each communication group where each suspicious compromise indicator is located is the only communication group in the black - sample detection. It should be noted that the higher the absolute detection rate, the greater the probability that the suspicious compromise indicator is a malicious compromise indicator; conversely, the lower the absolute detection rate, the smaller the probability that the suspicious compromise indicator is a malicious compromise indicator.
[0054] Optionally, in an exemplary embodiment, determining the compromise score of each suspicious compromise indicator according to the malicious determination indicator includes: determining the compromise score of each suspicious compromise indicator according to the third quantity, the full - sample detection rate, the black - sample detection rate, the remote - control malicious - code family rate, the absolute detection rate, and the eighth quantity.
[0055] Specifically, in order to eliminate false alarms of the compromise indicators, when determining the compromise scores of each suspicious compromise indicator based on the third quantity, the full sample detection rate, the black detection sample detection rate, the remote control malicious code family rate, the absolute detection rate, and the eighth quantity, it is also necessary to determine: whether the third quantity is equal to the second preset threshold, whether the full sample detection rate is greater than the third preset threshold, whether the black detection sample detection rate is greater than the fourth preset threshold, and whether the remote control malicious code family rate is greater than the fifth preset threshold; when the third quantity is equal to the second preset threshold, the full sample detection rate is greater than the third preset threshold, the black detection sample detection rate is greater than the fourth preset threshold, and the remote control malicious code family rate is greater than the fifth preset threshold, determine the compromise scores of each suspicious compromise indicator based on the full sample detection rate, the black detection sample detection rate, the remote control malicious code family rate, the absolute detection rate, and the eighth quantity.
[0056] Further, when the third quantity is greater than the second preset threshold, and / or the full sample detection rate is less than or equal to the third preset threshold, and / or the black detection sample detection rate is less than or equal to the fourth preset threshold, and / or the remote control malicious code family rate is less than or equal to the fifth preset threshold, it indicates that there are many reasons that prevent malicious determination of each suspicious compromise indicator. Therefore, the compromise scores of each suspicious compromise indicator cannot be determined.
[0057] Specifically: determine the first score according to the first magnitude relationship between the full sample detection rate and the fifth preset threshold, determine the second score according to the second magnitude relationship between the black detection sample detection rate and the sixth preset threshold, determine the third score according to the third magnitude relationship between the remote control malicious code family rate and the seventh preset threshold, determine the fourth score according to the fourth magnitude relationship between the absolute detection rate and the eighth preset threshold, and determine the fifth score according to the fifth magnitude relationship between the eighth quantity and the ninth preset threshold; use the sum of the first score, the second score, the third score, the fourth score, and the fifth score as the compromise score of each suspicious compromise indicator.
[0058] For example, when the full sample detection rate is greater than 50%, add points in a gradient manner to determine the first score; when the black detection sample detection rate is greater than 50%, add points in a gradient manner to determine the second score; when the remote control malicious code family rate is greater than 30%, add points in a gradient manner to determine the third score; when the absolute detection rate is greater than 35%, add 10 points to determine the fourth score; when the eighth quantity of the white detection samples is 0, add 10 points to determine the fifth score; then determine the compromise scores of each suspicious compromise indicator based on the first score, the second score, the third score, the fourth score, and the fifth score.
[0059] It should be noted that the gradient-based score addition can be understood as follows. When the full-sample detection rate is 55% and the fifth preset threshold is 50%, the difference between the full-sample detection rate and the fifth preset threshold is 5%, and 5 points can be obtained. When the full-sample detection rate is 60%, the difference between the full-sample detection rate and the fifth preset threshold is 10%, and 10 points can be obtained. When the full-sample detection rate is 70%, the difference between the full-sample detection rate and the fifth preset threshold is 20%, and 20 points can be obtained, and so on. The gradient-based score addition system for the remote control malicious code family rate and the black detection sample detection rate is similar to that of the full-sample detection rate.
