Feature library determination method and apparatus, storage medium, and electronic device

CN116032541BActive Publication Date: 2026-08-21HARBIN ANTIY TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211550776.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-05
Publication Date
2026-08-21
Estimated Expiration
2042-12-05

AI Technical Summary

Technical Problem

[0004]本申请实施例提供了一种特征库的确定方法和装置、存储介质及电子装置,以至少解决相关技术中特征库的建立需要大量的样本与模型进行训练,构建效率不高等问题

Benefits of technology

[0015]在本申请实施例中,根据目标对象的检测需求,从预设威胁框架库中确定出目标威胁框架,根据所述目标威胁框架从第一攻击样本中提取第一样本特征;通过预设映射算法对所述第一样本特征与所述目标威胁框架进行框架技术映射,得到映射后的第一威胁技术特征;根据所述第一威胁技术特征和所述第一样本特征形成所述第一攻击样本对应的威胁技术特征库;采用上述技术方案,解决了相关技术中特征库的建立需要大量的样本与模型进行训练,构建效率不高等问题,进而减少了特征库建立训练时间。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032541B_ABST
    Figure CN116032541B_ABST
Patent Text Reader

Abstract

The application discloses a feature library determination method and device, a storage medium and an electronic device. The method comprises the following steps: determining a target threat framework from a preset threat framework library according to the detection requirement of a target object, extracting first sample features from a first attack sample according to the target threat framework, wherein the first sample features comprise static features and / or dynamic features; performing framework technology mapping on the first sample features and the target threat framework through a preset mapping algorithm to obtain mapped first threat technology features; and forming a threat technology feature library corresponding to the first attack sample according to the first threat technology features and the first sample features. By using the technical solution, the problem that a large number of samples and models need to be trained for establishing a feature library and the construction efficiency of the feature library is low in the related art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and more specifically, to a method and apparatus for determining a signature database, a storage medium, and an electronic device. Background Technology

[0002] In related technologies, most methods for detecting unknown targeted threat attacks (APTs, Advanced Persistent Threats) employ intelligent detection and machine learning. However, these methods require a large number of samples and time to train and build models / feature libraries, and the detection effect is not significant.

[0003] In response to the problems in related technologies, such as the need for a large number of samples and models to train the feature library, resulting in low construction efficiency, no effective solution has yet been proposed. Summary of the Invention

[0004] This application provides a method and apparatus for determining a feature library, a storage medium, and an electronic device, to at least solve the problems in related technologies where the establishment of a feature library requires a large number of samples and models for training, resulting in low construction efficiency.

[0005] According to one embodiment of this application, a method for determining a feature library is provided, comprising: determining a target threat framework from a preset threat framework library based on the detection requirements of the target object; extracting a first sample feature from a first attack sample based on the target threat framework, wherein the first sample feature includes: static features and / or dynamic features; performing a frame technology mapping between the first sample feature and the target threat framework using a preset mapping algorithm to obtain a mapped first threat technology feature; and forming a threat technology feature library corresponding to the first attack sample based on the first threat technology feature and the first sample feature.

[0006] In an exemplary embodiment, after forming a threat technology feature library corresponding to the first attack sample based on the threat technology features, the method further includes: determining second sample features of a plurality of second attack samples to obtain a second sample feature set; performing a frame technology mapping between the second sample feature set and the target threat framework using a preset mapping algorithm to obtain mapped second threat technology features; and updating the threat technology feature library using the second threat technology features.

[0007] In an exemplary embodiment, the method further includes: if an unknown attack sample of an unknown threat is obtained, determining a third sample feature corresponding to the unknown attack sample; performing a frame technology mapping between the third sample feature and the target threat framework using a preset mapping algorithm to obtain a mapped third threat technology feature; determining the matching degree between the third threat technology feature and the threat technology features in the threat technology feature library; and if the matching degree is greater than a preset matching degree, performing threat analysis on the unknown attack sample.

[0008] In an exemplary embodiment, if the matching degree is greater than a preset matching degree, after performing threat analysis on the unknown attack sample, the method further includes: sending the unknown attack sample to a target object for sample analysis; obtaining the analysis result determined by the target object for the unknown attack sample; and parsing the analysis result to determine whether to use the unknown attack sample to supplement the threat technology feature library.

[0009] In one exemplary embodiment, parsing the analysis results to determine whether to use the unknown attack sample to supplement the threat technology signature database includes: if the analysis results indicate that the sample type of the unknown attack sample is an advanced persistent threat sample, determining to use the unknown attack sample to supplement the threat technology signature database; if the analysis results indicate that the sample type of the unknown attack sample is not an advanced persistent threat sample, determining not to use the unknown attack sample to supplement the threat technology signature database.

[0010] In an exemplary embodiment, determining to supplement the threat technology feature library with the unknown attack sample includes: determining a target feature vector corresponding to the unknown attack sample, wherein the target feature vector includes: a third sample feature and a third threat technology feature corresponding to the unknown attack sample; and using the target feature vector to supplement an existing feature vector to supplement the threat technology feature library, wherein the existing feature vector is used to indicate the vectors existing in the threat technology feature library.

[0011] In an exemplary embodiment, determining a target threat framework from a preset threat framework library based on the detection requirements of the target object includes: determining the analysis category and mapping category to be performed on the target object based on the detection requirements, and determining the target category parameter for finding the threat framework based on the analysis category and the mapping category; determining the similarity between the framework category parameter corresponding to each threat framework in the preset threat framework library and the target category parameter; and determining the threat framework corresponding to the framework category parameter with the highest similarity to the target category parameter as the target threat framework to be used.

