Method and device for inferring APT organization information in attack based on parameter generator

By using a parameter generator-based inference network in the APT organization knowledge graph, context parameters are generated for multiplication interaction operations, the problem of insufficient inference completion ability of APT organization knowledge graph in the prior art is solved, and more accurate inference and automated detection, tracking and traceability are achieved.

CN115827889BActive Publication Date: 2025-05-23NAT UNIV OF DEFENSE TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211471177.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-23
Publication Date
2025-05-23
Estimated Expiration
2042-11-23

AI Technical Summary

Technical Problem

The existing APT organization knowledge graph has limited performance in inference completion, and cannot realize automated detection, tracking and traceability. Due to the limitations of additive interaction, existing knowledge representation methods cannot effectively infer tail entities in triplet data of APT organization.

Method used

Using a parameter generator-based inference network, one-hot encoding and vectorization representation of triplet data of APT organization knowledge graph is performed, relationship embedding vectors are extracted, and the parameter generator is trained, context parameters are generated for inference missing entities, and in turn constructed an inference model of multiplicative interaction.

Benefits of technology

It realizes more accurate knowledge graph inference completion, improves the automation capabilities of APT organizations in detection, tracking and traceability, breaks through the representation limitations of additive interactions, and enhances the data representation capabilities in the field of cyberspace security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115827889B_ABST
    Figure CN115827889B_ABST
Patent Text Reader

Abstract

The present invention provides a method and device for inferring APT organization information in network attacks based on a parameter generator, which realizes more accurate reasoning completion of knowledge graphs, and is helpful for the detection, tracking and tracing of APT organization information in the cyberspace security industry. The method and device include vectorizing the text data of existing triples that meet the APT organization knowledge graph; extracting the relationship embedding vectors in the embedded vector data of the triples of the APT organization, and training a parameter generator for generating context parameters for inferring missing entities; constructing an APT organization knowledge graph reasoning model, extracting triple data from the latest attack data, and for some triple data of missing entities, vectorizing the relationship data and inputting it into the trained parameter generator to output context parameters; inputting known entities and context parameters into the reasoning model, and outputting the missing entities in the triples as APT organization information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cyberspace security technology, and in particular to a method and device for inferring APT organization information in attacks based on a parameter generator. Background Art

[0002] The existing knowledge graph of APT organizations in the field of network security can only play a very limited role. It is only a macro display interface for various related events and organizational attribute information of APT organizations, and cannot realize intelligent question and answer, reasoning completion, intelligent recommendation and other functions like knowledge graphs in industries such as medicine and finance. In addition, compared with data in other fields, data in the field of network security is more special. For example: only a few valuable abnormal data in a large number of system log files can be used for the study of network security threats, network security data is widely distributed but sparsely distributed, and 0-day vulnerabilities that pose a stronger threat to network security and lack timely response measures are often more favored by APT organizations but difficult to find.

[0003] Taking into account the factors described above, the current process of detecting, tracking and tracing APT organizations still relies on the manual experience of network security experts, which means that it cannot be done automatically without human participation. In addition, there is a lack of research on theories and technologies in this area. In the process of automating the detection, tracking and tracing of APT organizations, there are still a lot of research technologies that can be explored in depth and great room for breakthroughs.

[0004] In the research of APT organization detection, tracking and tracing in the field of cyberspace security, the existing cutting-edge technology is to construct an APT organization knowledge graph through APT organization data, and use the reasoning completion technology of the knowledge graph to supplement the missing entities and relationships in the APT organization knowledge graph. Completing the missing entities and relationships is equivalent to the process of detecting, tracking and tracing the APT organization.

[0005] In the process of constructing the knowledge graph of the APT organization, the knowledge graph triple data, such as (head entity, relationship, tail entity), must first be embedded and represented. The existing knowledge representation methods all embed entities and relationships separately, and then use the neural network-based reasoning model to achieve the common task of reasoning tail entities in the knowledge graph. The aggregation function in the reasoning model can be formally defined as the following formula:

[0006] h φ (e s ,r)=φ·[e s ; r]