[0060] For further illustration, the method for determining the malicious compromise indicator is as Figure 3 shown Figure 3 It is a schematic diagram of an optional method for determining a malicious compromise indicator according to an embodiment of the present invention. The specific steps are as follows:
[0061] Step S302: Obtain the sample detection report of the sample to be detected (equivalent to the target detection sample in the above embodiment);
[0062] It should be noted that considering the coverage of the IOC whitelist, the timeliness of the IOC whitelist, and the timeliness of the sample to be detected, the creation time of the sample to be detected should not exceed 30 days.
[0063] The sample detection report of the sample to be detected is as Figure 4 shown Figure 4 It is a schematic diagram of a sample detection report of an optional detection sample according to an embodiment of the present invention.
[0064] Step S304: Process the data in the sample detection report;
[0065] Step S306: Obtain the processing result, where the processing result includes:
[0066] 1) HTTP communication list:
[0067] http: / / a.test.com:3355 / ; http: / / xx.b.test.com:3355 / ; http: / / e.test.com:3355 / ; http: / / c.com:3355 / ; http: / / d.com:3355 / .
[0068] 2) DNS resolution list:
[0069] a.test.com, the resolution result is 200.0.0.2; xx.b.test.com, the resolution result is 200.0.0.3;
[0070] For e.test.com, the resolution result is 200.0.0.4; for c.com, the resolution result is 200.0.0.4;
[0071] For d.com, the resolution result is 200.0.0.4;
[0072] 3) TCP communication list: 200.0.0.2:3355; 200.0.0.3:3355; 200.0.0.4:3355; 200.0.0.4:3355;
[0074] 200.0.0.4:3355; 100.0.0.2:8888.
[0075] Step S308, create a compromised indicator grouping;
[0076] It should be noted that the minimum grouping of compromised indicators consists of URL, domain name, and IP address. Among them, the URL is the URL accessed by the sample to be detected, the domain name is the domain name with which the sample communicates, and the IP address is the direct communication IP address or the IP address resolved from the domain name through DNS and there is a communication IP address of domain name: port in TCP.
[0077] Such as Figure 5 shown, Figure 5 is a schematic diagram (one) of an optional grouping of malicious compromised indicators according to an embodiment of the present invention. As Figure 5 in, the host part associated with http: / / a.test.com:3355 / is the domain name a.test.com. Therefore, the IP address resolved from this domain name is obtained as 200.0.0.2 through DNS resolution. From the TCP communication, 200.0.0.2:3355 can be obtained, and it is determined that there is a valid access behavior for this URL. The URL: http: / / a.test.com:3355 / , domain name: a.test.com; IP address: 200.0.0.2:3355 are divided into one group; as Figure 5 in, there is no associated domain name and URL for 100.0.0.2:8888. Therefore, only 100.0.0.2:8888 is divided into one group.
[0078] Step S310, group merging;
[0079] For Figure 5The group1-6 created in [description] perform grouping and merging. The groups are associated through domain names or IPs. For domain name association, all domain names included in the group and the parent domain names of the domain names are recursively disassembled until the top-level domain name of the domain name is reached and a domain name list is formed. If there is an intersection in the domain name lists of two groups, the association is successful. For IP association, if there is an intersection in the IPs between two groups, the association is successful. The successfully associated groups are merged until the merging is completed. As Figure 6 and Figure 7 shown Figure 6 is an optional grouping schematic diagram (two) of malicious compromise indicators according to an embodiment of the present invention; Figure 7 is an optional grouping schematic diagram (three) of malicious compromise indicators according to an embodiment of the present invention.
[0080] The specific grouping and merging method is as follows:
[0081] 1) There is a domain name intersection test.com ( Figure 6 the slanted shaded part in [description]) in the top-level domain names of group1-3, so group1-3 are merged into a new group merge_group1 (equivalent to the second communication group in the above embodiment);
[0082] 2) The IP addresses of group4-5 are all 200.0.0.4 ( Figure 6 the grid shaded part in [description]), so group4-5 are merged into a new group merge_group2 (equivalent to the third communication group in the above embodiment);
[0083] 3) There is no association for group6, so the grouping cannot be merged, and merge_group3 is generated (equivalent to the fourth communication group in the above embodiment);
[0084] 4) There is an IP address intersection 200.0.0.4 ( Figure 7 the grid shaded part in [description]) in merge_group1-2, so merge_group1-2 are merged into a new group final_group1 (equivalent to the seventh communication group in the above embodiment);
[0085] 5) There is no association for merge_group3, so the grouping cannot be merged, and final_group2 is generated (equivalent to the fourth communication group in the above embodiment).