[0012] According to another embodiment of the present application, a feature library determination device is also provided, comprising: an extraction module, configured to determine a target threat framework from a preset threat framework library according to the detection requirements of the target object, and extract a first sample feature from a first attack sample according to the target threat framework, wherein the first sample feature includes: static features and / or dynamic features; a mapping module, configured to perform a framework technology mapping between the first sample feature and the target threat framework using a preset mapping algorithm to obtain a mapped first threat technology feature; and a feature module, configured to form a threat technology feature library corresponding to the first attack sample based on the first threat technology feature and the first sample feature.

[0013] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer program, and the computer program is configured to execute the above-described method for determining the feature library at runtime.

[0014] According to another aspect of the embodiments of this application, an electronic device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the aforementioned method for determining the feature library through the computer program.

[0015] In this embodiment, based on the detection requirements of the target object, a target threat framework is determined from a preset threat framework library, and a first sample feature is extracted from a first attack sample based on the target threat framework. A preset mapping algorithm is used to perform a framework technology mapping between the first sample feature and the target threat framework to obtain a mapped first threat technology feature. A threat technology feature library corresponding to the first attack sample is formed based on the first threat technology feature and the first sample feature. By adopting the above technical solution, the problems of low efficiency in building feature libraries due to the need for a large number of samples and models for training are solved, thereby reducing the training time for feature library establishment. Attached Figure Description

[0016] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0017] Figure 1 This is a hardware structure block diagram of a computer terminal for a method of determining a feature library according to an embodiment of this application.

[0018] Figure 2 This is a flowchart of a method for determining a feature library according to an embodiment of this application;

[0019] Figure 3This is a schematic diagram of a method for determining a feature library according to an embodiment of this application;

[0020] Figure 4 This is a schematic diagram of the architecture of the detection system according to an embodiment of this application;

[0021] Figure 5 This is a structural block diagram of a feature library determination device according to an embodiment of this application. Detailed Implementation

[0022] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0024] To better understand the embodiments corresponding to this application, the technical terms used in this application are explained below, but this explanation is not intended to be limiting.

[0025] Threat Framework: A threat framework is a system of methods and tools for systematically understanding cyber threats and building effective defenses. It is a scientific system of methods and tools that enables a deeper understanding of APT (Aggressive Persistent Threat) cyber threats, comprehensively analyzing their attack intentions, methods, processes, and techniques to enhance defense effectiveness. Threat frameworks typically adopt a hierarchical structure. This hierarchical structure achieves a basic consensus on analysis by constructing and defining core concepts and terminology; it then introduces more or more concrete attribute descriptions, feature extraction, relationship characterization, functional roles, and even algorithmic deductions, forming progressively deeper analytical layers, ultimately constituting a multi-layered analytical system. Using this analytical system, cyber defenders can conduct cyber threat analysis and prediction, exchange and share intelligence, optimize defense measures, and improve their defensive posture.

[0026] Feature vectors: A collective term for the data extracted for machine learning training. These data have categories, as well as specific attributes and meanings. For example, having auto-start behavior can be considered a category, while implementing auto-start behavior through the registry or functions are considered specific attributes.

[0027] Feature library: A feature library is a database file that stores a certain type of feature information. By obtaining the feature information of a sample, performing a series of complex calculations, and matching it with the feature information stored in the feature library, the probability of the sample being a malicious sample can be analyzed and determined.

[0028] The methods and embodiments provided in this application can be executed on a computer terminal or similar computing device. Taking running on a computer terminal as an example, Figure 1 This is a hardware structure block diagram of a computer terminal for a method of determining a feature library according to an embodiment of this application. For example... Figure 1 As shown, a computer terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. In one exemplary embodiment, the computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the computer terminal described above. For example, the computer terminal may also include components that are more complex than those described above. Figure 1 The more or fewer components shown, or having the same Figure 1 Equivalent functions or ratios shown Figure 1 The functions shown have more different configurations.

[0029] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the feature library determination method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, thus implementing the above-described method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0030] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the computer terminal. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0031] This embodiment provides a method for determining a feature library, applied to the aforementioned computer terminal. Figure 2 This is a flowchart of a method for determining a feature library according to an embodiment of this application, the process including the following steps:

[0032] Step S202: Based on the detection requirements of the target object, determine the target threat framework from the preset threat framework library, and extract the first sample features from the first attack sample based on the target threat framework;

[0033] The first sample feature includes at least one of the following: static features and dynamic features; optionally, the threat frameworks in the aforementioned preset threat framework library may include MITRE's ATT&CK, NSA's TCTF framework, Mandiant's MBC threat framework, etc. In practical use, based on the type of attack sample to be detected by the target object, an appropriate threat framework is selected by analyzing different threat framework models and combining existing analysis methods and attack technique mapping methods.

[0034] Step S204: The first sample features and the target threat framework are mapped using a preset mapping algorithm to obtain the mapped first threat technology features;

[0035] Step S206: Form a threat technology feature library corresponding to the first attack sample based on the first threat technology features and the first sample features.

[0036] Optionally, if the target needs to establish multiple threat signature databases, determine the organization identifier of the target organization corresponding to each signature database; add the organization identifier to the name corresponding to each signature database for marking.