[0007] Among them, [es; r] is the Concat operation, which means a single-layer linear projection, es is the entity, r is the relationship, and the embedding representation technology of the head entity and the relationship can help realize the reasoning task of the missing tail entity. However, since the mathematical operation of the embedding representation of the head entity and the relationship and then associating the reasoning tail entity technology is essentially to establish an additive connection between the head entity and the relationship, this will limit the representation and association ability of the relationship. Example e s =[1,0,1],r=[0,1,0], in the calculation of the inference model, there is [e s ; r] = [1,0,1,0,1,0], which means placing the two vectors side by side and using the aggregation function h φ (e s ,r) for Φ·[e s ; r] calculation, which is also a linear calculation, e s There is actually no interaction between the two parts, although the aggregation function operates on the surface of e s and r, but in the subsequent mathematical operations, they are still approximately processed separately, which is the deficiency of additive connection. As a result, the existing representation embedding technology cannot well implement the reasoning task of the tail entity of the knowledge graph triple of the APT organization. Summary of the invention

[0008] In response to the above problems, the present invention provides a method and device for inferring APT organization information in network attacks based on a parameter generator, which realizes more accurate reasoning completion of knowledge graphs, and facilitates the detection, tracking and tracing of APT organization information in the cyberspace security industry.

[0009] The technical solution is as follows: a method for inferring APT organization information in an attack based on a parameter generator, characterized in that it includes the following steps:

[0010] For the existing triple-tuple text data that meets the APT organization knowledge graph, one-hot encoding is used for digital representation;

[0011] The encoded data of the triples are vectorized through the pre-trained embedding vector matrix to obtain the embedded vector data of the triples of the APT organization;

[0012] Extracting relational embedding vectors from the embedding vector data of the triples of the APT organization, and training a parameter generator, wherein the parameter generator is used to generate contextual parameters for missing entities in the knowledge graph of the inferred APT organization;

[0013] Construct an APT organization knowledge graph reasoning model based on a parameter generator, input known entity vectors of the embedded vector data of the triples of the APT organization and the context parameters obtained by the parameter generator into the APT organization knowledge graph reasoning model, and output the missing entity vectors in the predicted triples;

[0014] Extract triple-shaped data that meets the knowledge graph of the APT organization from the latest attack data. For the triple-shaped data that lacks one of the entities in the extracted triple-shaped data, vectorize the relationship data in the triple-shaped data, input it into the trained parameter generator, and output the context parameters.

[0015] The embedding vectors of known entities in the triples of the APT organization with missing entities and the context parameters generated by the parameter generator are input into the APT organization knowledge graph reasoning model, and the missing entities in the triples obtained by reasoning are output as the APT organization information obtained by reasoning.

[0016] Furthermore, the (head entity, attribute relationship, tail entity) in the triples in the APT organization knowledge graph include: (APT organization name, take_advantage_of, attack method), (APT organization name, use, a specific attack tool), (APT organization name, reported_by, the organization's APT report), (APT organization name, command_and_control, infrastructure), (APT organization name, utilize, vulnerability), (URL link, contain, infrastructure entity of the APT organization), (Infrastructure entity of the APT organization, permeation_and_attack, critical infrastructure), (vulnerability, identification_number, CVE vulnerability number), (vulnerability, belonged_to, attack method).

[0017] Furthermore, the parameter generator is constructed and trained based on the multi-layer perceptron neural network model, and the context parameter g generated by the parameter generator is MLP It is expressed as:

[0018] g MLP =MLP(Rr)

[0019] Among them, R is the embedding matrix of the relation embedding vector with x rows and y columns, x is the dimension of the embedding vector, y is the total number of relations, r is the one-hot encoded relation embedding vector, and MLP represents the multi-layer perceptron neural network model.

[0020] Furthermore, the parameter generator is constructed and trained based on the linear mapping model, and the context parameter g generated by the parameter generator islinear It is expressed as:

[0021] g linear =W linear Rr+b

[0022] Among them, W linear and R are both trainable parameters, W linear is a matrix with j rows and k columns, j is the dimension of the generated parameters, k is the dimension of the relationship embedding vector; R is the embedding matrix of the relationship embedding vector with x rows and y columns, x is the dimension of the embedding vector, and b is the bias vector.

[0023] Further, the parameter generator is constructed and trained based on the parameter query matrix, and the context parameter g generated by the parameter generator is lookup It is expressed as:

[0024] g lookup (r) = W lookup r

[0025] Among them, r is the one-hot encoded relation embedding vector, W lookup is a parameter query matrix with n rows and m columns, where n is the total number of relations, m is the dimension of the parameters for generating relations, and for each uniquely encoded relation embedding vector r, the dimension of the relation embedding vector r is n, and there are context parameters of the relation embedding vector r in the parameter query matrix.

[0026] Furthermore, the aggregation function of the APT organization knowledge graph reasoning model is expressed as:

[0027] f θ (x) = θ*x

[0028] θ=g;x=h Φ (et)=et

[0029] Among them, g represents the context parameters obtained by the parameter generator, and et represents the embedding vector of the tail entity.

