Method and apparatus for generating kill chain stage, electronic device and storage medium
By expanding and reasoning about the correlation information of attack behavior, rich and accurate kill chain stage information is generated, which solves the problem of information deficiency in existing technologies and supports effective analysis of attackers and formulation of defense strategies.
Patent Information
- Application Number
- CN202211541194.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-02
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2042-12-02
AI Technical Summary
Existing methods for generating kill chain stages suffer from severe information gaps, making it difficult to support the analysis of attackers' tactics and techniques, as well as attacks originating from the same source.
The first correlation information is extracted from the attack information of the attack behavior and expanded to generate the second correlation information. The generation rule base and generation engine are used to infer the kill chain stage and its feature information, and the information is modified and stored through manual detection.
It improves the richness and accuracy of kill chain stage information, provides more comprehensive kill chain stage data, and supports the correct identification and analysis of attack organizations and attack tactics.
Smart Images

Figure CN116015730B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a kill chain stage generation method, device, electronic device, and storage medium. Background Art
[0002] Advanced Persistent Threat (APT) attacks are persistent and effective cyberattacks launched by an organization against a specific target, characterized by strong stealth and targeting. Cyberattacks, especially those launched by APT organizations against specific targets, typically consist of a series of interrelated attacks.
[0003] In network security protection, the kill chain stage of the detected attack behavior can be identified and generated based on the Cyber Kill Chain, and the kill chain relationship between the attack behaviors can be constructed based on the generated kill chain stage information. Then, the attacker's attack technology, process, strategy and other characteristics can be analyzed through means such as kill chain homology analysis. This helps to analyze network attack behavior from the attacker and global perspectives, help identify the attack characteristics of APT organizations, and formulate corresponding defense strategies.
[0004] Cyber kill chain stage generation is the foundation of kill chain construction. However, due to limited detection methods and security protection blocks, the kill chain stage generation results obtained by current kill chain stage generation methods are seriously missing information, making it difficult to support attack analysis such as attacker tactics and homology. Summary of the Invention
[0005] In view of this, an object of the present invention is to provide a kill chain stage generation method, device, electronic device and storage medium, which can improve the problem of missing kill chain stage generation result information obtained by traditional kill chain stage generation methods.
[0006] In order to achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:
[0007] In a first aspect, an embodiment of the present invention provides a kill chain stage generation method, the method comprising:
[0008] For a detected attack behavior, extract first correlation information about a kill chain stage from attack information of the attack behavior;
[0009] Expanding the first correlation information based on the attack behavior to obtain second correlation information;
[0010] generating, based on the second association information, multiple kill chain stages of the attack behavior and feature information of each kill chain stage;
[0011] Each kill chain stage is detected, editing information corresponding to the detection result is obtained, and the kill chain stage is modified and stored according to the editing information.
[0012] Furthermore, the step of generating multiple kill chain stages of the attack behavior and feature information of each kill chain stage based on the second correlation information includes:
[0013] Determining a plurality of target generation rules from a preset generation rule library based on the behavior information in the second association information;
[0014] For each of the target generation rules, a preset generation engine is used to perform kill chain stage reasoning according to the target generation rule to obtain the target kill chain stage and feature information of the target kill chain stage.
[0015] Furthermore, the generation rule library includes generation rules for each kill chain stage of each attack behavior, as well as condition information for each generation rule;
[0016] The step of determining a plurality of target generation rules from a preset generation rule library based on the behavior information in the second association information includes:
[0017] For each piece of behavior information in the second association information, matching the behavior information with all condition information in the generation rule base;
[0018] The generation rule corresponding to the condition information matching the behavior information is used as the target generation rule.
[0019] Furthermore, the step of expanding the first correlation information based on the attack behavior to obtain second correlation information includes:
[0020] Determining the attack type of the attack behavior;
[0021] According to the search rules corresponding to the attack type, the attack target information of the attack behavior is obtained from a preset organization information database;
[0022] The attack target information is combined with the first correlation information to obtain second correlation information of the attack behavior.