[0037] Through the above steps, when a target threat framework is determined from a preset threat framework library based on the detection requirements of the target object, a first sample feature is extracted from a first attack sample based on the target threat framework. The first sample feature includes at least one of the following: static features and dynamic features. A preset mapping algorithm is used to map the first sample feature to the target threat framework, resulting in a mapped first threat technology feature. A threat technology feature library corresponding to the first attack sample is formed based on the first threat technology feature and the first sample feature. This technical solution solves the problems of low efficiency in feature library construction due to the need for a large number of samples and models for training, thereby reducing the training time for feature library construction.

[0038] It should be noted that the first attack sample mentioned above can be an APT attack sample of an Advanced Persistent Threat (APT). Using the above method, the threat technology feature library based on the threat framework does not require massive samples for modeling and training. Instead, it analyzes the first attack sample of a known threat, infers the characteristics of the APT organization in terms of attack technology, and extracts features, thereby reducing the time required to build and train the feature library and reducing the number of samples required to build the feature library.

[0039] In an exemplary embodiment, after forming a threat technology feature library corresponding to the first attack sample based on the threat technology features, the method further includes: determining second sample features of a plurality of second attack samples to obtain a second sample feature set; performing a frame technology mapping between the second sample feature set and the target threat framework using a preset mapping algorithm to obtain mapped second threat technology features; and updating the threat technology feature library using the second threat technology features.

[0040] Optionally, the first attack sample and the second attack sample are advanced persistent threat samples of known threats. In addition, the output objects of the first attack sample and the second attack sample can be different or the same. For example, the first attack sample and the second attack sample are samples of attack records made by the same attacking organization at different times, or the first attack sample is an attack sample corresponding to attacking organization A and the second attack sample is an attack sample corresponding to attacking organization B. That is, by enriching the sources of known threat samples, the identified threat technical feature library is made more comprehensive in application, and by increasing the number of samples, the accuracy of the threat technical feature library in identifying unknown samples is increased.

[0041] Understandably, the more threat signatures in the threat signature database, the more accurate the identification of unknown samples will be when using the database. Therefore, the threat signature database can be improved by identifying multiple second attack samples that have similar attack methods, tactics, and techniques to the first attack sample, making the database more comprehensive in identifying the corresponding unknown samples. In addition, the second attack sample can be a sample generated after the first attack sample, which is the same as the first attack sample. The second attack sample can be used to verify and improve the currently generated threat signature database.

[0042] Optionally, the above-mentioned verification and improvement of the currently generated threat technology feature library through the second attack sample includes: using the threat technology feature library to identify the second attack sample and determine whether the features of the second attack sample are the same as those of the first attack sample; when there is a difference, determining the second threat technology feature corresponding to the second attack sample that has different features from the first attack sample, and adding the second threat technology feature to the threat technology feature library, so that the threat technology feature library can identify threat technology features more comprehensively and accurately.

[0043] In an exemplary embodiment, the method further includes: when an unknown attack sample of an unknown threat is obtained, determining a third sample feature corresponding to the unknown attack sample; mapping the third sample feature to the target threat framework using a preset mapping algorithm to obtain a mapped third threat technical feature; determining the matching degree between the third threat technical feature and the threat technical features in the threat technical feature library; and determining that threat analysis needs to be performed on the unknown attack sample when the matching degree is greater than a preset matching degree.

[0044] In simple terms, after the threat signature database is determined, it can be used to analyze unknown attack samples. For example, the features of an unknown attack sample can be extracted and the mapping results of the features of the unknown attack sample in the threat framework can be determined to obtain the third threat signature. The third threat signature is then matched with the established threat signature database to obtain the matching degree. That is, the matching degree between features is used to determine whether the unknown attack sample belongs to the type of attack sample corresponding to the current threat signature database.

[0045] In other words, by constructing threat technology feature libraries corresponding to different attack samples, and combining multiple threat technology feature libraries, a comprehensive feature library can be determined. Through this feature library, unknown attack samples with similar threat technology features to those in the feature library can be actively identified. In turn, corresponding samples can be found from multiple unknown samples, improving the detection efficiency of high-threat attack samples and providing basic data support for network defense.

[0046] In an exemplary embodiment, after determining that threat analysis needs to be performed on the unknown attack sample when the matching degree is greater than a preset matching degree, the method further includes: sending the unknown attack sample to a target object for sample analysis; obtaining the analysis result determined by the target object for the unknown attack sample; and parsing the analysis result to determine whether to use the unknown attack sample to supplement the threat technology feature library.

[0047] In one exemplary embodiment, parsing the analysis results to determine whether to use the unknown attack sample to supplement the threat technology signature database includes: if the analysis results indicate that the sample type of the unknown attack sample is an advanced persistent threat sample, determining to use the unknown attack sample to supplement the threat technology signature database; and if the analysis results indicate that the sample type of the unknown attack sample is not an advanced persistent threat sample, determining not to use the unknown attack sample to supplement the threat technology signature database.

[0048] Understandably, when an unknown attack sample is identified as requiring further analysis, it indicates that the sample is suspected to be an advanced persistent threat (APS) sample. Specific analysis of the target object is needed to better determine the threat details corresponding to the unknown attack sample. Specifically, this involves determining whether the current unknown attack sample is indeed an APPS sample and identifying whether the target feature vector corresponding to the unknown attack sample is similar to multiple feature vectors in the threat signature database. If no similarity is found, the unknown attack sample is determined to be a first-time occurrence, and it needs to be used to supplement the threat signature database, thereby improving the accuracy of identifying different unknown samples.