[0030] Furthermore, when training the parameter generator, the data set used includes multiple types of data in the field of network security, including data on malicious code families, malicious traffic data, and APT organization data.

[0031] A computer device, characterized in that it comprises: a processor, a memory and a program; the program is stored in the memory, and the processor calls the program stored in the memory to execute the above-mentioned method of APT organization information in parameter generator-based reasoning attack.

[0032] A computer-readable storage medium, characterized in that: the computer-readable storage medium is used to store a program, and the program is used in the above-mentioned method of APT organization information in parameter generator-based reasoning attack.

[0033] The prior art is limited by the additive interaction nature of entities and relationships when reasoning about APT organization information through knowledge graphs. The present invention innovatively uses the relationships in the triple data of the APT organization knowledge graph in cyberspace security as context parameters for generating head / tail entities, and then uses the embedding vector of the entity and the context parameter generated by the relationship as input for multiplicative operations through a neural network-based reasoning model, that is, the original additive interaction of entities and relationships is updated to multiplicative interaction, breaking through the limitation of additive operations for knowledge representation and improving the data representation capability of the APT organization knowledge graph in the field of cyberspace security. This brings an innovative and effective implementation plan for using the knowledge reasoning completion technology in the APT organization knowledge graph to realize the detection, tracking and tracing tasks of APT organizations. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 A schematic diagram of the steps of a method for organizing APT information in a parameter generator-based reasoning attack in one embodiment of the present invention;

[0035] Figure 2 A schematic diagram of a triplet of two head entities connected to two tail entities through four relationships;

[0036] Figure 3 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0037] For a long time, in the field of cyberspace security, APT organizations have been modeled and knowledge bases have been established. The knowledge bases have been used to simulate attacks and repeat training, so that attribution can be performed around existing knowledge data, malicious behaviors can be detected, and malicious network activities can be linked to specific organizations or individuals. Therefore, studying the detection, attribution and tracing technology of APT attacks is a core task to assist in the rapid detection of highly concealed unknown threats such as APT attacks, to associate different attack events from the same threat, and to expand the scope of clues.

[0038] The detection, tracking and tracing of APT organizations have always been the key research issues in the field of cyberspace security. This technological invention is a technological innovation studied to solve this problem.

[0039] See Figure 1 The method of the present invention for inferring APT organization information in an attack based on a parameter generator comprises the following steps:

[0040] Step 1: Use one-hot encoding to digitally represent the existing text data in the form of triples that meet the knowledge graph of the APT organization;

[0041] Step 2: Vectorize the triplet encoding data through the pre-trained embedding vector matrix to obtain the embedded vector data of the triplet of the APT organization;

[0042] Step 3: extract the relation embedding vectors in the embedding vector data of the triples of the APT organization, and train a parameter generator, wherein the parameter generator is used to generate context parameters for missing entities in the knowledge graph of the inferred APT organization;

[0043] Step 4: Build the APT organization knowledge graph reasoning model based on the parameter generator, input the known entity vectors of the embedded vector data of the APT organization's triples and the context parameters obtained through the parameter generator into the APT organization knowledge graph reasoning model, and output the missing entity vectors in the predicted triples;

[0044] Step 5: Extract triple-shaped data that meets the APT organization knowledge graph from the latest attack data. For the triple-shaped data that lacks one of the entities in the extracted triple-shaped data, vectorize the relationship data in the triple-shaped data, input it into the trained parameter generator, and output the context parameters.

[0045] Step 6: Input the embedding vector of the known entity in the triple of the APT organization with missing entity and the context parameter generated by the parameter generator into the APT organization knowledge graph reasoning model, output the missing entity in the triple obtained by reasoning, and use it as the APT organization information obtained by reasoning, so as to infer the APT organization information that launched the attack from the latest attack data.

[0046] In an embodiment of the present invention, the relational data in the triple data of the APT organization knowledge graph in the field of cyberspace security is used to generate parameters for its contextual head / tail entity data, so as to further generate triple knowledge representation more efficiently, thereby realizing the research on the detection, tracking and tracing of APT organizations. In an embodiment of the present invention, the reasoning model performs multiplicative interactive operations in mathematical operations on the head / tail entity data and the relational data in the triple data of the APT organization knowledge graph in the field of cyberspace security, breaking through the problem that the existing knowledge representation technology is limited in its representation ability of the additive interactive operations used for the head / tail entity data and the relational data.

