Automated attack-defense confrontation evaluation method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202211652180.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-21
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-12-21
AI Technical Summary
目前,面向安全推演的攻防对抗通常依赖于蓝方设置攻击手段、红方设置防御手段以及导调介入干预,进行人工判定,具有耗时长、准确率低、说服力不强等问题
[0038]本发明实施例提供了一种自动化攻防对抗评估方法、装置、电子设备及存储介质,本发明获取具有多元攻防知识的网络攻防知识图谱,基于网络攻防知识图谱中记载的多维信息及映射关系,对攻防对抗中攻击的攻击装备及目标资产进行推演,判定攻击对抗结果,自动化地实现基于攻防机理的攻防对抗结果评估,从而避免人工介入,可有效提升安全推演的效率与准确率。
Smart Images

Figure CN115883243B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to an automated attack and defense assessment method, apparatus, electronic device, and storage medium. Background Technology
[0002] As the security levels and protection requirements of large-scale equipment continue to rise, cybersecurity risks within such equipment are receiving increasing attention. For some specialized equipment, attack testing methods are not suitable for verifying security performance; therefore, it is necessary to rely on attack-defense simulations to test it. Currently, attack-defense simulations for security purposes typically rely on the blue team setting up attack methods, the red team setting up defense methods, and intervention from the intermediary, followed by manual judgment. This approach suffers from drawbacks such as being time-consuming, having low accuracy, and lacking persuasiveness. Summary of the Invention
[0003] To address the problem that attack and defense confrontations oriented towards security simulation rely too heavily on manual evaluation, this invention provides an automated attack and defense confrontation evaluation method, device, electronic device, and storage medium, which can automatically evaluate the results of attack and defense confrontations based on attack and defense mechanisms.
[0004] In a first aspect, embodiments of the present invention provide an automated attack and defense assessment method, comprising:
[0005] Obtain a network attack and defense knowledge graph; the network attack and defense knowledge graph records asset information, attack equipment information, attack behavior information, defense equipment information and defense behavior information, the relationship between asset information and defense equipment information, and the mapping relationship between attack equipment information and attack behavior information, defense equipment information and defense behavior information, and attack behavior information and defense behavior information.
[0006] Determine the attack path planning scheme for offensive and defensive confrontation;
[0007] Based on the attack path planning scheme, the attack equipment and target assets for this round of attack are determined;
[0008] Based on the attack equipment and the network attack and defense knowledge graph, the attack behaviors involved in this round of attack are determined;
[0009] Based on the attack behavior and the network attack and defense knowledge graph, determine the defensive behaviors involved in this round of attack;
[0010] Based on the aforementioned defensive behaviors and the network attack and defense knowledge graph, the defensive equipment involved in this round of attack is determined;
[0011] Based on the defense equipment and the network attack and defense knowledge graph, it is determined whether there is a connection between the defense equipment and the target asset in this round of attack. If there is no connection, the round of attack is considered successful; if there is a connection, the round of attack is considered unsuccessful.
[0012] Optionally, the automated attack and defense assessment method further includes:
[0013] Determine whether to end the confrontation; otherwise, return to the steps of determining the attack equipment and target assets for this round of attack based on the attack path planning scheme.
[0014] Optionally, the network attack and defense knowledge graph is constructed in the following way:
[0015] Obtain network attack and defense data;
[0016] The network attack and defense data is classified into five dimensions, corresponding to five categories of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior.
[0017] Based on the categorized network attack and defense data, a network attack and defense knowledge graph is constructed.
[0018] Optionally, the graph construction yields a network attack and defense knowledge graph, including:
[0019] Construct the ontology layer relationship graph (OG) and the data layer relationship graph (DG);
[0020] The ontology hierarchy diagram (OG) is used to represent the hierarchical relationships between concepts. OG =<CO,RO> Where CO represents a concept node and RO represents the relationship edge between concepts; the ontology layer relationship graph OG includes five-dimensional concepts, corresponding to five types of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior, and the concept nodes are connected according to the hierarchical relationship of the concepts.
[0021] The data layer relationship diagram (DG) is used to represent the correspondence between entities, DG =<ED,RD> , where ED represents an entity node with entity attributes, and RD represents the relationship edge between entities; the entity nodes in the data layer relationship graph DG are connected to the lowest level concepts in the ontology layer relationship graph OG, and the corresponding entity attribute information is recorded.
[0022] Optionally, the attack behavior information in the network attack and defense knowledge graph comes from the attack framework, and the defense behavior information comes from the defense framework.
[0023] Optionally, the mapping relationships between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information in the network attack and defense knowledge graph are determined in the following way:
[0024] Based on the name of the attack equipment and the attack framework, establish a mapping relationship between attack equipment information and attack behavior information;
[0025] Based on the names of the defensive equipment and the aforementioned defensive framework, a mapping relationship between defensive equipment information and defensive behavior information is established;
[0026] Based on the attack framework and the defense framework, a mapping relationship is established between attack behavior information and defense behavior information.
[0027] Optionally, the attack framework adopts the ATT&CK attack framework; the defense framework adopts the Engage defense framework.