[0049] Optionally, for dynamic features, unknown attack samples can be run on virtual machines to simulate the actual execution results of the unknown attack samples and obtain the corresponding execution records. This allows system monitoring software to capture the system calls of the running malicious code (equivalent to the aforementioned unknown attack samples). From the captured information, a series of operations such as registry and file read / write can be obtained, facilitating further analysis. If necessary, a virtual network response needs to be simulated on the local machine to respond to the network access of the malicious code, monitor its network dynamics, understand network-related characteristics, capture the dynamic behavioral features of the unknown attack samples, and then map them onto the threat framework to obtain the first technical point. Combined with static analysis, the obtained static behavioral features, and the second technical point obtained by mapping onto the threat framework, an attack technical feature (equivalent to the target feature vector in the above embodiment) is formed. This attack technical feature is used to supplement and improve the established threat technical feature library.

[0050] Optionally, the types of the aforementioned unknown attack samples can be divided into: general samples and advanced persistent threat samples. General samples can be understood as samples of low value, and there is no need to supplement the features of the generated threat signature database based on these general samples. Advanced persistent threat samples can be understood as samples of high value, whose corresponding threat signatures may be threat signatures that are not currently present in the threat signature database or whose recognition accuracy is low in the current threat signature database. Therefore, it is necessary to use unknown attack samples to supplement the features of the generated threat signature database. By determining the target feature vector of the unknown attack sample, the target feature vector is fused with the generated threat signature database, thereby enhancing the accuracy of the generated threat signature database in recognizing samples with low recognition accuracy and making the feature recognition of the threat signature database more diversified.

[0051] In an exemplary embodiment, determining to supplement the threat technology feature library with the unknown attack sample includes: determining a target feature vector corresponding to the unknown attack sample, wherein the target feature vector includes: a third sample feature corresponding to the unknown attack sample and a third threat technology feature corresponding to the unknown attack sample; and using the target feature vector to supplement existing feature vectors to supplement the threat technology feature library, wherein the existing feature vectors are used to indicate vectors existing in the threat technology feature library.

[0052] It should be noted that, in order to ensure that the determined threat signature database can quickly identify attack samples with high threat levels, when generating the threat signature database, a target number of attack samples will be determined from multiple attack samples of known threats to the target object as the basis for generating the threat signature database. This will enable the determined threat signature database to identify attack samples corresponding to high threat features to the greatest extent. The aforementioned target number can be flexibly set according to the actual application situation, and this application does not impose too many restrictions on it.

[0053] In an exemplary embodiment, determining a target threat framework from a preset threat framework library based on the detection requirements of the target object includes: determining the analysis category and mapping category to be performed on the target object based on the detection requirements, and determining the target category parameter for finding the threat framework based on the analysis category and the mapping category; determining the similarity between the framework category parameter corresponding to each threat framework in the preset threat framework library and the target category parameter; and determining the threat framework corresponding to the framework category parameter with the highest similarity to the target category parameter as the target threat framework to be used.

[0054] In other words, the threat framework is the most suitable threat framework determined from the preset threat framework library based on actual detection needs. Optionally, the preset threat framework library also initiates framework updates within a preset time period, thereby incorporating the latest publicly available threat frameworks into the preset threat framework library. Furthermore, the target object can initiate a framework adjustment command to write the new framework into the preset threat framework library. This ensures the efficiency of generating the corresponding threat technical feature library using the target threat framework in the preset threat framework library and greatly improves the practicality of the determined threat technical feature library.

[0055] To better understand the process of determining the feature library described above, the implementation flow of the method for determining the feature library will be further explained below with reference to optional embodiments, but this is not intended to limit the technical solution of the embodiments of this application.

[0056] This embodiment provides a method for determining a feature library. By establishing a corresponding feature library, the threat framework mapped to all attack samples of a certain attack organization is organized and related threat technical features are formed. Through continuous optimization of the threat technical features, an attack method tactical stack feature library is formed (equivalent to the threat technical feature library in the above embodiment). This library is then used as an analysis tool to analyze samples, which can increase the detection capability of unknown threats while also taking into account the source tracing capability of unknown samples. Figure 3 This is a schematic diagram of a method for determining a feature library according to an embodiment of this application, as shown below. Figure 3 As shown, the specific steps are as follows:

[0057] Step S01: Threat Framework Selection; By analyzing different threat framework models, combining existing analysis methods and attack technique mapping methods, an appropriate threat framework is selected, and supplemented and improved as needed. It should be noted that the preliminary threat framework selection will be completed before conducting APT attack analysis.

[0058] Step S02: Extract the dynamic and static features of the APT attack sample;

[0059] Optionally, for a specific attack by a particular attack organization, all samples involved in the attack can be extracted for dynamic and static analysis, and dynamic and static features can be extracted. Specifically, static features are partially visible features obtained by viewing the resource nodes of the sample's corresponding code, such as icons, menu interfaces, code versions, etc. Dynamic features are obtained by simulating a virtual network response from the local machine to respond to the network access of the attack sample, monitoring its network dynamics, thereby understanding network-related characteristics and the characteristics that may cause adverse consequences after execution.

[0060] S03: Attack Technique Mapping; Based on the extracted dynamic and static features and the selected threat framework, threat framework technique mapping is performed using a technique mapping algorithm.

[0061] S04: Establish an attack technology stack feature library (equivalent to the threat technology feature library in the above embodiments); organize the mapped technology points (equivalent to the threat technology features in the above embodiments) to form an attack technology stack feature library of a certain APT organization.

[0062] S05: Improve and adjust the attack technology stack feature library; extract sample features from previous attacks launched by the same organization, repeat steps S02 to S03, and use the feature library established in S04 for matching and verification. If significant differences are found, supplement and improve the feature library.