[0047] Specifically, in one embodiment of the present invention, in step 1, the triple of the APT organization is constructed in the form of a triple based on the APT organization knowledge graph, and the triples in the APT organization knowledge graph (head entity, attribute relationship, tail entity) include: (APT organization name, take_advantage_of, attack means), (APT organization name, use, a specific attack tool), (APT organization name, reported_by, the APT report of the organization), (APT organization name, command_and_control, infrastructure), (APT organization name, utilize, vulnerability), (URL link, contain, infrastructure entity of the APT organization), (Infrastructure entity of the APT organization, permeation_and_attack, critical infrastructure), (vulnerability, identification_number, CVE vulnerability number), (vulnerability, belonged_to, attack means).

[0048] In the triples of the APT organization knowledge graph, the specific relationships between the head entity and the tail entity can be: take_advantage_of means utilization, use means use, reported_by means reported, command_and_control means command and control, utilize means utilization, contain means containment, permeation_and_attack means penetration and attack, identification_number means identification code, and belonged_to means belonging to.

[0049] The construction of the APT organization knowledge graph in the field of network security is a method that combines the attack organization knowledge graph, natural language processing technology and template crawlers to achieve semi-automatic collection of APT and malicious code family intelligence. Actively crawl the APT analysis reports that have been released and the threat data obtained in cooperation with security companies. The main data sources include: structured data (intelligence database, STIX intelligence, etc.), semi-structured data (open source intelligence communities such as Alienvault, IBM x-force intelligence community website, +.MISP, ATT&CK, etc.), and unstructured data (Talos security blog, Github APT report, etc.). For semi-structured data, knowledge relationships such as "belong to", "use", "include", and "module similarity" can be extracted through the jump relationship of website links. For unstructured data, regular expressions are mainly used to extract threat indicators (IP, domain name, file hash, etc.), and keyword matching is used to extract the relationship between reports and organizations. The basic implementation idea is mainly carried out in two steps. The first is to design the attack organization knowledge graph ontology to determine the intelligence collection type, attributes and related dictionary specification definitions; the second is to combine crawlers and natural language processing technology to build an intelligence operation system that can be quickly expanded and extracted.

[0050] Specifically, in step 1, the text data of the existing APT organization triples organized in the form of triples of the APT organization knowledge graph are digitally represented using one-hot encoding.

[0051] Specifically, in step 2, the encoded data of the APT organization's triples obtained in step 1 are vectorized through a pre-trained embedding vector matrix to obtain the embedded vector data for each triple data.

[0052] In each embodiment, the contents of steps 1 and 2 are substantially the same.

[0053] In step 3, a parameter generator is trained for the relationship embedding vector in the embedding vector data of the triple, which takes the head / tail entity as the context environment. The parameter generator is used to generate context parameters for reasoning missing entities. The parameter generator will be used to obtain the parameters of the neural network that predicts the target entity with the traditional entity embedding vector. That is, the parameters of the reasoning model built based on the neural network are no longer obtained by training, but are provided by the parameter generator generated by the relationship.

[0054] When training the parameter generator, the dataset used includes multiple types of data in the field of network security, including data of malicious code families, malicious traffic data, and APT organization data. The purpose is to allow the model to learn the basic characteristics of data in the field of network security, so that the model can better understand network security data and more accurately generate model parameters and data representation vectors. The training process is to enable the model to have the ability to handle various problems in the field of network security, and when the model is used, the model solves the network security problems corresponding to a type of data to be processed.

[0055] Specifically, in the first embodiment, a parameter generator is constructed and trained based on a multi-layer perceptron neural network model, and the context parameter g generated by the parameter generator is MLP It is expressed as:

[0056] g MLP =MLP(Rr)

[0057] Among them, R is the embedding matrix of the relation embedding vector with x rows and y columns, x is the dimension of the embedding vector, y is the total number of relations, r is the one-hot encoded relation embedding vector, and MLP represents the multi-layer perceptron neural network model.

[0058] In step 4, after obtaining the embedding vector for the existing APT organization knowledge graph triple data set, an APT organization knowledge graph reasoning model is constructed based on the parameter generator, and the known entity vectors and context parameters of the embedding vector data of the APT organization's triples are input into the reasoning model. The APT organization knowledge graph reasoning model can output the missing entity vectors in the predicted triples; in the first embodiment, the aggregation function of the APT organization knowledge graph reasoning model is expressed as:

[0059] f θ1 (x) = θ*x

[0060] θ=g MLP ; g MLP =MLP(Rr); x = h Φ (e t )=e t

[0061] So we have: f θ1 (x)=(MLP(Rr))*e t , e t is the embedding vector of the tail entity;

[0062] Then in step 5, the triple data that satisfies the APT organization knowledge graph is extracted from the latest attack data. For the triple data of the APT organization name with missing head entities in the extracted triple data, the relational data in the triple is vectorized and input into the trained parameter generator to output the context parameter g.MLP ;

[0063] In step 6, the context parameter g is obtained by combining a known tail entity vector in the triple and passing it through the parameter generator MLP Input f θ1 (x), we can get f θ1 (x) The missing head entity obtained by reasoning, that is, the missing APT organization name, can complete the APT organization knowledge graph, thereby realizing the inference of the APT organization information that launched the attack from the latest attack data.