[0023] Furthermore, when the attack type is phishing, the step of obtaining the attack target information of the attack behavior from a preset organization information database according to the search rule corresponding to the attack type includes:
[0024] The domain name of the email recipient of the attack behavior is used as a search item, and the organization corresponding to the email recipient domain name and the industry information of the organization are obtained from a preset organization information database.
[0025] Furthermore, when the attack type is not phishing, the step of obtaining the attack target information of the attack behavior from a preset organization information database according to the search rule corresponding to the attack type includes:
[0026] The attacked IP of the attack behavior is used as a search item, and the organization corresponding to the attacked IP and the industry information of the organization are obtained from a preset organization information database.
[0027] Furthermore, the step of detecting each kill chain stage and obtaining editing information corresponding to the detection result includes:
[0028] Interactively displaying all the kill chain stages, characteristic information of each kill chain stage, attack behavior, and second associated information to enable detection personnel to perform detection;
[0029] For each kill chain stage, editing information input by the detection personnel after detection is obtained.
[0030] In a second aspect, an embodiment of the present invention provides a kill chain stage generation device, comprising an information extraction module, an information expansion module, a generation module, and a detection module;
[0031] The information extraction module is configured to extract, for a detected attack behavior, first associated information about a kill chain stage from attack information of the attack behavior;
[0032] The information expansion module is configured to expand the first associated information based on the attack behavior to obtain second associated information;
[0033] The generating module is configured to generate multiple kill chain stages of the attack behavior and feature information of each kill chain stage based on the second correlation information;
[0034] The detection module is configured to detect each of the kill chain stages, obtain editing information corresponding to the detection result, and modify and store the kill chain stage according to the editing information.
[0035] In a third aspect, an embodiment of the present invention provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program executable by the processor, and the processor can execute the computer program to implement the kill chain stage generation method as described in the first aspect.
[0036] In a fourth aspect, an embodiment of the present invention provides a storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the kill chain stage generation method as described in the first aspect is implemented.
[0037] The kill chain stage generation method, device, electronic device, and storage medium provided by embodiments of the present invention obtain first association information about the kill chain stages from attack behavior detection data, and expand the first association information based on the attack behavior to obtain second association information, thereby expanding the kill chain related information of the attack behavior. Based on the expanded second association information, multiple kill chain stages and characteristic information of the kill chain stages are generated for the attack behavior. Based on the edit information obtained after detecting each kill chain stage, the kill chain stage is modified and stored, thereby expanding multiple kill chain stages based on the second association information obtained after the information expansion, which can greatly improve the richness of the kill chain stage information.
[0038] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0040] Figure 1 A schematic diagram of the structure of a kill chain stage generation system provided by an embodiment of the present invention is shown.
[0041] Figure 2 A schematic diagram of the process of generating a kill chain stage according to an embodiment of the present invention is shown.
[0042] Figure 3 Shown Figure 2 Flow chart of some sub-steps of step S13.
[0043] Figure 4 Shown Figure 2 Flow chart of some sub-steps of step S15.
[0044] Figure 5 Shown Figure 4 Flow chart of some sub-steps of step S151.
[0045] Figure 6 Shown Figure 2 Flow chart of some sub-steps of step S17.
[0046] Figure 7 A block diagram of a kill chain stage generation device provided by an embodiment of the present invention is shown.
[0047] Figure 8 A block diagram of an electronic device provided by an embodiment of the present invention is shown.
[0048] Figure numerals: 100 - kill chain stage generation system; 110 - kill chain generation device; 120 - attack detection device; 130 - client; 140 - kill chain stage generation device; 150 - information extraction module; 160 - information expansion module; 170 - generation module; 180 - detection module; 190 - electronic device. DETAILED DESCRIPTION
[0049] The following will be combined with the accompanying drawings to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.
[0050] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but is merely intended to represent selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative work are within the scope of protection of the present invention.
[0051] It should be noted that relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
[0052] Network kill chain stage generation is fundamental to kill chain construction. Currently, a commonly used kill chain stage generation method analyzes the attack behavior characteristics corresponding to a detection rule, pre-defines the network kill chain stage corresponding to the detection rule, and stores this information as associated information for the detection rule. When an attack behavior is discovered based on the detection rule, the kill chain stage associated with the rule is determined to be the kill chain stage of the attack behavior, and the corresponding kill chain stage is generated. This kill chain stage generation method can generate a kill chain stage for each attack behavior, providing kill chain stage data for kill chain construction.