[0063] S06: Improve the APT attack technique stack feature library; extract sample features from past attacks by other attack organizations, threat framework mapping results, repeat steps S02-S05, and establish an APT-type sample attack technique stack feature library. That is, identify the attack technique stack feature libraries corresponding to different organizations, summarize these attack technique stack feature libraries, and determine the APT-type sample attack technique stack feature library. Through this APT-type sample attack technique stack feature library, the organization corresponding to an unknown attack sample can be identified, and the threat level corresponding to the unknown attack sample can be determined.

[0064] S07: Detection and analysis of unknown threat samples;

[0065] The features and threat framework mapping results of a certain unknown attack sample are extracted and matched with the established attack technology stack feature library to obtain the matching degree. The samples with high matching degree are then further analyzed.

[0066] S08: New Feature Addition; This means confirming the addition of newly discovered APT sample attack techniques to the database. The specific process is as follows: Analyze and confirm newly discovered unknown threats to determine whether they are Advanced Persistent Threat (APPT) samples. For newly confirmed APPTs, follow steps S02 to S05 to add the newly extracted attack technique stack features to the attack technique stack feature database.

[0067] As an optional implementation, an alternative embodiment of the present invention also provides an advanced persistent threat sample detection system based on a combination of multiple attack technology stacks. Figure 4 This is a schematic diagram of the architecture of the detection system according to an embodiment of this application. It utilizes known advanced persistent threat samples and threat framework attack technology stacks, and through technology mapping and feature library refinement, forms a feature library based on the attack technology stack. For unknown samples, dynamic and static features are extracted, and threat framework technology points are mapped to obtain attack technology features. These features are then matched and calculated with the feature library of the attack technology stack to determine whether the sample is a potentially high-value sample.

[0068] It should be noted that the feature library built using the above method for Advanced Persistent Threat (APT) samples is small and precise, and its creation time is relatively short, unlike machine learning and intelligent computing which require large amounts of data for training. Therefore, it can save a significant amount of sample training time. Furthermore, by establishing a feature library based on the attack technology stack through the mapping relationship between the features corresponding to the attack samples and the threat framework, the determined feature library greatly enhances the detection capability for unknown malicious threats.

[0069] As an alternative implementation, a novel method for detecting unknown attack samples is proposed. This method extracts dynamic and static features from attack samples of advanced persistent threat (APS) groups and maps them to selected threat frameworks to form a feature library based on the attack technology stack. Dynamic and static analysis is performed on unknown threat samples, and threat framework technology mapping is performed to obtain the attack technology stack features of the unknown samples. These features are then matched with the established feature library of attack technology stacks to calculate the matching degree between the samples and the attack organization's samples.

[0070] Optionally, the specific implementation process of the above detection method is as follows:

[0071] Step 1: By analyzing different threat framework models, combining existing analysis methods and attack technique mapping methods, select an appropriate threat framework, and supplement and improve it as needed.

[0072] Step 2: For a specific attack by a certain attacking organization, extract all samples involved in the attack and perform dynamic and static analysis, and extract dynamic and static features.

[0073] Step 3: Based on the extracted dynamic and static features and the selected threat framework, perform threat framework technology mapping using a technology mapping algorithm.

[0074] Step 4: Organize the mapped technical points to form a feature library of attack techniques of a certain APT group.

[0075] Step 5: Extract sample features from previous attacks launched by the same organization, repeat the steps in Step 2 and Step 3 above, and use the feature library established in Step 4 for matching and verification. If significant differences are found, supplement and improve the feature library.

[0076] Step 6: Extract sample features and threat framework mapping results from previous attacks by other attack organizations, and repeat steps 2 to 5 to establish an APT-type sample attack technology stack feature library.

[0077] Step 7: Extract the features of a certain unknown attack sample and the threat framework mapping results, perform matching operations with the established attack technology stack feature library, obtain the matching degree, and further analyze the samples with high matching degrees.

[0078] Step 8: For newly discovered and confirmed advanced persistent threat samples, perform feature extraction and technology stack mapping, and supplement them to the sample attack technology stack feature library.

[0079] In summary, by using the threat framework as a template, a feature library based on the full attack technology stack was created. By matching the feature library of sample attack technology stacks with the corresponding technology stack features of unknown samples, a new approach and method are provided for the detection and discovery of unknown threat samples. Feature extraction is performed by inferring the attack technology characteristics of advanced persistent threat organizations by analyzing known threats, reducing the training time for feature library / model building. For unknown advanced persistent threat samples, the analyzed attack technology stack feature library provides a new detection approach for unknown threats, increasing the ability to discover unknown threats. Furthermore, the process of building the attack technology stack feature library for advanced persistent threats can be continuously optimized, increasing the detection capability of unknown threats while also considering the source tracing capability of unknown samples, improving threat detection accuracy, and providing methodological support for network defense.

[0080] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.

[0081] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0082] According to another aspect of the present invention, an apparatus for determining a feature library for implementing the above-described method for determining a feature library is also provided. For example... Figure 5 As shown, Figure 5 This is a schematic diagram of an optional feature library determination device according to an embodiment of the present invention, the device comprising:

[0083] Extraction module 52 is used to determine the target threat framework from the preset threat framework library according to the detection requirements of the target object, and extract the first sample feature from the first attack sample according to the target threat framework, wherein the first sample feature includes: static features and / or dynamic features;

[0084] Optionally, the first attack sample mentioned above can be multiple attack samples belonging to the same attack organization for known threats, or multiple attack samples belonging to different attack organizations for known threats.