[0086] Step S312, grouping determination;
[0087] Determine the determination result of each group. The determination results are divided into three types: invalid group (equivalent to the communication packet with the packet type of invalid communication packet in the above embodiment), suspicious group (equivalent to the communication packet with the packet type of invalid communication packet in the above embodiment), and whitelist group (equivalent to the communication packet with the packet type of trusted communication packet in the above embodiment). Take the determination result of the group as the determination result of all IOCs in the group. The determination method is as follows:
[0088] 1) If there is no valid communication IP address in the group or all IP addresses in the group are not Internet valid IP addresses, determine that the group is an invalid group;
[0089] 2) If at least one IOC in all IOCs in the group is consistent with an IOC in the IOC whitelist, determine that the group is a whitelist group;
[0090] 3) If there is no IOC in the group that is consistent with an IOC in the IOC whitelist, determine that the group is a suspicious group;
[0091] 4) If the number of suspicious groups + the number of invalid groups is greater than 1, determine that all suspicious groups are invalid groups.
[0092] Step S314, save the IOC result;
[0093] Record information such as IOC, IOC determination result, and sample malicious code family in the sample detection report into the result set.
[0094] Step S316, generate an index matrix;
[0095] 1) Construct an IOC multi-index comprehensive determination matrix to provide a determination basis for malicious IOC identification, as shown in Table 1;
[0096] Table 1
[0097]
[0098] 2) According to the above IOC multi-index comprehensive determination matrix, determine the following indexes:
[0099] 1. The number of IOCs determined as white: The number of groups whose determination results of the groups corresponding to the IOCs among all samples associated with the IOC are whitelist groups;
[0100] 2. The detection rate of all samples: The percentage of the number of groups whose determination results of the groups corresponding to the IOCs among all samples associated with the IOC are suspicious groups in the total number of all samples;
[0101] 3. The detection rate of black samples: The percentage of the number of groups whose determination results of the groups corresponding to the IOCs among all black samples associated with the IOC are suspicious groups in the total number of all black samples;
[0102] 4. Proportion of remote control malicious code families: The percentage of the number of black samples containing malicious code families with remote control IP addresses among all black samples associated with IOCs in the total number of all black samples;
[0103] 5. Absolute detection rate: The percentage of IOCs that are judged suspicious by IOC and the group where the IOC is located is the only group among black samples among all black samples associated with IOCs;
[0104] 6. Number of samples judged as white: The number of all white samples associated with IOCs;
[0105] 3) Complete the identification of malicious IOCs based on the IOC multi-index comprehensive judgment matrix, calculate the comprehensive score of the IOC, and if the comprehensive score of the IOC exceeds 60 points, it is determined as a malicious IOC. The determination method is as follows:
[0106] 1. If the number of IOCs judged as white is greater than 0, the IOC does not participate in the determination;
[0107] 2. If the full sample detection rate is less than 50%, the IOC does not participate in the determination, otherwise, add points in gradients of P / 5, with a maximum addition of 20 points, where P = full sample detection rate - 50%;
[0108] 3. If the black sample detection rate is less than 50%, the IOC does not participate in the determination, otherwise, add points in gradients of P / 5, with a maximum addition of 20 points, where P = black sample detection rate - 50%;
[0109] 4. If the proportion of remote control malicious code families is less than 30%, the IOC does not participate in the determination, otherwise, add points in gradients of P / 5, with a maximum addition of 10 points, where P = proportion of remote control malicious code families - 30%;
[0110] 5. If the absolute detection rate exceeds 35%, add 10 points;
[0111] 6. If the number of samples judged as white is 0, add 10 points.
[0112] Step S318, output malicious IOCs.