[0053] However, due to limited detection methods and security protection blockages, the kill chain generation method described above lacks significant information about each link in the kill chain, making it difficult to analyze the attacker's tactics and common sources. For example, open source information collection activities conducted by attackers during the reconnaissance phase of the kill chain are difficult to detect, resulting in missing information at that stage.
[0054] Based on the above considerations, an embodiment of the present invention provides a kill chain stage generation method that can improve the problem of missing kill chain stage generation result information obtained by traditional kill chain stage generation methods. The kill chain stage generation method is introduced below.
[0055] The kill chain stage generation method provided by the embodiment of the present invention can be applied to Figure 1 In the kill chain stage generation system 100, the kill chain stage generation system 100 includes an attack detection device 120 and a kill chain generation device 110. The attack detection device 120 can be communicatively connected to the kill chain generation device 110 via a network. The attack detection device 120 can also be communicatively connected to multiple clients 130 via the network.
[0056] The attack detection device 120 and the kill chain generation device 110 can be, but are not limited to, independent servers, server clusters, personal computers, laptop computers, tablet computers, and other devices.
[0057] The attack detection device 120 is configured to detect any network behavior of each client 130 according to a preset attack rule library, identify attack behaviors, and send attack information related to the attack behaviors to the kill chain generation device 110. The attack information may also include an attack type tag related to the attack behavior.
[0058] The kill chain generation device 110 is configured to receive attack information sent by the attack detection device 120 and implement the kill chain stage generation method provided in an embodiment of the present invention.
[0059] It should be noted that the attack detection device 120 may directly send the attack information to the kill chain generation device 110, or may extract the first correlation information about the kill chain stage from the attack information of the attack behavior and then send the first correlation information to the kill chain generation device 110. This is not specifically limited in this embodiment.
[0060] In a possible implementation, a kill chain stage generation method is provided, referring to Figure 2 , may include the following steps. In this embodiment, the kill chain stage generation method is applied to Figure 1 The kill chain generation device 110 in FIG. 1 is used as an example.
[0061] S11 , for the detected attack behavior, extracting first correlation information about the kill chain stage from the attack information of the attack behavior.
[0062] The first associated information includes but is not limited to: the kill chain stage determination of the attack behavior, threat type, attacking IP, attacked IP, malicious attack sample, attack type, vulnerability type used in the attack, and email attachment information. The first associated information obtained in step S11 can be expressed as Among them, Attack represents the attack behavior. The first associated information set representing the attack behavior Attack.
[0063] It should be understood that the attack information refers to all data information generated from the attack process to the detection of the attack behavior, and the first associated information is information that can be directly extracted from the attack information.
[0064] S13: Based on the attack behavior, expand the first correlation information to obtain second correlation information.
[0065] S15: Generate multiple kill chain stages of the attack behavior and feature information of each kill chain stage based on the second correlation information.
[0066] S17: Detect each kill chain stage, obtain editing information corresponding to the detection result, and modify and store the kill chain stage according to the editing information.
[0067] After detecting an attack, attack detection device 120 sends attack information to kill chain generation device 110. After receiving the attack information from attack detection device 120, kill chain generation device 110 extracts first correlation information related to the kill chain stage from the attack information. Alternatively, after detecting an attack, attack detection device 120 extracts first correlation information related to the kill chain stage from the attack information and sends the first correlation information to kill chain generation device 110.
[0068] After obtaining the first correlation information, the kill chain generation device 110 can expand the first correlation information based on the attack behavior according to certain rules to obtain second correlation information. Consequently, based on the second correlation information, the kill chain generation device 110 generates multiple kill chain stages of the attack behavior and characteristic information for each kill chain stage. Furthermore, each kill chain stage can be tested according to certain detection rules or manual testing to obtain edit information. When the edit information is confirmed to be OK, the kill chain stage and its characteristic information can be directly saved. If the edit information includes modification information, the kill chain stage and its characteristic information can be modified based on the modification information and then saved.