[0085] Mapping module 54 is used to perform frame technology mapping between the first sample features and the target threat framework using a preset mapping algorithm to obtain the mapped first threat technology features;

[0086] The feature module 56 is used to form a threat technology feature library corresponding to the first attack sample based on the first threat technology features and the first sample features.

[0087] Using the above-mentioned device, a target threat framework is determined from a preset threat framework library according to the detection requirements of the target object. A first sample feature is extracted from a first attack sample based on the target threat framework. The first sample feature and the target threat framework are mapped using a preset mapping algorithm to obtain the mapped first threat technology feature. A threat technology feature library corresponding to the first attack sample is formed based on the first threat technology feature and the first sample feature. By adopting the above technical solution, the problems of low construction efficiency caused by the need for a large number of samples and models to train the feature library in related technologies are solved, thereby reducing the feature library establishment and training time.

[0088] In one exemplary embodiment, the above apparatus further includes: an update module, configured to determine second sample features of a plurality of second attack samples to obtain a second sample feature set; perform a frame technology mapping between the second sample feature set and the target threat framework using a preset mapping algorithm to obtain a mapped second threat technology feature; and update the threat technology feature library using the second threat technology feature.

[0089] Understandably, the more threat signatures in the threat signature database, the more accurate the identification of unknown samples will be when using the database. Therefore, the threat signature database can be improved by identifying multiple second attack samples that have similar attack methods, tactics, and techniques to the first attack sample, making the database more comprehensive in identifying the corresponding unknown samples. In addition, the second attack sample can be a sample generated after the first attack sample, which is the same as the first attack sample. The second attack sample can be used to verify and improve the currently generated threat signature database.

[0090] Optionally, the above-mentioned verification and improvement of the currently generated threat technology feature library can be achieved through the second attack sample, including: using the threat technology feature library to identify the second attack sample and determine whether the features of the second attack sample are the same as those of the first attack sample; when there are differences, determining the second threat technology feature corresponding to the second attack sample that has different features from the first attack sample, and adding the second threat technology feature to the threat technology feature library, so that the threat technology feature library can identify threat technology features more comprehensively and accurately.

[0091] In an exemplary embodiment, the above apparatus further includes: a matching module, configured to, if an unknown attack sample of an unknown threat is obtained, determine a third sample feature corresponding to the unknown attack sample; perform a frame technology mapping between the third sample feature and the target threat frame using a preset mapping algorithm to obtain a mapped third threat technology feature; determine the matching degree between the third threat technology feature and the threat technology features in the threat technology feature library; and if the matching degree is greater than a preset matching degree, determine that threat analysis needs to be performed on the unknown attack sample.

[0092] In simple terms, after the threat signature database is determined, it can be used to analyze unknown attack samples. For example, the features of an unknown attack sample can be extracted and the mapping results of the features of the unknown attack sample in the threat framework can be determined to obtain the third threat signature. The third threat signature is then matched with the established threat signature database to obtain the matching degree. That is, the matching degree between the features is used to determine whether the unknown attack sample belongs to the type of attack sample corresponding to the current threat signature database.

[0093] In other words, by constructing threat technology feature libraries corresponding to different attack samples, and combining multiple threat technology feature libraries, a comprehensive feature library can be determined. Through this feature library, unknown attack samples with similar threat technology features to those in the feature library can be actively identified. In turn, corresponding samples can be found from multiple unknown samples, improving the detection efficiency of high-threat attack samples and providing basic data support for network defense.

[0094] In an exemplary embodiment, the matching module further includes: an analysis unit, configured to send the unknown attack sample to a target object for sample analysis; obtain the analysis results determined by the target object for the unknown attack sample; and parse the analysis results to determine whether to use the unknown attack sample to supplement the threat technology feature database.

[0095] In an exemplary embodiment, the analysis unit is further configured to: if the analysis result indicates that the unknown attack sample is an advanced persistent threat sample, determine to use the unknown attack sample to supplement the threat technology feature database; if the analysis result indicates that the unknown attack sample is not an advanced persistent threat sample, determine not to use the unknown attack sample to supplement the threat technology feature database.

[0096] In an exemplary embodiment, the analysis unit is further configured to determine a target feature vector corresponding to the unknown attack sample, wherein the target feature vector includes: a third sample feature corresponding to the unknown attack sample and a third threat technology feature corresponding to the unknown attack sample; and to supplement existing feature vectors with the target feature vector to supplement the threat technology feature library, wherein the existing feature vectors are used to indicate vectors existing in the threat technology feature library.

[0097] Understandably, when an unknown attack sample is identified as requiring further analysis, it indicates that the sample is suspected to be an advanced persistent threat (APS) sample. Specific analysis of the target object is needed to better determine the threat details corresponding to the unknown attack sample. Specifically, this involves determining whether the current unknown attack sample is indeed an APPS sample and identifying whether the target feature vector corresponding to the unknown attack sample is similar to multiple feature vectors in the threat signature database. If no similarity is found, the unknown attack sample is determined to be a first-time occurrence, and it needs to be used to supplement the threat signature database, thereby improving the accuracy of identifying different unknown samples.