[0028] Secondly, embodiments of the present invention also provide an automated attack and defense assessment device, comprising:
[0029] The knowledge graph acquisition module is used to acquire network attack and defense knowledge graphs. The network attack and defense knowledge graphs contain asset information, attack equipment information, attack behavior information, defense equipment information, and defense behavior information, as well as mapping relationships between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information.
[0030] The scheme determination module is used to determine the attack path planning scheme for offensive and defensive confrontation;
[0031] The target determination module is used to determine the attack equipment and target assets for this round of attack based on the attack path planning scheme.
[0032] The first inference module is used to determine the attack behaviors involved in this round of attack based on the attack equipment and the network attack and defense knowledge graph.
[0033] The second deduction module is used to determine the defensive behaviors involved in this round of attack based on the attack behavior and the network attack and defense knowledge graph.
[0034] The third inference module is used to determine the defensive equipment involved in this round of attack based on the defensive behavior and the network attack and defense knowledge graph.
[0035] The deduction and judgment module is used to determine whether there is a correlation between the defense equipment and the target asset in this round of attack based on the defense equipment and the network attack and defense knowledge graph. If there is no correlation, the attack is judged to be successful; if there is a correlation, the attack is judged to be unsuccessful.
[0036] Thirdly, embodiments of the present invention also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the method described in any embodiment of this specification.
[0037] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the methods described in any embodiment of this specification.
[0038] This invention provides an automated attack and defense confrontation assessment method, device, electronic device, and storage medium. This invention acquires a network attack and defense knowledge graph with diverse attack and defense knowledge. Based on the multidimensional information and mapping relationships recorded in the network attack and defense knowledge graph, it deduces the attack equipment and target assets in the attack and defense confrontation, determines the attack confrontation result, and automatically realizes the assessment of the attack and defense confrontation result based on the attack and defense mechanism, thereby avoiding manual intervention and effectively improving the efficiency and accuracy of security deduction. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0040] Figure 1 This is a flowchart of an automated attack and defense confrontation evaluation method provided by an embodiment of the present invention;
[0041] Figure 2 This is a five-dimensional diagram illustrating the ontology of network attack and defense.
[0042] Figure 3 This is a flowchart of another automated attack and defense confrontation evaluation method provided by an embodiment of the present invention;
[0043] Figure 4 This is a hardware architecture diagram of an electronic device provided in an embodiment of the present invention;
[0044] Figure 5 This is a structural diagram of an automated attack and defense assessment device provided in an embodiment of the present invention. Detailed Implementation
[0045] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0046] Automated attack and defense simulation refers to automated attack and defense exercises for cyberspace security. Based on network topology, asset information, and network attack and defense technologies, it enables a cyberspace game between a Red Team and a Blue Team, contributing to the development of the cyberspace security industry and equipment. As mentioned earlier, current attack and defense simulations for security typically rely on the Blue Team setting attack methods, the Red Team setting defense methods, and intervention from the intermediary, followed by manual judgment. This approach suffers from problems such as high time consumption, low accuracy, and weak persuasiveness. Automated attack and defense simulation has become an urgent problem to be solved in the development of security simulations for large-scale equipment. Therefore, this invention provides an automated attack and defense simulation evaluation method, device, electronic equipment, and storage medium based on attack and defense mechanisms.
[0047] The following describes the specific implementation of the above concept.
[0048] Please refer to Figure 1 This invention provides an automated attack and defense assessment method, which includes:
[0049] Step 100: Obtain a network attack and defense knowledge graph; the network attack and defense knowledge graph contains asset information, attack equipment information, attack behavior information, defense equipment information and defense behavior information, the relationship between asset information and defense equipment information, and the mapping relationship between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information.
[0050] The relationship between asset information and defense equipment information reflects the relationship between each asset and the defense equipment it exists in; network attack and defense knowledge graphs can also typically include the relationship between asset information and attack equipment information, reflecting the relationship between each asset and the attack equipment acting on it.
[0051] Step 102: Determine the attack path planning scheme for offensive and defensive confrontation;
[0052] The attack path planning scheme includes at least one attack path, each attack path includes at least one attack node, and each attack node corresponds to one round of attack, including the attack equipment and target assets of that round of attack.
[0053] Step 104: Based on the attack path planning scheme, determine the attack equipment and target assets for this round of attack;
[0054] Step 106: Based on the attack equipment and the network attack and defense knowledge graph, determine the attack behaviors involved in this round of attack;
[0055] Step 108: Based on the attack behavior and the network attack and defense knowledge graph, determine the defensive behaviors involved in this round of attack;
[0056] Step 110: Based on the defensive behavior and the network attack and defense knowledge graph, determine the defensive equipment involved in this round of attack;
[0057] Step 112: Based on the defense equipment and the network attack and defense knowledge graph, determine whether there is a correlation between the defense equipment and the target asset in this round of attack. If there is no correlation, the attack is considered successful; if there is a correlation, the attack is considered unsuccessful.
[0058] The attack and defense confrontation assessment method provided by this invention combines data from five dimensions in the network attack and defense knowledge graph (i.e., asset information, attack equipment information, attack behavior information, defense equipment information, and defense behavior information) to construct an attack and defense mechanism for security simulation, thereby realizing automated attack and defense confrontation, reducing the dependence on the director's manual experience judgment in attack and defense confrontation, and effectively improving the efficiency and accuracy of security simulation.