[0069] Compared to traditional kill chain stage generation methods, the kill chain stage generation method provided in embodiments of the present invention expands the first correlation information about the attack behavior related to the kill chain generation stage and, based on the second correlation information obtained after this information expansion, infers and expands multiple kill chain stages and characteristic information for each kill chain stage. This significantly improves the richness of kill chain stage information and alleviates the problem of information loss that hinders analysis of attacker tactics and homology. Furthermore, after obtaining multiple kill chain stages and characteristic information for the attack behavior, each kill chain stage is tested and modified, significantly improving the accuracy of the generated kill chain stages and their characteristic information.
[0070] The method of expanding the first associated information to obtain the second associated information can be flexibly selected. For example, based on the knowledge graph, information whose relevance to the second associated information reaches a set threshold can be extracted from the knowledge graph, or it can be expanded according to preset rules. In this embodiment, no specific limitation is made.
[0071] In order to obtain as much information as possible about the attack behavior involving the kill chain stage, and to ensure the accuracy of the information and reduce the interference of irrelevant information. Figure 3 , the above step S13 can be further implemented as the following steps.
[0072] S131, determining the attack type of the attack behavior.
[0073] S132: Acquire attack target information of the attack behavior from a preset organization information database according to a search rule corresponding to the attack type.
[0074] S133: Combine the attack target information with the first correlation information to obtain second correlation information of the attack behavior.
[0075] Attack types include, but are not limited to, phishing, reconnaissance attacks, network monitoring, port scanning, etc. Attack target information includes, but is not limited to, the organization or institution to which the attacked target belongs, and the industry information of the organization or institution to which the attacked target belongs.
[0076] It should be understood that the attack target information can be flexibly selected according to actual needs. For example, it can also include the IP of the device where the scanned port is located, the organization or institution to which the long-term user of the device where the scanned port is located belongs, and the industry information of the organization or institution. In this embodiment, no specific limitation is made.
[0077] The kill chain generation device 110 may be pre-built with an organization information database that stores organization information collected using open source collection methods, including the organization and industry to which each IP corresponds, and the organization and industry information corresponding to each email recipient domain name.
[0078] In one possible implementation, the attack type can be categorized as phishing or non-phishing. When the attack behavior is phishing, step S132 can be further implemented by using the domain name of the email recipient of the attack behavior as a search item to obtain the organization and industry information corresponding to the email recipient domain name from a preset organization information database.
[0079] When the attack type of the attack behavior is not phishing, the above step S132 can be further implemented as follows: using the attacked IP of the attack behavior as a search item, obtaining the organization and industry information corresponding to the attacked IP from a preset organization information database.
[0080] The second association information obtained through the above steps S13, S131-S133 can be expressed as: Among them, Attack represents the attack behavior. The second associated information set representing the expanded attack behavior Attack.
[0081] The method of generating multiple kill chain stages of attack behavior and characteristic information of each kill chain stage can be flexibly set. For example, it can be generated according to the rules corresponding to the attack behavior, or it can be generated according to the rules corresponding to the kill chain stage. In this embodiment, no specific limitation is made.
[0082] In order to expand the number of kill chain stages and their characteristic information related to attack behaviors as much as possible, in one possible implementation, a macro is introduced, a generation rule library and a generation engine are introduced, and the kill chain generation device 110 runs a pre-configured generation engine and builds a generation rule library. The generation rule library stores the generation rules of each kill chain stage for each type of attack. Figure 4, the above step S15 can be further implemented as the following steps.
[0083] S151 : Determine a plurality of target generation rules from a preset generation rule library according to the behavior information in the second association information.
[0084] S152: For each target generation rule, a preset generation engine is used to perform kill chain stage reasoning according to the target generation rule to obtain target kill chain stages and characteristic information of the target kill chain stages.
[0085] Furthermore, the generation rule library may also include condition information of each generation rule. In a possible implementation, the target generation rule may be determined based on the matching between the condition information and the behavior information in the second association information. Figure 5 , the above step S151 can be further implemented as the following steps.
[0086] S151A: For each piece of behavior information in the second association information, match the behavior information with all condition information in the generation rule base.