[0098] Optionally, for dynamic features, unknown attack samples can be run on virtual machines to simulate the actual execution results of the unknown attack samples and obtain the corresponding execution records. This allows system monitoring software to capture the system calls of the running malicious code (equivalent to the aforementioned unknown attack samples). From the captured information, a series of operations such as registry and file read / write can be obtained, facilitating further analysis. If necessary, a virtual network response needs to be simulated on the local machine to respond to the network access of the malicious code, monitor its network dynamics, understand network-related characteristics, capture the dynamic behavioral features of the unknown attack samples, and then map them onto the threat framework to obtain the first technical point. Combined with static analysis, the obtained static behavioral features, and the second technical point obtained by mapping onto the threat framework, an attack technical feature (equivalent to the target feature vector in the above embodiment) is formed. This attack technical feature is used to supplement and improve the established threat technical feature library.

[0099] Optionally, the types of the aforementioned unknown attack samples can be categorized as: general samples and advanced persistent threat samples. General samples can be understood as samples of low value, and there is no need to supplement the existing threat signature database based on these general samples. Advanced persistent threat samples can be understood as samples of high value, whose corresponding threat signatures may be those not currently present in the threat signature database or whose identification accuracy is low. Therefore, it is necessary to use unknown attack samples to supplement the existing threat signature database. By determining the target feature vector of the unknown attack sample, this target feature vector is fused with the existing threat signature database, thereby enhancing the accuracy of the existing threat signature database in identifying samples with low identification accuracy and making the feature identification of the threat signature database more diversified.

[0100] It should be noted that, in order to ensure that the determined threat signature database can quickly identify attack samples with high threat levels, when generating the threat signature database, a target number of attack samples will be determined from multiple attack samples of known threats to the target object as the basis for generating the threat signature database. This will enable the determined threat signature database to identify attack samples corresponding to high threat features to the greatest extent. The aforementioned target number can be flexibly set according to the actual application situation, and this application does not impose too many restrictions on it.

[0101] In an exemplary embodiment, the above apparatus further includes: a determining module, configured to determine the analysis category and mapping category to be performed on the target object according to the detection requirements, and determine the target category parameter for finding threat frameworks based on the analysis category and the mapping category; determine the similarity between the framework category parameter corresponding to each threat framework in the preset threat framework library and the target category parameter; and determine the threat framework corresponding to the framework category parameter with the highest similarity to the target category parameter as the target threat framework to be used.

[0102] In other words, the threat framework is the most suitable threat framework determined from the preset threat framework library based on actual detection needs. Optionally, the preset threat framework library also initiates framework updates within a preset time period, thereby incorporating the latest publicly available threat frameworks into the preset threat framework library. Furthermore, the target object can initiate a framework adjustment command to write the new framework into the preset threat framework library. This ensures the efficiency of generating the corresponding threat technical feature library using the target threat framework in the preset threat framework library and greatly improves the practicality of the determined threat technical feature library.

[0103] For specific implementation examples, please refer to the examples shown in the above-described method for determining the feature library; these examples will not be repeated here.

[0104] Optionally, in this embodiment, the aforementioned electronic device may be located in at least one of a plurality of network devices in a computer network.

[0105] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:

[0106] S1, based on the detection requirements of the target object, determine the target threat framework from the preset threat framework library, and extract the first sample feature from the first attack sample based on the target threat framework, wherein the first sample feature includes: static features and / or dynamic features;

[0107] S2, using a preset mapping algorithm, the first sample features are mapped to the target threat framework to obtain the mapped first threat technology features;

[0108] S3, Based on the first threat technical features and the first sample features, a threat technical feature library corresponding to the first attack sample is formed.

[0109] In one embodiment, the aforementioned terminal device or server can be a node in a distributed system, wherein the distributed system can be a blockchain system, which is a distributed system formed by connecting multiple nodes through network communication. The nodes can form a peer-to-peer (P2P) network, and any form of computing device, such as a server, terminal, or other electronic device, can become a node in the blockchain system by joining this peer-to-peer network.

[0110] According to one aspect of this application, a computer program product is provided, comprising a computer program / instructions containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via a communication component, and / or installed from a removable medium. When the computer program is executed by a central processing unit, it performs various functions provided in embodiments of this application.

[0111] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0112] It should be noted that the computer system of the electronic device is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0113] A computer system includes a Central Processing Unit (CPU), which performs various appropriate actions and processes based on programs stored in Read-Only Memory (ROM) or loaded from RAM. ROM also stores various programs and data required for system operation. The CPU, ROM, and RAM are interconnected via a bus. Input / output interfaces (I / O interfaces) are also connected to the bus.

[0114] The following components are connected to the input / output interface: input sections including keyboards, mice, etc.; output sections including cathode ray tubes (CRTs), liquid crystal displays (LCDs), and speakers; storage sections including hard drives; and communication sections including network interface cards such as LAN cards and modems. The communication section performs communication processing via a network such as the Internet. Drives are also connected to the input / output interface as needed. Removable media, such as disks, optical discs, magneto-optical discs, semiconductor memories, etc., are installed on the drive as needed so that computer programs read from them can be installed into the storage section as required.

[0115] Specifically, according to embodiments of this application, the processes described in the various method flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication component, and / or installed from a removable medium. When the computer program is executed by a central processing unit, it performs various functions defined in the system of this application.

[0116] According to one aspect of this application, a computer-readable storage medium is provided, wherein a processor of a computer device reads computer instructions from the computer-readable storage medium, and executes the computer instructions, causing the computer device to perform the methods provided in the various alternative implementations described above.

[0117] Optionally, in this embodiment, the computer-readable storage medium described above may be configured to store a computer program for performing the following steps:

[0118] S1, based on the detection requirements of the target object, determine the target threat framework from the preset threat framework library, and extract the first sample feature from the first attack sample based on the target threat framework, wherein the first sample feature includes: static features and / or dynamic features;

[0119] S2, using a preset mapping algorithm, the first sample features are mapped to the target threat framework to obtain the mapped first threat technology features;

[0120] S3, Based on the first threat technical features and the first sample features, a threat technical feature library corresponding to the first attack sample is formed.