[0059] Furthermore, considering that in offensive and defensive confrontations, each attack path may include multiple attack nodes, corresponding to multiple rounds of attacks, this offensive and defensive confrontation evaluation method also includes:
[0060] Step 114: Determine whether to end the confrontation; otherwise, return to step 104 to evaluate the next round of attacks until the confrontation ends.
[0061] Optionally, considering that the attack path planning scheme may also include multiple attack paths, the return to step 104 in step 114 further includes:
[0062] If the attack is determined to be successful in step 112, return to step 104. When determining the attack equipment and target assets for this attack, continue executing the original attack path. That is, based on the current attack path, determine the attack equipment and target assets for the new attack. When all attacks on the attack path are determined to be successful, the attack in the offensive and defensive confrontation is determined to be successful.
[0063] If the attack fails in step 112, return to step 104. When determining the attack equipment and target assets for this attack, start a new attack based on a new attack path, that is, determine the attack equipment and target assets for the new attack based on another attack path that has not been executed in the attack path planning scheme. If all attack paths in the attack path planning scheme are determined to fail after execution, the attack in the attack and defense confrontation is determined to have failed.
[0064] Through the above embodiments, a more comprehensive and systematic automated attack and defense assessment can be performed when the attack path planning scheme includes multiple attack paths, and each attack path includes one or more attack nodes.
[0065] The following description Figure 1 The execution method for each step is shown.
[0066] Optionally, the network attack and defense knowledge graph obtained in step 100 is constructed in the following manner:
[0067] Obtain network attack and defense data;
[0068] The network attack and defense data is classified into five dimensions, corresponding to five categories of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior.
[0069] Based on the categorized network attack and defense data, a network attack and defense knowledge graph is constructed.
[0070] A network attack and defense knowledge graph is a knowledge structure built by combining basic data such as cyberspace attack tactics, defense measures, vulnerabilities, and network information assets, along with their relationships. It can intelligently and systematically display network attack and defense knowledge from multiple dimensions and perspectives within the context of network attack and defense confrontation, helping to improve the understanding of cyberspace threats and attack and defense capabilities. The construction of a network attack and defense knowledge graph is an urgent problem to be solved in the development of knowledge-based experience in attack and defense confrontation. Currently, network attack and defense related knowledge graphs are neither macroscopically comprehensive nor microscopically grounded; that is, their coverage is not broad, their systematization is insufficient, and their targeting is weak. There is a lack of unified, accurate, comprehensive, and referable network attack and defense knowledge graphs in this technical field.
[0071] This invention constructs a network attack and defense ontology from five dimensions: asset dimension, attack equipment dimension, defense equipment dimension, attack framework dimension, and defense framework dimension. The relationships between these dimensions are as follows: Figure 2 As shown in the diagram. The asset dimension is the basis of the attack, corresponding to asset information; the attack equipment dimension is the basis of the attack, corresponding to attack equipment information; the defense equipment dimension is the basis of the defense, corresponding to defense equipment information; the attack framework dimension is the attack behavior, corresponding to attack behavior information; and the defense framework dimension is the defense behavior, corresponding to defense behavior information. Attack behaviors in the attack framework dimension use attack equipment in the attack equipment dimension to act on assets in the asset dimension (i.e., the attack equipment can attack assets). Assets exist in defense equipment in the defense equipment dimension (i.e., the defense equipment can protect assets), thus generating defense behaviors in the defense equipment dimension to resist attack behaviors in the attack framework. These five dimensions form an attack-defense closed loop, which can be used to completely describe the attack-defense process. Therefore, these five dimensions are used as the basis for modeling. Using the above embodiment, a diverse, comprehensive, and more universal network attack-defense knowledge graph can be constructed based on the five dimensions: asset dimension, attack equipment dimension, defense equipment dimension, attack behavior dimension, and defense behavior dimension.
[0072] Furthermore, the graph construction yields a network attack and defense knowledge graph, including:
[0073] Construct the ontology layer relationship graph (OG) and the data layer relationship graph (DG);
[0074] In other words, the network attack and defense knowledge graph includes an ontology layer relationship graph (OG) and a data layer relationship graph (DG).
[0075] The ontology hierarchy diagram (OG) is used to represent the hierarchical relationships between concepts (or ontology), OG =<CO,RO> In this context, CO represents a concept node, and RO represents the relationship edge between concepts. The ontology layer relationship graph OG includes five-dimensional concepts, corresponding to five types of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior. Concept nodes are connected according to the hierarchical relationship between concepts. A concept can be considered a classification of definitions. For example, assets, attack equipment, attack behavior, defense equipment, and defense behavior are all top-level concepts. The concept of assets is a lower-level concept, i.e., its subclasses, which may include sub-concepts such as software, hardware, and personnel. The concept of attack equipment is a lower-level concept, i.e., its subclasses, which may include sub-concepts such as equipment name and department.
[0076] The data layer relationship diagram (DG) is used to represent the correspondence between entities, DG =<ED,RD> In this context, ED represents an entity node with entity attributes, and RD represents the relationship edge between entities. The entity nodes in the Data Layer Relationship Graph (DG) are connected to the lowest-level concepts in the Ontology Layer Relationship Graph (OG), and their corresponding entity attribute information is recorded. The Data Layer Relationship Graph (DG) is primarily composed of a series of facts, and knowledge is stored in units of facts, namely, the entity attribute information of the entity nodes.