[0087] S151B: The generation rule corresponding to the condition information that matches the behavior information is used as the target generation rule.
[0088] The matching method can be set flexibly. For example, when the condition information of a certain generation rule is consistent with one or more behavior information in the second association information, or when the information type of one or more behavior information in the second association information is consistent with the condition information of a certain generation rule, the generation rule corresponding to the condition information is a target generation rule.
[0089] In other embodiments, a preset classification rule or a neural network can be used to classify all behavioral information in the second association information to obtain multiple kill chain categories related to the kill chain stage. Each kill chain category is then matched with the condition information of each generation rule in the generation rule library. The generation rule corresponding to the matched condition information is the target generation rule. The neural network can be a pre-trained neural network used to classify behavioral information in the kill chain stage.
[0090] Through the above steps S15, S151-S152 and their related sub-steps, multiple kill chain stages can be expanded and generated.
[0091] For example, when the second association information includes the Trojan software that the attacker attempts to implant during the installation and implantation phase, and behavioral information such as the C2 server domain name connected during the command and control phase, it matches the generation rules for installing and implanting Trojan software and the generation rules for command control. The generation engine then generates the kill chain phase and characteristic information of the Trojan software based on the generation rules for installing and implanting Trojan software, and generates the command and control kill chain phase and characteristic information based on the generation rules for name control.
[0092] When the second correlation information includes the attack type of a web vulnerability attack and the industry information of the target organization, it matches the generation rules of the reconnaissance and tracking kill chain stage. Therefore, the generation engine uses the generation rules of the reconnaissance stage to infer the attacker's reconnaissance target during the reconnaissance phase and then generates the reconnaissance and tracking kill chain stages and their characteristic information.
[0093] The multiple kill chain stages and their characteristic information obtained through the above steps S15, S151-S152 and their related sub-steps can be expressed as {Attack, γ}, where Attack represents the attack behavior, γ * Represents the kill chain stage set inferred from the attack behavior Attack.
[0094] The method of testing each kill chain stage and obtaining the editing information corresponding to the test results can be flexibly set. For example, the kill chain stage can be tested using the detection script corresponding to each kill chain stage to obtain the editing information corresponding to the detection result. Alternatively, each kill chain stage can be tested manually and the editing information can be manually entered based on the test results.
[0095] In a possible implementation, in order to improve the accuracy of the kill chain stages and their characteristic information, and to further supplement the kill chain stage information to enrich the information, a manual detection method is introduced. Figure 6 , the above step S17 can be further implemented as the following steps.
[0096] S171: All kill chain stages, characteristic information of each kill chain stage, attack behavior, and second associated information are interactively displayed to enable detection personnel to perform detection.
[0097] S172: For each kill chain stage, obtain editing information input by the inspector after the inspection.
[0098] All kill chain stages of the attack behavior, characteristic information for each kill chain stage, the attack behavior, and the second associated information can be displayed on the display interface of the kill chain generation device 110. A tester can then test and confirm each kill chain stage one by one. If a kill chain stage is found to be correct and no information has been canceled, a confirmation message indicating correctness is entered. If a kill chain stage is found to contain errors or missing information, edit information for modification is manually entered. The kill chain generation device 110 receives the edit information, modifies the corresponding kill chain stage based on the edit information, and stores the modified kill chain stage.
[0099] For example, when a phishing email is detected, the malicious attachment of the phishing email is manually analyzed. When the encoding features of the malicious attachment in the weapon construction stage, the vulnerability attempted to be used in the vulnerability exploitation stage, or the installation software used in the installation and implantation stage are found, the two kill chain stages of weapon construction and vulnerability exploitation and their features are generated, and the feature information of the installation and implantation kill chain stage is supplemented.
[0100] Embodiments of the present invention provide a kill chain stage generation method. By analyzing and processing the correlation information of detected attack behaviors, the first correlation information extracted from the detection data is expanded, and based on the expanded second correlation information, multiple kill chain stages and their characteristic information are inferred. This method can infer multiple kill chain stages and their characteristic information from a single attack behavior, providing more comprehensive kill chain stage data for kill chain construction, facilitating the correct identification and analysis of attack organizations and their attack techniques and tactics, and providing effective support for security decision-making.