[0064] Specifically in the second embodiment, a parameter generator is constructed and trained based on the parameter query matrix. The parameter query matrix W lookup is a matrix with n rows and m columns, where n is the total number of relations and m is the dimension of the parameters for generating relations. For each uniquely encoded relation embedding vector r, the dimension of the relation embedding vector r is n. In the parameter query matrix, there is a corresponding context parameter of the relation embedding vector r. The parameter g generated by the parameter generator lookup (r) is expressed as: g lookup (r) = W lookup r.

[0065] In step 4, after obtaining the embedding vector for the existing APT organization knowledge graph triple data set, an APT organization knowledge graph reasoning model is constructed based on the parameter generator, and the known entity vectors and context parameters of the embedding vector data of the APT organization's triples are input into the reasoning model. The APT organization knowledge graph reasoning model can output the missing entity vectors in the predicted triples; in the second embodiment, the aggregation function of the APT organization knowledge graph reasoning model is expressed as:

[0066] f θ2 (x) = θ*x

[0067] θ=g lookup ; g lookup (r) = W lookup r; x = h Φ (et)=e t

[0068] So we have: f θ2 (x) = W lookup r*e t , e t is the embedding vector of the tail entity;

[0069] Then in step 5, the triple data that satisfies the APT organization knowledge graph is extracted from the latest attack data. For the triple data of the APT organization name with missing head entities in the extracted triple data, the relational data in the triple is vectorized and input into the trained parameter generator to output the context parameter g. lookup ;

[0070] In step 6, the context parameter g is obtained by combining a known tail entity vector in the triple and passing it through the parameter generator lookup Input f θ2 (x), we can get f θ2 (x) The missing head entity obtained by reasoning, that is, the missing APT organization name, can complete the APT organization knowledge graph, thereby realizing the inference of the APT organization information that launched the attack from the latest attack data.

[0071] Specifically, in the third embodiment, a parameter generator is constructed and trained based on a linear mapping function to generate context parameters of a relationship vector. The context parameters g generated by the parameter generator are lookup (r) is expressed as:

[0072] g linear =W linear Rr+b

[0073] Among them, W linear and R are both trainable parameters, W linear is a matrix with j rows and k columns, where j is the dimension of the generated parameters and k is the dimension of the relationship embedding vector; R is the embedding matrix of the relationship embedding vector with x rows and y columns, where x is the dimension of the embedding vector and y is the total number of relationships, where k = x; b is the bias vector, whose dimension is z, which is consistent with the dimension of the generated parameters, z = j.

[0074] In step 4, after obtaining the embedding vector for the existing APT organization knowledge graph triple data set, an APT organization knowledge graph reasoning model is constructed based on the parameter generator, and the known entity vectors and context parameters of the embedding vector data of the APT organization's triples are input into the reasoning model. The APT organization knowledge graph reasoning model can output the missing entity vectors in the predicted triples; in the third embodiment, the aggregation function of the APT organization knowledge graph reasoning model is expressed as:

[0075] f θ3 (x) = θ*x

[0076] θ=g linear ; g linear =W linear Rr+b;x=h Φ (e t)=e t

[0077] So we have: f θ3 (x)=(W linear Rr+b)*e t , e t is the embedding vector of the tail entity;

[0078] In step 5, the latest APT attack sample data or APT attack trace data on the victim host is extracted to obtain triple data in the format of the APT organization knowledge graph. For the partial triple data in which one of the entities is missing in the extracted triple data, the relational data in the triple of the missing entity is vectorized and input into the trained parameter generator to output the context parameter g. linear ;

[0079] In step 6, the context parameter g is obtained by combining a known tail entity vector in the triple and passing it through the parameter generator linear Input f θ3 (x), we can get f θ3 (x) The missing head entity obtained by reasoning, that is, the missing APT organization name, can complete the APT organization knowledge graph, thereby realizing the inference of the APT organization information that launched the attack from the latest attack data.