[0077] The final constructed cyberspace security knowledge graph consists of nodes and edges, i.e., KG = { <n> , <r>}, <n>Let N represent the set of nodes, and N∈(CO∪ED); <r>Let R denote the set of edges, and R ∈ (RO ∪ RD).
[0078] The network attack and defense knowledge graph constructed in this invention covers asset information, attack equipment information, attack behavior information, defense equipment information, and defense behavior information required to realize a complete security simulation process. Among them, asset information corresponds to the asset dimension of the network attack and defense knowledge graph, attack equipment information corresponds to the attack equipment dimension of the network attack and defense knowledge graph, attack behavior information corresponds to the attack framework dimension of the network attack and defense knowledge graph, defense equipment information corresponds to the defense equipment dimension of the network attack and defense knowledge graph, and defense behavior information corresponds to the defense framework dimension of the network attack and defense knowledge graph.
[0079] The network attack and defense knowledge graph records the relationship between asset information and defense equipment information, reflecting the relationship between each asset and the defense equipment it exists in. In fact, it also records the relationship between asset information and attack equipment information, reflecting the relationship between each asset and the attack equipment acting on it.
[0080] Optionally, to ensure that the network attack and defense knowledge graph has sufficient credible information, the attack behavior information in the network attack and defense knowledge graph may come from existing attack frameworks, and the defense behavior information may come from existing defense frameworks.
[0081] Furthermore, in the network attack and defense knowledge graph, the mapping relationships between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information can be determined in the following ways:
[0082] Based on the name of the attack equipment and the attack framework, establish a mapping relationship between attack equipment information and attack behavior information;
[0083] Based on the names of the defensive equipment and the aforementioned defensive framework, a mapping relationship between defensive equipment information and defensive behavior information is established;
[0084] Based on the attack framework and the defense framework, a mapping relationship is established between attack behavior information and defense behavior information.
[0085] By using the above embodiments, the attack framework and the defense framework can be used to establish three mapping relationships between the four dimensions of the network attack and defense knowledge graph: attack equipment dimension and attack framework dimension, defense framework dimension and defense equipment dimension, and attack framework dimension and defense framework dimension.
[0086] Preferably, the attack framework can be the ATT&CK attack framework; the defense framework can be the Engage defense framework. In other embodiments, other existing attack and defense frameworks can also be used to construct and maintain the network attack and defense knowledge graph. Regularly maintaining the network attack and defense knowledge graph is beneficial for more comprehensively integrating the information required for attack and defense confrontation.
[0087] The mapping relationship between a certain attack tool and the ATT&CK attack framework is as follows: Attack Tool A — ATT&CK Attack Framework {Initial Access [Watering Hole Attack (Exploiting Downloaded Files, Adobe Flash, Various Browser Vulnerabilities, Websites to Obtain Sensitive Information)], Execution [Exploiting Host Vulnerabilities (Exploiting System Service Vulnerabilities, Common Protocol Vulnerabilities, Office Software Vulnerabilities, Other Third-Party Application Vulnerabilities), Scheduled Tasks / Work (Exploiting the at.exe command program, Scheduled Tasks, Launchd Execution, Cron Program Execution)], ...}.
[0088] For all attack devices in the network attack and defense knowledge graph, the above relationships can be used to determine the mapping relationship between the attack device dimension and the attack framework dimension in the network attack and defense knowledge graph, that is, to establish the mapping relationship between attack device information and attack behavior information.
[0089] The mapping relationship between a certain defense equipment and the Engage defense framework is as follows: Defense Equipment A —— Engage Defense Framework {Exposure [Collection (API monitoring, software monitoring)], Influence [Prevention (baseline establishment, hardware control), Induction (security control), Blocking (isolation)], Provocation [Rationalization (application diversity, information control)}.
[0090] For all the defensive equipment in the network attack and defense knowledge graph, the above relationships can be used to determine the mapping relationship between the defensive equipment dimension and the defense framework dimension in the network attack and defense knowledge graph, that is, to establish the mapping relationship between defensive equipment information and defensive behavior information.
[0091] The mapping relationship between attack frameworks and defense frameworks, that is, the mapping relationship between attack behaviors and defense behaviors, is in the form of: ATT&CK attack framework (phishing) - Engage defense framework (system activity monitoring, migration attack vectors, email manipulation, simulation data, role creation). This means that the defense methods corresponding to the phishing attack behavior are system activity monitoring, migration attack vectors, email manipulation, simulation data, and role creation.
[0092] For all attack and defense behaviors in the network attack and defense knowledge graph, the above relationships can be used to determine the mapping relationship between the attack frame dimension and the defense frame dimension in the network attack and defense knowledge graph, that is, to establish the mapping relationship between attack behavior information and defense behavior information.
[0093] The mapping relationships in the aforementioned network attack and defense knowledge graph can be established between entity nodes in the ontology layer relationship graph OG and the data layer relationship graph DG connected to the ontology layer relationship graph OG, and can inherit the mapping relationships between concept nodes in the ontology layer relationship graph OG.