[0101] Based on the inventive concept of the above-mentioned kill chain stage generation method, the present invention also provides a kill chain stage generation device 140, which can be applied to Figure 1 The kill chain generation device 110 in FIG. Figure 7 The kill chain generation device may include an information extraction module 150 , an information expansion module 160 , a generation module 170 and a detection module 180 .
[0102] The information extraction module 150 is configured to extract first associated information about a kill chain stage from attack information of a detected attack behavior.
[0103] The information expansion module 160 is configured to expand the first associated information based on the attack behavior to obtain second associated information.
[0104] The generating module 170 is configured to generate multiple kill chain stages of the attack behavior and feature information of each kill chain stage according to the second correlation information.
[0105] The detection module 180 is configured to detect each kill chain stage, obtain editing information corresponding to the detection result, and modify and store the kill chain stage according to the editing information.
[0106] In the kill chain stage generation device 140, the information extraction module 150, information expansion module 160, generation module 170, and detection module 180 work together to expand the first associated information of the attack behavior at the kill chain generation stage. Furthermore, based on the second associated information obtained after the information expansion, the multiple kill chain stages and characteristic information of each kill chain stage are inferred and expanded. This can greatly improve the richness of the kill chain stage information and alleviate the problem of difficulty in supporting attack analysis such as attacker tactics and homology due to missing information.
[0107] The specific definition of the kill chain stage generation device 140 can be found in the definition of the kill chain stage generation method above and will not be repeated here. Each module within the kill chain stage generation device 140 can be implemented in whole or in part via software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor within an electronic device in hardware form, or stored in the electronic device's memory in software form, allowing the processor to invoke and execute the corresponding operations of each module.
[0108] In one embodiment, an electronic device 190 is provided. The electronic device 190 may be a server, and its internal structure diagram may be as follows: Figure 8 As shown. The electronic device 190 includes a processor, memory, communication interface, display screen and input device connected via a system bus. Among them, the processor of the electronic device 190 is used to provide computing and control capabilities. The memory of the electronic device 190 includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The communication interface of the electronic device 190 is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, an operator network, near field communication (NFC) or other technologies. When the computer program is executed by the processor, the kill chain stage generation method provided in the above embodiment is implemented.
[0109] Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the electronic device 190 to which the solution of the present invention is applied. The specific electronic device 190 may include Figure 8 More or fewer components may be shown, or some components may be combined, or the components may be arranged differently.
[0110] In one embodiment, the kill chain stage generation device 140 provided by the present invention can be implemented in the form of a computer program. The computer program can be used in Figure 8 The electronic device 190 is shown as running. The memory of the electronic device 190 can store various program modules constituting the kill chain stage generation device 140, such as: Figure 8 The information extraction module 150, information expansion module 160, generation module 170 and detection module 180 are shown. The computer program composed of various program modules enables the processor to execute the steps of the kill chain stage generation method described in this specification.
[0111] For example, Figure 8 The electronic device 190 shown may be Figure 7 The information extraction module 150 in the kill chain stage generation device 140 shown executes step S11. The electronic device 190 may execute step S13 through the information expansion module 160. The electronic device 190 may execute step S15 through the generation module 170. The electronic device 190 may execute step S17 through the detection module 180.
[0112] In one embodiment, an electronic device 190 is provided, including a memory and a processor, the memory storing a computer program, and the processor performing the following steps when executing the computer program: for a detected attack behavior, extracting first association information about a kill chain stage from attack information of the attack behavior; based on the attack behavior, expanding the first association information to obtain second association information; generating multiple kill chain stages of the attack behavior and feature information of each kill chain stage based on the second association information; detecting each kill chain stage, obtaining editing information corresponding to the detection result, and modifying and storing the kill chain stage based on the editing information.
[0113] In one embodiment, a storage medium is provided, having a computer program stored thereon. When executed by a processor, the computer program implements the following steps: for a detected attack behavior, extracting first correlation information about a kill chain stage from attack information of the attack behavior; expanding the first correlation information based on the attack behavior to obtain second correlation information; generating multiple kill chain stages of the attack behavior and feature information of each kill chain stage based on the second correlation information; detecting each kill chain stage, obtaining editing information corresponding to the detection result, and modifying and storing the kill chain stage based on the editing information.