[0080] In datasets with small relationships, using a multi-layer perceptron neural network model will produce more satisfactory results. It can solve the problem of overfitting when training datasets with small relationships using linear function mapping methods.

[0081] In the present invention, the training of the inference model and parameter generator is to initialize the parameters of the machine learning or deep learning model for a large-scale data set, formulate an objective function according to the core idea of ​​the algorithm, which is usually also called the loss function in the training stage, and set the threshold condition that the output of the objective function should meet. For the input of the digital vector form of the large-scale data set, let the machine traverse and execute all the input data according to the machine learning algorithm or the deep learning algorithm. During the cyclic processing, the model continuously adjusts the parameters of the model in order to achieve the threshold condition of the objective function, and finally meets the threshold. At this time, the parameters of the model are the optimal parameters relative to the input data set. The model with trained parameters can realize the tasks of classification, clustering or prediction of new data.

[0082] In order to solve the problem of limited representation caused by additive interaction between entities and relationships in mathematical operations, this technical invention proposes using the relationship data in the triple data to generate parameters of the context environment of the head / tail entity in the knowledge graph of the APT organization in the field of cyberspace security, so that the existing knowledge representation method replaces the additive interaction process between the head / tail entity and the relationship in mathematical operations with the multiplicative interaction process in mathematical operations, avoiding the mutual independence and non-interaction of entities and relationships in the in-depth processing process, thereby removing the hindering factor of the additive limitation of entities and relationships.

[0083] The present invention replaces and updates the mathematical additive interaction operation between the head entity and the relationship data in the triple of the APT organization knowledge graph with the mathematical multiplicative interaction operation between the head entity and the relationship data in the triple, which solves the problem that the additive interaction between entities and relationships affects each other on the surface but is independent of each other in the actual mathematical operation process. The mathematical multiplicative interaction operation between the head entity and the relationship data ensures that during the mathematical operation process, the embedding vectors of the head entity and the relationship affect each other and jointly play the role of data to determine the embedding representation of the tail entity, thereby achieving more accurate knowledge graph reasoning and completion tasks, which corresponds to the detection, tracking and tracing research issues of APT organizations in the cyberspace security industry.

[0084] The following example is used to illustrate the shortcomings of the additive interactive nature of embedding entities and relationships to represent re-reasoning in the knowledge graph reasoning of the prior art, and to contrast the superiority of the method of the present invention in which the head / tail entity data and the relationship data in the triple data of the APT organization knowledge graph in the field of cyberspace security are subjected to multiplicative interactive operations in mathematical operations.

[0085] Figure 2 It shows the triple form of two head entities connected to the other two tail entities through four relations. Figure 2 In the format of the triple data of the association between entities and relations, the format is listed in Table 1 below.

[0086] Triple data: (head entity, relationship, tail entity) <![CDATA[(e 0 ,r 0 ,e 2 )]]> <![CDATA[(e 0 ,r 1 ,e 3 )]]> <![CDATA[(e 1 ,r 1 ,e 2 )]]> <![CDATA[(e 1 ,r 0 ,e 3 )]]>

[0087] Table 1

[0088] For the perception layer of a neural network or the aggregation function of a linear mapping function, the inference model is formally defined here as the following formula:

[0089] h φ (e s ,r)=φ·[e s ; r]

[0090] [e s ; r] is the Concat operation, which means a single-layer linear projection. Because the Concat operation makes the entity es and the relation r are independent of each other and can be written as:

[0091] h φ (e s ,r)=φ s e s +φ r r r

[0092] According to the data format listed in Table 1 above, use the above aggregation function h φ (e s ,r) formula, bringing in the embedded representation data of entities and relationships, we can get the following formula:

[0093] e 2 =φ e e 0 +φ r r 0

[0094] e 3 =φ e e 0 +φ r r 1

[0095] e 3 =φ e e 1 +φ r r 0

[0096] e 3 =φ e e 1 +φ r r 1

[0097] Subtract the above four expressions to get the following two expressions:

[0098] (e 2 -e 3 )=φ r (r 0 -r 1 )

[0099] (e 3 -e 2 )=φ r (r 0 -r 1 )

[0100] The two formulas obtained by subtracting the formulas are very contradictory. The system of equations can only be solved when the following conditions are met. The specific conditions are:

[0101] e2 =e 3 : This group of solutions will lead to e 2 ,e 3 Inability to distinguish;

[0102] φ r =0 or r 0 =r 1 : This group of solutions will lead to r 0 ,r 1 Indistinguishable or ineffective;

[0103] φ e =0 or e 0 =e 1 : This group of solutions will lead to e 0 ,e 1 Cannot distinguish.