[0094] Based on the graph constructed from concepts and entities, this invention also utilizes attack and defense frameworks to establish three mapping relationships between the four dimensions of data in the network attack and defense knowledge graph (i.e., attack equipment dimension and attack framework dimension data, defense framework dimension and defense equipment dimension data, and attack framework dimension and defense framework dimension data). That is, the mapping relationship between attack equipment information and attack behavior information, defense equipment information and defense behavior information, and attack behavior information and defense behavior information, thereby providing support for the establishment of attack and defense mechanisms in the security simulation process.
[0095] Optionally, for step 102, "determining the attack path planning scheme for offensive and defensive confrontation," it further includes:
[0096] To obtain attack path planning schemes for offensive and defensive confrontations, or
[0097] Attack planning is carried out to obtain attack path planning schemes for offensive and defensive confrontation.
[0098] In step 102, the attack path planning scheme can be determined by directly reading existing data or by attack planning. The attack path planning scheme may include one or more attack paths, and each attack path may include one or more attack nodes. Each attack node corresponds to one round of attack, including the attack equipment and target assets of that round of attack.
[0099] Preferably, the attack path planning scheme can also be adjusted as needed.
[0100] Optionally, for step 104, "based on the attack path planning scheme, determine the attack equipment and target assets for this round of attack," it further includes:
[0101] Determine the attack path;
[0102] Based on the determined attack path, the attack nodes are identified;
[0103] Based on the identified attack nodes, the attack equipment and target assets for this round of attack are determined.
[0104] Optionally, for step 106, "based on the attack equipment and the network attack and defense knowledge graph, determine the attack behaviors involved in this round of attack," further includes:
[0105] Based on the name of the attack equipment in this round of attack, search in the network attack and defense knowledge graph to determine the attack equipment information corresponding to the attack equipment in this round of attack.
[0106] Based on the mapping relationship between attack equipment information and attack behavior information in the network attack and defense knowledge graph, the attack behaviors involved in this round of attack are determined.
[0107] Optionally, for step 108, "based on the attack behavior and the network attack and defense knowledge graph, determine the defensive behaviors involved in this round of attack," further includes:
[0108] Based on the identified attack behaviors involved in this round of attacks and the mapping relationship between attack behavior information and defense behavior information in the network attack and defense knowledge graph, the defense behaviors involved in this round of attacks are determined.
[0109] Optionally, for step 110, "based on the defensive behavior and the network attack and defense knowledge graph, determine the defensive equipment involved in this round of attack," further includes:
[0110] Based on the determined defensive actions involved in this round of attack and the mapping relationship between defensive equipment information and defensive action information in the network attack and defense knowledge graph, the defensive equipment involved in this round of attack is determined.
[0111] Optionally, for step 112, "based on the defense equipment and the network attack and defense knowledge graph, determine whether there is a correlation between the defense equipment and the target asset in this round of attack," further includes:
[0112] Based on the identified defensive equipment involved in this round of attacks and the correlation between asset information and defensive equipment information in the network attack and defense knowledge graph, all assets associated with the defensive equipment involved in this round of attacks are identified.
[0113] The identified assets are searched to determine if the target asset exists. If it does, the defense equipment is considered to be associated with the target asset; otherwise, no association is considered.
[0114] The above embodiments combine the mapping relationship of multi-dimensional data of network attack and defense knowledge graph to determine the attack and defense mechanism for security simulation, deduce attack behavior based on the mapping relationship between attack equipment and attack framework, deduce defense behavior based on the mapping relationship between attack framework and defense framework, deduce defense equipment based on the mapping relationship between defense framework and defense equipment, and finally determine whether there is a correlation between the required defense equipment and the target asset, so as to realize the evaluation of the attack and defense confrontation results based on the attack and defense mechanism.
[0115] In a specific embodiment, step 104 determines that the attack tool "Honeycomb" for this round of attack operates on the information system of the target asset based on the attack path planning scheme; step 106, based on the mapping relationship between the attack tool and the attack framework, deduces that the current attack behavior is "collecting local system data"; step 108, based on the mapping relationship between the attack framework and the defense framework, deduces that the defense behavior that the defender should have at this time is "security control" and "software manipulation"; step 110, based on the mapping relationship between the defense framework and the defense tool, deduces that the defense tool that the defender should have at this time is "sandbox" and "Data Loss Prevention System (DLP)"; step 112 determines whether the information system of the target asset has both "sandbox" and "Data Loss Prevention System (DLP)" defense tools. If it does, this round of attack fails; if it does not, the attack succeeds.
[0116] like Figure 3 As shown, the present invention also provides an automated attack and defense assessment method, comprising:
[0117] Step 300: Obtain network attack and defense data, and classify the network attack and defense data into five dimensions, corresponding to five categories of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior.