[0113] The above embodiments include the following processes: creating groups, merging groups, determining group types, and summarizing metrics. All communication IOCs included in the sample are grouped into traffic groups based on the communication grouping method, the traffic groups are merged according to the IOC relevance, a final determination is made on the final groups in combination with the IOC whitelist, an indicator matrix is constructed for the IOC determination results, and malicious IOCs are identified. Taking the sample detection report as the factual basis, assuming that each sample detection report with external network communication contains at least one malicious IOC, then these IOCs should all be determined as suspicious in the samples associated with them. If there are IOCs that are all determined as suspicious in the samples associated with them, it indicates that the IOC is a malicious IOC. The more the number of associated blacklisted samples, the greater the likelihood that the IOC is malicious. If there is a situation where the samples associated with an IOC are determined as white, the determination for this IOC cannot be completed.
[0114] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.
[0115] According to another aspect of the embodiments of the present invention, there is also provided a malicious compromise indicator determination device for implementing the above malicious compromise indicator determination method. As Figure 8 shown, Figure 8 FIG. is a schematic structural diagram of an optional malicious compromise indicator determination device according to an embodiment of the present invention. The device includes:
[0116] An acquisition module 82, configured to acquire a sample detection report of a target detection sample, where the sample detection report includes: a plurality of compromise indicators for indicating network communication behaviors;
[0117] A grouping module 84, configured to group the plurality of compromise indicators according to a preset rule to obtain a plurality of communication groups, where any one compromise indicator is only divided into one communication group among the plurality of communication groups;
[0118] A first determination module 86, configured to determine the group types of the plurality of communication groups, and determine a first communication group with a group type of a suspicious communication group from the plurality of communication groups, where all the compromise indicators in the first communication group are suspicious compromise indicators;
[0119] A second determination module 88, configured to determine a compromise score of a suspicious compromise indicator included in all the first communication packets according to a malicious determination indicator, and determine a suspicious compromise indicator with a compromise score greater than a first preset threshold as a malicious compromise indicator.
[0120] With the above device, by obtaining a sample detection report of a target detection sample; grouping a plurality of compromise indicators in the sample detection report according to a preset rule to obtain a plurality of communication packets; determining a packet type of the plurality of communication packets, and determining a first communication packet with a packet type of a suspicious communication packet from the plurality of communication packets; determining a compromise score of a suspicious compromise indicator included in all the first communication packets according to a malicious determination indicator, and determining a suspicious compromise indicator with a compromise score greater than a first preset threshold as a malicious compromise indicator, thereby solving the technical problem in the related art that the determination result of a communication compromise indicator other than the detection sample itself cannot be determined.
[0121] In an exemplary embodiment of the present invention, the grouping module 84 is further configured to divide compromise indicators with a domain name intersection among the plurality of compromise indicators into at least one second communication packet, divide compromise indicators with an IP address intersection among a plurality of remaining compromise indicators into at least one third communication packet, and divide compromise indicators without a domain name intersection and an IP address intersection into at least one fourth communication packet, where the remaining compromise indicators are used to indicate compromise indicators other than the compromise indicators in the second communication packet among the plurality of compromise indicators; determine a communication packet in which an IP address intersection exists between the at least one second communication packet and the at least one third communication packet; if so, merge the second communication packet and the third communication packet into a seventh communication packet, where the plurality of communication packets include: the fourth communication packet, the seventh communication packet.
[0122] Optionally, the first determination module is configured to perform at least one of the following: when there is a compromise indicator in each communication packet that is the same as a compromise indicator in a whitelist, determine that the packet type of each communication packet is a trusted communication packet, where a plurality of trusted compromise indicators are stored in the whitelist; when there is no compromise indicator in each communication packet that is the same as a compromise indicator in the whitelist, determine that the packet type of each communication packet is a suspicious communication packet; when there is an IP address of an invalid communication for any compromise indicator in each communication packet, determine that the packet type of each communication packet is an invalid communication packet; when all compromise indicators in each communication packet have non-Internet valid IP addresses, determine that the packet type of each communication packet is an invalid communication packet.