[0114] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a portion of code, and the module, program segment or a portion of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0115] In addition, the functional modules in the various embodiments of the present invention may be integrated together to form an independent part, or each module may exist independently, or two or more modules may be integrated to form an independent part.
[0116] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0117] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A kill chain stage generation method, characterized in that: The method comprises: For a detected attack behavior, extract first correlation information about a kill chain stage from attack information of the attack behavior; Based on the attack behavior, the first correlation information is expanded to obtain second correlation information, including: determining an attack type of the attack behavior; obtaining attack target information of the attack behavior from a preset organization information database according to a search rule corresponding to the attack type, the attack target information including the organization or institution to which the attacked target belongs and industry information of the organization or institution to which the attacked target belongs; and combining the attack target information with the first correlation information to obtain second correlation information of the attack behavior; Generating multiple kill chain stages of the attack behavior and characteristic information of each kill chain stage based on the second correlation information includes: determining multiple target generation rules based on a match between the behavior information in the second correlation information and condition information of each generation rule included in a preset generation rule library; and performing kill chain stage inference on each target generation rule using a preset generation engine based on the target generation rule to obtain a target kill chain stage and characteristic information of the target kill chain stage. Each kill chain stage is detected, editing information corresponding to the detection result is obtained, and the kill chain stage is modified and stored according to the editing information.
2. The kill chain stage generation method according to claim 1, characterized in that: The generation rule library includes generation rules for each kill chain stage of each attack behavior. The step of determining multiple target generation rules from the preset generation rule library based on the behavior information in the second association information includes: For each piece of behavior information in the second association information, matching the behavior information with all condition information in the generation rule base; The generation rule corresponding to the condition information matching the behavior information is used as the target generation rule.
3. The kill chain stage generation method according to claim 1, characterized in that: When the attack type is phishing, the step of obtaining the attack target information of the attack behavior from a preset organization information database according to the search rule corresponding to the attack type includes: The domain name of the email recipient of the attack behavior is used as a search item, and the organization corresponding to the email recipient domain name and the industry information of the organization are obtained from a preset organization information database.
4. The kill chain stage generation method according to claim 1, characterized in that: When the attack type is not phishing, the step of obtaining the attack target information of the attack behavior from a preset organization information database according to the search rule corresponding to the attack type includes: The attacked IP of the attack behavior is used as a search item, and the organization corresponding to the attacked IP and the industry information of the organization are obtained from a preset organization information database.
5. The kill chain stage generation method according to claim 1, characterized in that: The step of detecting each kill chain stage and obtaining editing information corresponding to the detection result includes: Interactively displaying all the kill chain stages, characteristic information of each kill chain stage, attack behavior, and second associated information to enable detection personnel to perform detection; For each kill chain stage, editing information input by the detection personnel after detection is obtained.
6. A kill chain stage generation device, used to implement the kill chain stage generation method according to claim 1, characterized in that: It includes information extraction module, information expansion module, generation module and detection module; The information extraction module is configured to extract, for a detected attack behavior, first associated information about a kill chain stage from attack information of the attack behavior; The information expansion module is configured to expand the first associated information based on the attack behavior to obtain second associated information; The generating module is configured to generate multiple kill chain stages of the attack behavior and feature information of each kill chain stage based on the second correlation information; The detection module is configured to detect each of the kill chain stages, obtain editing information corresponding to the detection result, and modify and store the kill chain stage according to the editing information.
7. An electronic device, characterized in that: The system comprises a processor and a memory, wherein the memory stores a computer program executable by the processor, and the processor can execute the computer program to implement the kill chain stage generation method according to any one of claims 1 to 5.
8. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the kill chain stage generation method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
A method and apparatus for identifying network attack chain based on dynamic correlation analysis
CN109167781A
APT attack behavior analysis and detection method and device based on cascade attack chain model
CN110602042A
Network attack victim determination method, equipment, storage medium and device
CN113364780A