[0121] Optionally, in this embodiment, those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0122] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0123] If the integrated units in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in the aforementioned computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause one or more computer devices (which may be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention.

[0124] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0125] In the several embodiments provided in this application, it should be understood that the disclosed client can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between units or modules, and may be electrical or other forms.

[0126] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0127] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0128] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for determining a feature library, characterized in that, include: Based on the detection requirements of the target object, a target threat framework is determined from a preset threat framework library, and a first sample feature is extracted from a first attack sample based on the target threat framework, wherein the first sample feature includes: static features and / or dynamic features; The first sample features are mapped to the target threat framework using a preset mapping algorithm to obtain the mapped first threat technology features. A threat technology feature library corresponding to the first attack sample is formed based on the first threat technology feature and the first sample feature; The name of the threat signature database shall at least include the organization identifier corresponding to the first attack sample; the first attack sample is an advanced persistent threat sample of a known threat. The step of determining the target threat framework from a preset threat framework library based on the detection requirements of the target object includes: Based on the detection requirements, the target category parameters of the threat framework to be searched are determined. The target category parameters are used to indicate the analysis category and mapping category to be performed on the target object. Determine the similarity between the frame category parameter corresponding to each threat frame in the preset threat framework library and the target category parameter; The threat framework corresponding to the frame category parameter with the highest similarity to the target category parameter is determined as the target threat framework to be used; wherein, the preset threat framework library is a framework library that initiates framework updates within a preset time period, and the newly added updated framework is written to the current preset threat framework library through the framework adjustment instruction issued by the target object.

2. The method for determining the feature library according to claim 1, characterized in that, After forming a threat signature database corresponding to the first attack sample based on the first threat signature and the first sample signature, the method further includes: Determine the second sample features of multiple second attack samples to obtain the second sample feature set; The second sample feature set is mapped to the target threat framework by a preset mapping algorithm to obtain the mapped second threat technology features. The threat technology feature library is updated using the second threat technology feature and the second sample feature set.

3. The method for determining the feature library according to claim 1 or 2, characterized in that, The method further includes: If an unknown attack sample of an unknown threat is obtained, determine the third sample feature corresponding to the unknown attack sample; The third sample features are mapped to the target threat framework using a preset mapping algorithm to obtain the mapped third threat technical features. Determine the degree of matching between the third threat technical feature and the threat technical features in the threat technical feature database; If the matching degree is greater than the preset matching degree, threat analysis is performed on the unknown attack sample.

4. The method for determining the feature library according to claim 3, characterized in that, If the matching degree is greater than a preset matching degree, after performing threat analysis on the unknown attack sample, the method further includes: The unknown attack sample is sent to the target object for sample analysis; Obtain the analysis results determined by the target object for the unknown attack sample; The analysis results are parsed to determine whether the unknown attack samples should be used to supplement the threat signature database.

5. The method for determining the feature library according to claim 4, characterized in that, The analysis results are parsed to determine whether the unknown attack samples should be used to supplement the threat signature database, including: If the analysis results indicate that the unknown attack sample is an advanced persistent threat sample, then the unknown attack sample is used to supplement the threat signature database. If the analysis results indicate that the unknown attack sample is not an advanced persistent threat sample, it is determined that the unknown attack sample will not be used to supplement the threat signature database.

6. The method for determining the feature library according to claim 5, characterized in that, Determining to supplement the threat signature database with the unknown attack samples includes: Determine the target feature vector corresponding to the unknown attack sample, wherein the target feature vector includes: the third sample feature and the third threat technology feature corresponding to the unknown attack sample; The target feature vector is used to supplement the existing feature vectors to supplement the threat technology feature database, wherein the existing feature vectors are used to indicate the vectors existing in the threat technology feature database.

7. A device for determining a feature library, characterized in that, include: The extraction module is used to determine the target threat framework from a preset threat framework library according to the detection requirements of the target object, and extract the first sample features from the first attack sample according to the target threat framework, wherein the first sample features include: static features and / or dynamic features; The mapping module is used to perform a frame technology mapping between the first sample features and the target threat framework using a preset mapping algorithm to obtain the mapped first threat technology features. The feature module is used to form a threat technology feature library corresponding to the first attack sample based on the first threat technology features and the first sample features; The name of the threat signature database shall at least include the organization identifier corresponding to the first attack sample; the first attack sample is an advanced persistent threat sample of a known threat. The extraction module is further configured to determine the target category parameters of the threat framework to be searched based on the detection requirements. The target category parameters are used to indicate the analysis category and mapping category to be performed on the target object. Determine the similarity between the frame category parameter corresponding to each threat frame in the preset threat framework library and the target category parameter; The threat framework corresponding to the frame category parameter with the highest similarity to the target category parameter is determined as the target threat framework to be used; wherein, the preset threat framework library is a framework library that initiates framework updates within a preset time period, and the newly added updated framework is written to the current preset threat framework library through the framework adjustment instruction issued by the target object.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein the program, when executed, performs the method described in any one of claims 1 to 6.

9. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the method described in any one of claims 1 to 6 through the computer program.

Citation Information

Patent Citations

  • Risk assessment method and device, computer system and medium

    CN111859400A

  • Network attack analysis method and device, electronic equipment and storage medium

    CN114205128A