[0118] Step 302: Based on the classified network attack and defense data, construct a network attack and defense knowledge graph; the network attack and defense knowledge graph includes constructing an ontology layer relationship graph (OG) and a data layer relationship graph (DG);
[0119] Step 304: For the network attack and defense knowledge graph obtained by the graph construction, based on the attack framework and the defense framework, determine the mapping relationship between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information;
[0120] Step 306: Determine the attack path planning scheme for offensive and defensive confrontation;
[0121] Step 308: Based on the attack path planning scheme, determine the attack equipment and target assets for this round of attack;
[0122] Step 310: Based on the attack equipment and the network attack and defense knowledge graph, determine the attack behaviors involved in this round of attack;
[0123] Step 312: Based on the attack behavior and the network attack and defense knowledge graph, determine the defensive behaviors involved in this round of attack;
[0124] Step 314: Based on the defensive behavior and the network attack and defense knowledge graph, determine the defensive equipment involved in this round of attack;
[0125] Step 316: Based on the defense equipment and the network attack and defense knowledge graph, determine whether there is a correlation between the defense equipment and the target asset in this round of attack. If there is no correlation, the attack is considered successful; if there is a correlation, the attack is considered unsuccessful.
[0126] Step 318: Determine whether to end the confrontation;
[0127] If the confrontation does not end and the attack is determined to be successful in step 316, then return to step 308 and determine the attack equipment and target assets for the new round of attack based on the current attack path; when all rounds of attack on the attack path are determined to be successful, the attack in the offensive and defensive confrontation is determined to be successful and the confrontation ends.
[0128] If the confrontation does not end and the attack is determined to have failed in step 316, then return to step 308 and determine the attack equipment and target assets for the new round of attack based on another unexecuted attack path in the attack path planning scheme; if all attack paths in the attack path planning scheme are determined to have failed after execution, then the attack in the attack-defense confrontation is determined to have failed and the confrontation ends.
[0129] To address the problems of current security simulations relying on the director's manual experience for judgment, which is time-consuming, inaccurate, and lacks persuasiveness, this invention addresses these issues by focusing on three aspects: network attack and defense knowledge graph construction, establishment of multi-dimensional data mapping relationships within the knowledge graph, and automated attack and defense confrontation. It fully utilizes massive amounts of heterogeneous situational intelligence data in cyberspace, breaking through a series of key technologies such as network attack and defense ontology / knowledge graph construction and attack and defense mechanism establishment, and researching automated attack and defense confrontation evaluation methods. Based on network topology, asset information, and network attack and defense techniques, this invention enables cyberspace game theory between the Red and Blue teams, and further realizes an integrated workflow for the organization and application of network attack and defense knowledge based on knowledge graphs and innovative attack and defense mechanisms. This contributes to the development of the cyberspace security industry and equipment.
[0130] like Figure 4 , Figure 5 As shown, this invention provides an automated attack and defense assessment device. The device can be implemented through software, hardware, or a combination of both. From a hardware perspective, as... Figure 4 The diagram shown is a hardware architecture diagram of an electronic device containing an automated attack and defense assessment device provided in an embodiment of the present invention. (Except for...) Figure 4 In addition to the processor, memory, network interface, and non-volatile memory shown, the electronic device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing packets. Taking software implementation as an example, such as... Figure 5 As shown, a device in a logical sense is formed by the CPU of its host electronic device reading the corresponding computer program from non-volatile memory into memory for execution. This embodiment provides an automated attack and defense assessment device, comprising:
[0131] The knowledge graph acquisition module 501 is used to acquire a network attack and defense knowledge graph; the network attack and defense knowledge graph contains asset information, attack equipment information, attack behavior information, defense equipment information and defense behavior information, as well as the mapping relationships between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information.
[0132] The scheme determination module 502 is used to determine the attack path planning scheme for offensive and defensive confrontation;
[0133] The target determination module 503 is used to determine the attack equipment and target assets for this round of attack based on the attack path planning scheme.
[0134] The first inference module 504 is used to determine the attack behaviors involved in this round of attack based on the attack equipment and the network attack and defense knowledge graph.
[0135] The second inference module 505 is used to determine the defensive behaviors involved in this round of attack based on the attack behavior and the network attack and defense knowledge graph.
[0136] The third inference module 506 is used to determine the defensive equipment involved in this round of attack based on the defensive behavior and the network attack and defense knowledge graph.
[0137] The deduction and judgment module 507 is used to determine whether there is a correlation between the defense equipment and the target asset in this round of attack based on the defense equipment and the network attack and defense knowledge graph. If there is no correlation, the attack is judged to be successful; if there is a correlation, the attack is judged to be unsuccessful.
[0138] In this embodiment of the invention, the map acquisition module 501 can be used to execute step 100 in the above method embodiment, the scheme determination module 502 can be used to execute step 102 in the above method embodiment, the target determination module 503 can be used to execute step 104 in the above method embodiment, the first deduction module 504 can be used to execute step 106 in the above method embodiment, the second deduction module 505 can be used to execute step 108 in the above method embodiment, the third deduction module 506 can be used to execute step 110 in the above method embodiment, and the deduction judgment module 507 can be used to execute step 112 in the above method embodiment.
[0139] Optionally, the automated attack and defense assessment device also includes:
[0140] The loop judgment module 508 is used to determine whether the confrontation has ended. Otherwise, it returns to call the target determination module 503 to evaluate the next round of attack until the confrontation ends.
[0141] The loop judgment module 508 can be used to execute step 114 in the above method embodiment.
[0142] Optionally, the network attack and defense knowledge graph is constructed in the following way:
[0143] Obtain network attack and defense data;
[0144] The network attack and defense data is classified into five dimensions, corresponding to five categories of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior.
[0145] Based on the categorized network attack and defense data, a network attack and defense knowledge graph is constructed.