[0123] In an exemplary embodiment of the present invention, the second determination module is further configured to determine a plurality of first detection samples associated with each suspicious compromise indicator, and determine black detection samples and white detection samples among the plurality of first detection samples. Among them, the plurality of first sample detection reports of the plurality of first detection samples all include: a first compromise indicator consistent with each suspicious compromise indicator; determining a second compromise indicator with an indicator type of a suspicious compromise indicator and a third compromise indicator with an indicator type of a trusted compromise indicator among the first compromise indicators; determining a fourth compromise indicator corresponding to the black detection sample among the second compromise indicators, and determining a fifth compromise indicator and a sixth compromise indicator among the fourth compromise indicators. Among them, there is only one communication packet in the black detection sample corresponding to the fifth compromise indicator, and the malicious code family information of the black detection sample corresponding to the sixth compromise indicator contains a remote control IP address; determining a malicious determination indicator according to the first detection sample, the second compromise indicator, the third compromise indicator, the fourth compromise indicator, the fifth compromise indicator, the sixth compromise indicator, the black detection sample, and the white detection sample; determining a compromise score of each suspicious compromise indicator according to the malicious determination indicator.
[0124] In an exemplary embodiment, the second determination module is configured to determine a first quantity of the first detection samples, a second quantity of the second compromise indicators, a third quantity of the third compromise indicators, a fourth quantity of the fourth compromise indicators, a fifth quantity of the fifth compromise indicators, a sixth quantity of the sixth compromise indicators, a seventh quantity of the black detection samples, and an eighth quantity of the white detection samples; determining the full sample detection rate of each suspicious compromise indicator according to the first quantity and the second quantity; determining the black detection sample detection rate of each suspicious compromise indicator according to the fourth quantity and the seventh quantity; determining the remote control malicious code family rate of each suspicious compromise indicator according to the sixth quantity and the seventh quantity; determining the absolute detection rate of each suspicious compromise indicator according to the fifth quantity and the seventh quantity; determining the compromise score of each suspicious compromise indicator according to the third quantity, the full sample detection rate, the black detection sample detection rate, the remote control malicious code family rate, the absolute detection rate, and the eighth quantity.
[0125] In an exemplary embodiment, the second determination module is configured to determine the compromise score of each suspicious compromise indicator according to the malicious determination indicator, including: determining the compromise score of each suspicious compromise indicator according to the third quantity, the full sample detection rate, the black detection sample detection rate, the remote control malicious code family rate, the absolute detection rate, and the eighth quantity.
[0126] In an exemplary embodiment, a second determination module is configured to determine whether the third quantity is equal to a second preset threshold, whether the full sample detection rate is greater than a third preset threshold, whether the detection rate of black detection samples is greater than a fourth preset threshold, and whether the remote control malicious code family rate is greater than a fifth preset threshold; in the case where the third quantity is equal to the second preset threshold, the full sample detection rate is greater than the third preset threshold, the detection rate of black detection samples is greater than the fourth preset threshold, and the remote control malicious code family rate is greater than the fifth preset threshold, determine a first score according to a first magnitude relationship between the full sample detection rate and the third preset threshold, determine a second score according to a second magnitude relationship between the detection rate of black detection samples and the fourth preset threshold, determine a third score according to a third magnitude relationship between the remote control malicious code family rate and the fifth preset threshold, determine a fourth score according to a fourth magnitude relationship between the absolute detection rate and a sixth preset threshold, and determine a fifth score according to a fifth magnitude relationship between the eighth quantity and a seventh preset threshold; use the sum of the first score, the second score, the third score, the fourth score, and the fifth score as the compromise score of each suspicious compromise indicator.
[0127] For specific embodiments, reference may be made to the examples shown in the above method for determining malicious compromise indicators, and details are not described herein again.
[0128] Optionally, in this embodiment, the above electronic device may be at least one network device among multiple network devices in a computer network.
[0129] Optionally, in this embodiment, the above processor may be configured to execute the following steps by a computer program:
[0130] S1. Obtain a sample detection report of a target detection sample, where the sample detection report includes: multiple compromise indicators for indicating network communication behaviors;
[0131] S2. Group the multiple compromise indicators according to a preset rule to obtain multiple communication groups;
[0132] S3. Determine the group types of the multiple communication groups, and determine a first communication group with a group type of a suspicious communication group from the multiple communication groups, where all compromise indicators in the first communication group are suspicious compromise indicators;
[0133] S4. Determine the compromise scores of the suspicious compromise indicators included in all the first communication groups according to malicious determination indicators, and determine the suspicious compromise indicators with compromise scores greater than a first preset threshold as malicious compromise indicators.