[0104] However, after the above conditions are met, the entity or relationship will become meaningless. Therefore, the model of entity and relationship additive interaction cannot handle this very simple situation. The main reason is that although the aggregate function operates on the surface of the entity s and relation r, but in the subsequent mathematical operations, they are still approximately processed separately. Through this example, the problems caused by the additive interaction operation of entities and relations by the existing knowledge representation technology are fully demonstrated, and the shortcomings of the additive interaction operation of entities and relations are explained.

[0105] For the missing head entity e s (e s ,r,e t ), the embedding vector r of the relationship and the e of the tail entity in the prior art t The addition operation of the inference model is: φ (e t ,r)=φ h ·[e t ; r],f φ (x) = φ f ·(φ h ·[e t ; r]), so r and e t Since it is essentially a concat operation, it is an additive operation.

[0106] Using the method of the present invention, taking Example 3 as an example, in the parameter generator constructed based on the linear mapping function, the corresponding inference model infers the missing head entity e s The specific aggregation function is:

[0107] f θ3 (x)=(W linear Rr+b)*e t

[0108] Through the decomposition operation of the above formula, in the first part, we can get the product form of the relationship vector r and the entity vector et, that is, the multiplicative interaction process between the tail entity and the relationship is realized, and therefore, it has the characteristics of multiplicative interaction.

[0109] The previous model is to use the tail entity vector e t It is concatenated with the relation vector Rr to form a new vector as the input vector x, x = (Rr, e t ), for example: e t = (1, 2, 3), Rr = (4, 5, 6), then x = (Rr, e t ) = (4, 5, 6, 1, 2, 3,), resulting in e t During the calculation process, Rr and Rr do not affect each other and are independent of each other.

[0110] In Example 3, the f of the inference model θ3 (x)=(W linear Rr+b)*e t In the prior art, a=W is replaced by y=ax+b. linear Rr+b,x=e t , removing the b part in y=ax+b. Therefore, Rr and e t Through this product form, a multiplicative relationship is established, with W linear R t The product part of , thereby breaking through the limitation of additive operation for knowledge representation, and improving the data representation ability of APT organization knowledge graph in the field of cyberspace security. This brings an innovative and effective implementation plan for using the knowledge reasoning completion technology in the APT organization knowledge graph to realize the detection, tracking and tracing tasks of APT organizations.

[0111] In an embodiment of the present invention, a computer device is also provided, comprising: a processor, a memory and a program;

[0112] The program is stored in the memory, and the processor calls the program stored in the memory to execute the above-mentioned method of inferring APT organization information in the attack based on the parameter generator.

[0113] The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 3As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected through a bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for organizing APT information in an attack based on parameter generator reasoning is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a key, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse, etc.

[0114] The memory may be, but is not limited to, a random access memory (RAM), a read only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable read-only memory (EEPROM), etc. The memory is used to store programs, and the processor executes the programs after receiving the execution instruction.

[0115] The processor can be an integrated circuit chip with signal processing capabilities. The above-mentioned processor can be a general-purpose processor, including a central processing unit (Central Processing Unit, referred to as: CPU), a network processor (Network Processor, referred to as: NP), etc. The processor can also be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application-specific integrated circuits (Application Specific Integrated Circuit, ASIC), field programmable gate arrays (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The various methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0116] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0117] In an embodiment of the present invention, a computer-readable storage medium is further provided, and the computer-readable storage medium is used to store a program, and the program is used to execute the above-mentioned method of APT organization information in parameter generator-based reasoning attack.

[0118] Those skilled in the art will appreciate that the embodiments of the embodiments of the present invention may be provided as methods, computer devices, or computer program products. Therefore, the embodiments of the present invention may take the form of complete hardware embodiments, complete software embodiments, or embodiments combining software and hardware. Moreover, the embodiments of the present invention may take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0119] The embodiments of the present invention are described with reference to flowcharts of methods, computer devices, or computer program products according to the embodiments of the present invention. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate a device for implementing the functions specified in the flowchart.

[0120] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in the flowchart.