[0146] The constructed graph yields a network attack and defense knowledge graph, including:
[0147] Construct the ontology layer relationship graph (OG) and the data layer relationship graph (DG);
[0148] The ontology hierarchy diagram (OG) is used to represent the hierarchical relationships between concepts. OG =<CO,RO> Where CO represents a concept node and RO represents the relationship edge between concepts; the ontology layer relationship graph OG includes five-dimensional concepts, corresponding to five types of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior, and the concept nodes are connected according to the hierarchical relationship of the concepts.
[0149] The data layer relationship diagram (DG) is used to represent the correspondence between entities, DG =<ED,RD> , where ED represents an entity node with entity attributes, and RD represents the relationship edge between entities; the entity nodes in the data layer relationship graph DG are connected to the lowest level concepts in the ontology layer relationship graph OG, and the corresponding entity attribute information is recorded.
[0150] Optionally, the attack behavior information in the network attack and defense knowledge graph comes from the attack framework, and the defense behavior information comes from the defense framework.
[0151] Optionally, the mapping relationships between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information in the network attack and defense knowledge graph are determined in the following way:
[0152] Based on the name of the attack equipment and the attack framework, establish a mapping relationship between attack equipment information and attack behavior information;
[0153] Based on the names of the defensive equipment and the aforementioned defensive framework, a mapping relationship between defensive equipment information and defensive behavior information is established;
[0154] Based on the attack framework and the defense framework, a mapping relationship is established between attack behavior information and defense behavior information.
[0155] It is understood that the structures illustrated in the embodiments of the present invention do not constitute a specific limitation on an automated attack and defense assessment device. In other embodiments of the present invention, an automated attack and defense assessment device may include more or fewer components than illustrated, or combine some components, or split some components, or arrange different components. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0156] The information interaction and execution process between the modules in the above-mentioned device are based on the same concept as the method embodiment of the present invention, and the specific details can be found in the description of the method embodiment of the present invention, and will not be repeated here.
[0157] This invention also provides an electronic device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements an automated attack and defense assessment method according to any embodiment of this invention.
[0158] This invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform an automated attack and defense assessment method according to any embodiment of this invention.
[0159] Specifically, a system or apparatus equipped with a storage medium may be provided, on which software program code implementing the functions of any of the embodiments described above is stored, and the computer (or CPU or MPU) of the system or apparatus may read and execute the program code stored in the storage medium.
[0160] In this case, the program code read from the storage medium can itself implement the function of any of the above embodiments, and therefore the program code and the storage medium storing the program code constitute part of the present invention.
[0161] Examples of storage media used to provide program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, program code can be downloaded from a server computer via a communication network.
[0162] Furthermore, it should be clear that not only can the program code read by the computer be executed, but also the operating system or other components operating on the computer can be instructed based on the program code to perform some or all of the actual operations, thereby realizing the function of any of the embodiments described above.
[0163] Furthermore, it is understood that the program code read from the storage medium is written to the memory set in the expansion board inserted into the computer or to the memory set in the expansion module connected to the computer. Then, based on the instructions of the program code, the CPU or other components installed on the expansion board or expansion module execute some and all of the actual operations, thereby realizing the function of any of the above embodiments.
[0164] The embodiments of the present invention have at least the following beneficial effects:
[0165] 1. In one embodiment of the present invention, an automated attack and defense confrontation assessment method and apparatus are provided, which can combine the mapping relationship between multi-dimensional data to construct an attack and defense mechanism oriented towards security deduction, thereby realizing automated attack and defense confrontation;
[0166] 2. In one embodiment of the present invention, an automated attack and defense confrontation assessment method and apparatus are provided. By analyzing existing network attack and defense data sources, a more universal network attack and defense knowledge graph is constructed based on five dimensions: asset dimension, attack equipment dimension, defense equipment dimension, attack framework dimension, and defense framework dimension. It can not only be used for automated attack and defense confrontation assessment, but also provide support for a complete description of the attack and defense process.
[0167] 3. In one embodiment of the present invention, an automated attack and defense confrontation assessment method and device are provided. Based on the ATT&CK attack framework and the Engage defense framework, three mapping relationships are established between the four dimensions of data in the network attack and defense knowledge graph. Specifically, these relationships include: attack equipment dimension and attack framework dimension data, defense framework dimension and defense equipment dimension data, and attack framework dimension and defense framework dimension data, thereby providing reliable support for the establishment of attack and defense mechanisms during security simulation.
[0168] In summary, in order to meet the work requirements of achieving automated attack and defense confrontation in security simulation systems, this invention focuses on a series of studies on the construction of network attack and defense knowledge graphs, the establishment of multi-dimensional data mapping relationships in knowledge graphs, and automated attack and defense confrontation based on attack and defense mechanisms. It innovates and develops scientific methods and technical means for security simulation, promotes the improvement of automated confrontation capabilities, and forms a sound mechanism and mature means that can be universally applied to cyberspace security simulation of large-scale equipment, thereby ensuring the cyberspace security of large-scale equipment.
[0169] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0170] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as ROM, RAM, magnetic disk, or optical disk.