[0134] In one embodiment, the above-mentioned terminal device or server may be a node in a distributed system. Among them, the distributed system may be a blockchain system, and the blockchain system may be a distributed system formed by connecting the multiple nodes in the form of network communication. Among them, the nodes can form a peer-to-peer (P2P) network, and any form of computing device, such as electronic devices like servers and terminals, can become a node in the blockchain system by joining the peer-to-peer network.
[0135] According to one aspect of the present application, a computer program product is provided. The computer program product includes computer programs / instructions, and the computer programs / instructions contain program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part, and / or installed from a removable medium. When the computer program is executed by the central processing unit, it executes various functions provided in the embodiments of the present application.
[0136] The serial numbers of the above-mentioned embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0137] It should be noted that the computer system of the electronic device is only an example and should not impose any restrictions on the functions and usage scope of the embodiments of the present application.
[0138] The computer system includes a central processing unit (CPU), which can perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM) or the programs loaded from the storage part into the random access memory (RAM). In the random access memory, various programs and data required for system operation are also stored. The central processing unit, the read-only memory, and the random access memory are connected to each other through a bus. The input / output interface (Input / Output interface, i.e., I / O interface) is also connected to the bus.
[0139] The following components are connected to the input / output interface: an input section including a keyboard, a mouse, etc.; an output section including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage section including a hard disk, etc.; and a communication section including a network interface card such as a local area network card, a modem, etc. The communication section performs communication processing via a network such as the Internet. A drive is also connected to the input / output interface as needed. Removable media such as magnetic disks, optical disks, magneto-optical disks, semiconductor memories, etc. are installed on the drive as needed so that a computer program read from thereon can be installed into the storage section as needed.
[0140] Specifically, according to an embodiment of the present application, the processes described in each method flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section, and / or installed from a removable medium. When the computer program is executed by a central processing unit, various functions defined in the system of the present application are executed.
[0141] According to one aspect of the present application, there is provided a computer-readable storage medium, and a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the above various optional implementation manners.
[0142] Optionally, in this embodiment, the above computer-readable storage medium may be configured to store a computer program for executing the following steps:
[0143] S1, obtaining a sample detection report of a target detection sample, where the sample detection report includes: a plurality of compromise indicators for indicating network communication behaviors;
[0144] S2, grouping the plurality of compromise indicators according to a preset rule to obtain a plurality of communication groups;
[0145] S3, determining the group types of the plurality of communication groups, and determining a first communication group with a group type of a suspicious communication group from the plurality of communication groups, where all the compromise indicators in the first communication group are suspicious compromise indicators;
[0146] S4, determining a compromise score of the suspicious compromise indicators included in all the first communication groups according to a malicious determination indicator, and determining the suspicious compromise indicators with a compromise score greater than a first preset threshold as malicious compromise indicators.
[0147] Optionally, in this embodiment, those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware of the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, or the like.
[0148] The serial numbers of the above embodiments of the present invention are only for description and do not represent the superiority or inferiority of the embodiments.
[0149] If the integrated unit in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the above computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing one or more computer devices (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention.
[0150] In the above embodiments of the present invention, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0151] In the several embodiments provided by the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0152] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0153] In addition, each functional unit in various embodiments of the present invention may be integrated into one processing unit, may exist separately as individual physical units, or two or more units may be integrated into one unit. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software functional units.