[0121] The above is a detailed introduction to the application of the method, system, computer device, and computer-readable storage medium based on parameter generator reasoning attack provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. Method for inferring APT organization information in attack based on parameter generator, It is characterized in that The following steps are involved: For the existing triple-tuple text data that meets the APT organization knowledge graph, one-hot encoding is used for digital representation; The encoded data of the triples are vectorized through the pre-trained embedding vector matrix to obtain the embedded vector data of the triples of the APT organization; Extracting relational embedding vectors from the embedding vector data of the triples of the APT organization, and training a parameter generator, wherein the parameter generator is used to generate contextual parameters for missing entities in the knowledge graph of the inferred APT organization; Construct an APT organization knowledge graph reasoning model based on a parameter generator, input known entity vectors of the embedded vector data of the triples of the APT organization and the context parameters obtained by the parameter generator into the APT organization knowledge graph reasoning model, and output the missing entity vectors in the predicted triples; Extract triple-shaped data that meets the knowledge graph of the APT organization from the latest attack data. For the triple-shaped data that lacks one of the entities in the extracted triple-shaped data, vectorize the relationship data in the triple-shaped data, input it into the trained parameter generator, and output the context parameters. The embedding vectors of known entities in the triples of the APT organization with missing entities and the context parameters generated by the parameter generator are input into the APT organization knowledge graph reasoning model, and the missing entities in the triples obtained by reasoning are output as the APT organization information obtained by reasoning.

2. The method for inferring APT organization information in attack based on parameter generator according to claim 1, Features: The triples (head entity, attribute relationship, tail entity) in the APT organization knowledge graph include: (APT organization name, take_advantage_of, attack method), (APT organization name, use, a specific attack tool), (APT organization name, reported_by, the organization's APT report), (APT organization name, command_and_control, infrastructure), (APT organization name, utilize, vulnerability), (URL link, contain, APT organization's infrastructure entity), (APT organization's infrastructure entity, permeation_and_attack, critical infrastructure), (vulnerability, identification_number, CVE vulnerability number), (vulnerability, belonged_to, attack method).

3. The method for inferring APT organization information in attack based on parameter generator according to claim 1, Features: The parameter generator is constructed and trained based on a multi-layer perceptron neural network model, and the context parameter g generated by the parameter generator is MLP It is expressed as: g MLP =MLP(Rr) Among them, R is the embedding matrix of the relation embedding vector with x rows and y columns, x is the dimension of the embedding vector, y is the total number of relations, r is the one-hot encoded relation embedding vector, and MLP represents the multi-layer perceptron neural network model.

4. The method for inferring APT organization information in attack based on parameter generator according to claim 1, Features: The parameter generator is constructed and trained based on the linear mapping model, and the context parameter g generated by the parameter generator is linear It is expressed as: g linear =W linear Rr+b Among them, W linear and R are both trainable parameters, W linear is a matrix with j rows and k columns, j is the dimension of the generated parameters, k is the dimension of the relationship embedding vector; R is the embedding matrix of the relationship embedding vector with x rows and y columns, x is the dimension of the embedding vector, and b is the bias vector.

5. The method for inferring APT organization information in attack based on parameter generator according to claim 1, Features: The parameter generator is constructed and trained based on the parameter query matrix, and the context parameter g generated by the parameter generator is lookup It is expressed as: g lookup (r)=W lookup r Among them, r is the one-hot encoded relation embedding vector, W lookup is a parameter query matrix with n rows and m columns, where n is the total number of relations, m is the dimension of the parameters for generating relations, and for each uniquely encoded relation embedding vector r, the dimension of the relation embedding vector r is n, and there are context parameters of the relation embedding vector r in the parameter query matrix.

6. The method for inferring APT organization information in attack based on parameter generator according to claim 1, Features: The aggregation function of the APT organization knowledge graph reasoning model is expressed as: f θ (x)=θ*x θ=g;x=h Φ (e t ) Among them, g represents the context parameter obtained by the parameter generator, e t Represented as the embedding vector of the entity, x is the embedding vector of the entity through the merging function h Φ (e t )The extracted entity features.

7. The method for inferring APT organization information in attack based on parameter generator according to claim 1, Features: When training the parameter generator, the data sets used include multiple categories of data in the field of network security, including data on malicious code families, malicious traffic data, and APT organization data.

8. A computer device, It is characterized in that It comprises: a processor, a memory and a program; the program is stored in the memory, and the processor calls the program stored in the memory to execute the method of APT organization information in parameter generator-based reasoning attack as described in claim 1.

9. A computer-readable storage medium, Features: The computer-readable storage medium is used to store a program, and the program is used to execute the method of inferring APT organization information in an attack based on a parameter generator as described in claim 1.

Citation Information

Patent Citations

  • Knowledge graph relationship prediction method and device based on attention mechanism

    CN113535984A

  • Method and device for text-enhanced knowledge graph joint representation learning

    US20220147836A1