[0171] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.< / r> < / n> < / r> < / n>
Claims
1. An automated attack and defense assessment method, characterized in that, include: Obtain network attack and defense knowledge graph; The network attack and defense knowledge graph records asset information, attack equipment information, attack behavior information, defense equipment information, and defense behavior information, as well as the relationships between asset information and defense equipment information, and the mapping relationships between attack equipment information and attack behavior information, defense equipment information and defense behavior information, and attack behavior information and defense behavior information. It constructs a network attack and defense domain ontology from five dimensions: asset dimension, attack equipment dimension, defense equipment dimension, attack framework dimension, and defense framework dimension. The asset dimension is the basis for attacks and corresponds to asset information; the attack equipment dimension is the basis for attacks and corresponds to attack equipment information; the defense equipment dimension is the basis for defense and corresponds to defense equipment information; the attack framework dimension is attack behavior and corresponds to attack behavior information; and the defense framework dimension is defense behavior and corresponds to defense behavior information. Attack behaviors in the attack framework dimension utilize attack equipment in the attack equipment dimension, act on assets in the asset dimension, and the assets possess defense equipment in the defense equipment dimension, generating defense behaviors in the defense equipment dimension to resist the attack behaviors in the attack framework. These five dimensions form an attack-defense closed loop. The attack behavior information in the network attack-defense knowledge graph comes from the attack framework, and the defense behavior information comes from the defense framework. The mapping relationship between attack equipment information and attack behavior information is established based on the name of the attack equipment and the attack framework; the mapping relationship between defense equipment information and defense behavior information is established based on the name of the defense equipment and the defense framework. The mapping relationship between attack behavior information and defense behavior information is established based on the attack framework and the defense framework; Determine the attack path planning scheme for offensive and defensive confrontation; Based on the attack path planning scheme, the attack equipment and target assets for this round of attack are determined; Based on the attack equipment and the network attack and defense knowledge graph, the attack behaviors involved in this round of attack are determined; Based on the attack behavior and the network attack and defense knowledge graph, determine the defensive behaviors involved in this round of attack; Based on the aforementioned defensive behaviors and the network attack and defense knowledge graph, the defensive equipment involved in this round of attack is determined; Based on the defense equipment and the network attack and defense knowledge graph, it is determined whether there is a connection between the defense equipment and the target asset in this round of attack. If there is no connection, the round of attack is considered successful; if there is a connection, the round of attack is considered unsuccessful.
2. The method according to claim 1, characterized in that, Also includes: Determine whether to end the confrontation; otherwise, return to the steps of determining the attack equipment and target assets for this round of attack based on the attack path planning scheme.
3. The method according to claim 1, characterized in that, The network attack and defense knowledge graph is constructed in the following way: Obtain network attack and defense data; The network attack and defense data is classified into five dimensions, corresponding to five categories of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior. Based on the categorized network attack and defense data, a network attack and defense knowledge graph is constructed.
4. The method according to claim 3, characterized in that, The constructed graph yields a network attack and defense knowledge graph, including: Constructing the ontology layer relationship graph OG Relationship diagram with data layer DG ; The ontology layer relationship diagram OG Used to represent hierarchical relationships between concepts. ,in CO Represents a concept node. RO The relational graph represents the relationships between concepts; the ontology layer relational graph OG It includes a five-dimensional concept, which corresponds to five types of information: assets, attack equipment, attack behavior, defense equipment, and defense behavior. The concept nodes are connected according to the hierarchical relationship of the concepts. The data layer relationship diagram DG Used to represent the correspondence between entities. ,in ED Represents an entity node, which has entity attributes. RD Representing the edges between entities; the data layer relationship graph DG The relationship between entity nodes and the ontology layer OG The lowest level of concepts are connected, and corresponding entity attribute information is recorded.
5. The method according to claim 1, characterized in that, The attack framework uses the ATT&CK attack framework; the defense framework uses the Engage defense framework.
6. An automated attack and defense assessment device, characterized in that, For performing the method as described in any one of claims 1-5 above, comprising: The knowledge graph acquisition module is used to acquire network attack and defense knowledge graphs. The network attack and defense knowledge graphs contain asset information, attack equipment information, attack behavior information, defense equipment information, and defense behavior information, as well as mapping relationships between attack equipment information and attack behavior information, between defense equipment information and defense behavior information, and between attack behavior information and defense behavior information. The scheme determination module is used to determine the attack path planning scheme for offensive and defensive confrontation; The target determination module is used to determine the attack equipment and target assets for this round of attack based on the attack path planning scheme. The first inference module is used to determine the attack behaviors involved in this round of attack based on the attack equipment and the network attack and defense knowledge graph. The second deduction module is used to determine the defensive behaviors involved in this round of attack based on the attack behavior and the network attack and defense knowledge graph. The third inference module is used to determine the defensive equipment involved in this round of attack based on the defensive behavior and the network attack and defense knowledge graph. The deduction and judgment module is used to determine whether there is a correlation between the defense equipment and the target asset in this round of attack based on the defense equipment and the network attack and defense knowledge graph. If there is no correlation, the attack is judged to be successful; if there is a correlation, the attack is judged to be unsuccessful.
7. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1-5.
8. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed in the computer, it causes the computer to perform the method of any one of claims 1-5.
Citation Information
Patent Citations
Simulation modeling method and device for network attack and defense process and network turn war chess
CN113536573A