[0154] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for determining malicious compromise indicators, characterized in that, Including: Obtain a sample detection report of a target detection sample, where the sample detection report includes: a plurality of compromised indicators for indicating network communication behaviors; Group the plurality of compromised indicators according to a preset rule to obtain a plurality of communication groups; Determine the group types of the plurality of communication groups, and determine a first communication group with a group type of a suspicious communication group from the plurality of communication groups, where all the compromised indicators in the first communication group are suspicious compromised indicators; Determine the compromise scores of the suspicious compromised indicators included in all the first communication groups according to a malicious determination indicator, and determine the suspicious compromised indicators with a compromise score greater than a first preset threshold as malicious compromised indicators; Wherein, determining the compromise scores of the suspicious compromised indicators included in all the first communication groups according to a malicious determination indicator includes: Determine a plurality of first detection samples associated with each suspicious compromised indicator, and determine the black detection samples and white detection samples among the plurality of first detection samples, where the plurality of first sample detection reports of the plurality of first detection samples all include: a first compromised indicator consistent with each suspicious compromised indicator; Determine a second compromised indicator with an indicator type of a suspicious compromised indicator and a third compromised indicator with an indicator type of a trusted compromised indicator among the first compromised indicators; Determine a fourth compromised indicator corresponding to the black detection sample among the second compromised indicators, and determine a fifth compromised indicator and a sixth compromised indicator among the fourth compromised indicators, where there is only one communication group in the black detection samples corresponding to the fifth compromised indicator, and the malicious code family information of the black detection samples corresponding to the sixth compromised indicator includes a remote control IP address; Determine a malicious determination indicator according to the first detection sample, the second compromised indicator, the third compromised indicator, the fourth compromised indicator, the fifth compromised indicator, the sixth compromised indicator, the black detection sample, and the white detection sample; Determine the compromise score of each suspicious compromised indicator according to the malicious determination indicator.
2. The method for determining malicious compromise indicators according to claim 1, wherein Grouping the plurality of compromised indicators according to a preset rule to obtain a plurality of communication groups includes: Dividing the compromised indicators with a domain name intersection among the plurality of compromised indicators into at least one second communication group, dividing the compromised indicators with an IP address intersection among the plurality of remaining compromised indicators into at least one third communication group, and dividing the compromised indicators without a domain name intersection and an IP address intersection into at least one fourth communication group, where the remaining compromised indicators are used to indicate the compromised indicators other than the compromised indicators in the second communication group among the plurality of compromised indicators; Determine whether there is a communication group with an IP address intersection between the IP addresses in the at least one second communication group and the at least one third communication group; If so, merge the second communication group and the third communication group into a seventh communication group, where the plurality of communication groups include: the fourth communication group, the seventh communication group.
3. The method for determining malicious compromise indicators according to claim 1, wherein Determining the group types of the plurality of communication groups includes at least one of the following: When there is a compromise indicator in each communication packet that is consistent with the compromise indicators in the whitelist, where multiple trusted compromise indicators are stored in the whitelist, determine the packet type of each communication packet as a trusted communication packet; When there is no compromise indicator in each communication packet that is consistent with the compromise indicators in the whitelist, determine the packet type of each communication packet as a suspicious communication packet; When there is an IP address with invalid communication for any compromise indicator in each communication packet, determine the packet type of each communication packet as an invalid communication packet; When all compromise indicators in each communication packet have non-Internet valid IP addresses, determine the packet type of each communication packet as an invalid communication packet.
4. The method for determining malicious compromise indicators according to claim 1, wherein Determine malicious judgment indicators according to the first detection sample, the second compromise indicator, the third compromise indicator, the fourth compromise indicator, the fifth compromise indicator, the sixth compromise indicator, the black detection sample, and the white detection sample, including: Determine the first quantity of the first detection sample, the second quantity of the second compromise indicator, the third quantity of the third compromise indicator, the fourth quantity of the fourth compromise indicator, the fifth quantity of the fifth compromise indicator, the sixth quantity of the sixth compromise indicator, the seventh quantity of the black detection sample, and the eighth quantity of the white detection sample; Determine malicious judgment indicators according to the first quantity, the second quantity, the third quantity, the fourth quantity, the fifth quantity, the sixth quantity, the seventh quantity, and the eighth quantity.
5. The method for determining malicious compromise indicators according to claim 4, characterized in that, The malicious judgment indicators include: full sample detection rate, black detection sample detection rate, remote control malicious code family rate, absolute detection rate, the quantity of the white detection sample, and the quantity of the third compromise indicator. Determine the compromise score of each suspicious compromise indicator according to the malicious judgment indicators, including: Determine the full sample detection rate of each suspicious compromise indicator according to the first quantity and the second quantity; Determine the black detection sample detection rate of each suspicious compromise indicator according to the fourth quantity and the seventh quantity; Determine the remote control malicious code family rate of each suspicious compromise indicator according to the sixth quantity and the seventh quantity; Determine the absolute detection rate of each suspicious compromise indicator according to the fifth quantity and the seventh quantity; Determine the compromise score of each suspicious compromise indicator according to the third quantity, the full sample detection rate, the black detection sample detection rate, the remote control malicious code family rate, the absolute detection rate, and the eighth quantity.
6. The method for determining malicious compromise indicators according to claim 5, wherein Determine the compromise score of each suspicious compromise indicator according to the third quantity, the full sample detection rate, the black detection sample detection rate, the remote control malicious code family rate, the absolute detection rate, and the eighth quantity, including: Determine whether the third quantity is equal to a second preset threshold, whether the full sample detection rate is greater than a third preset threshold, whether the black detection sample detection rate is greater than a fourth preset threshold, and whether the remote control malicious code family rate is greater than a fifth preset threshold; When the third quantity is equal to the second preset threshold, the full-sample detection rate is greater than the third preset threshold, the detection rate of black detection samples is greater than the fourth preset threshold, and the rate of remote-control malicious code families is greater than the fifth preset threshold, determine a first score according to the first magnitude relationship between the full-sample detection rate and the third preset threshold, determine a second score according to the second magnitude relationship between the detection rate of black detection samples and the fourth preset threshold, determine a third score according to the third magnitude relationship between the rate of remote-control malicious code families and the fifth preset threshold, determine a fourth score according to the fourth magnitude relationship between the absolute detection rate and the sixth preset threshold, and determine a fifth score according to the fifth magnitude relationship between the eighth quantity and the seventh preset threshold; Take the sum of the first score, the second score, the third score, the fourth score, and the fifth score as the compromise score of each suspicious compromise indicator.
7. A device for determining malicious compromise indicators, characterized in that, Including: An acquisition module, configured to acquire a sample detection report of a target detection sample, where the sample detection report includes: a plurality of compromise indicators for indicating network communication behaviors; A grouping module, configured to group the plurality of compromise indicators according to a preset rule to obtain a plurality of communication groups; A first determination module, configured to determine the grouping types of the plurality of communication groups, and determine a first communication group with a grouping type of a suspicious communication group from the plurality of communication groups, where all compromise indicators in the first communication group are suspicious compromise indicators; A second determination module, configured to determine the compromise scores of the suspicious compromise indicators included in all the first communication groups according to malicious determination indicators, and determine the suspicious compromise indicators with compromise scores greater than the first preset threshold as malicious compromise indicators; Wherein, the second determination module is further configured to determine a plurality of first detection samples associated with each suspicious compromise indicator, and determine black detection samples and white detection samples in the plurality of first detection samples, where the plurality of first sample detection reports of the plurality of first detection samples all include: a first compromise indicator consistent with each suspicious compromise indicator; determine a second compromise indicator with an indicator type of a suspicious compromise indicator and a third compromise indicator with an indicator type of a trusted compromise indicator in the first compromise indicator; determine a fourth compromise indicator corresponding to the black detection sample in the second compromise indicator, and determine a fifth compromise indicator and a sixth compromise indicator in the fourth compromise indicator, where there is only one communication group in the black detection samples corresponding to the fifth compromise indicator, and the malicious code family information of the black detection samples corresponding to the sixth compromise indicator includes a remote-control IP address; determine malicious determination indicators according to the first detection samples, the second compromise indicator, the third compromise indicator, the fourth compromise indicator, the fifth compromise indicator, the sixth compromise indicator, the black detection samples, and the white detection samples; and determine the compromise scores of each suspicious compromise indicator according to the malicious determination indicators.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, where the program, when running, executes the method according to any one of claims 1 to 6.
9. An electronic device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to execute the method described in any one of claims 1 to 6 through the computer program.
Citation Information
Patent Citations
Lost index extraction method and device, electronic equipment and storage medium
CN115225413A