A method and system for constructing an uncertainty attack resource graph
By constructing an uncertain attack resource graph, the problem of missing information in deterministic graphs is solved, improving the effectiveness of gang attack analysis and the accuracy of APT organization attribution.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT
- Filing Date
- 2022-12-16
- Publication Date
- 2026-04-10
AI Technical Summary
In existing technologies, attack resource graphs built based on deterministic relationships are prone to missing attack information, making it difficult to effectively analyze complex group attack behaviors, especially the attribution relationships of APT organizations are difficult to express accurately.
We adopt a method for constructing an uncertainty-based attack resource graph. By acquiring the raw data of gang attack behavior, we use a pre-set confidence algorithm to process the correlation data, generate confidence information, and construct an uncertainty graph. This method retains more effective information and improves the expressive power and information content of the graph.
It improves the effectiveness of group attack analysis, enabling more accurate identification and tracking of dynamically changing attack resources, and enhances the ability to analyze the attribution relationships of APT organizations.
Smart Images

Figure CN116032576B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a construction method and system of an uncertainty attack resource graph. BACKGROUND
[0002] At present, with the deepening and evolution of the confrontation between network attacks and defenses, network attack behaviors are developing towards distribution and scale. In real network attacks, attackers often use the gang way to attack. Gangs are usually divided into two categories. One is to use the same attack method, such as the same attack method, vulnerability exploitation method, etc. to attack different or the same asset purposes. This attack gang has the same attack tactics, even uses the same script and vulnerability, and the IP is in the same network segment. These are relatively easy to identify. The other is a gang with clear division of labor. Different members are responsible for different attack stages in each stage of the attack. A common feature of gang attacks is that they are more covert. The attack resources they master are often changing. In the process of network security gang analysis, especially in the process of modeling and analyzing complex attacks and high-level threat attacks, knowledge graph or attack graph is usually used for analysis. Attack resources with correlation are analyzed by graph correlation aggregation, so as to analyze their gang attack behavior. Attack resource graph can intuitively express multi-dimensional data and behavior, and has good application effect on security analysis.
[0003] In the prior art, knowledge graph or attack graph is generally constructed based on deterministic relationship or by setting a threshold to delete the relationship below the threshold, which may cause the loss of attack information, thereby affecting the effectiveness of gang attack analysis. On the other hand, the relationship between some attack resources is difficult to be expressed by deterministic means. For example, the attribution relationship of APT organization often needs a complex analysis process to draw a conclusion. The attribution between attack resources is difficult, which further reduces the effectiveness of gang attack analysis. SUMMARY
[0004] The purpose of the embodiments of the present application is to provide a construction method and system of an uncertainty attack resource graph, an electronic device and a computer readable storage medium, which can realize the technical effect of improving the effectiveness of gang attack analysis.
[0005] In a first aspect, the embodiments of the present application provide a construction method of an uncertainty attack resource graph, comprising:
[0006] Obtaining original data of gang attack behavior;
[0007] Performing data extraction of the gang attack according to the original data to obtain correlation data between attack resource entities;
[0008] According to a preset confidence algorithm, the association relationship data is processed to obtain confidence information;
[0009] According to the association relationship data and the confidence information, an uncertainty graph is constructed.
[0010] In the implementation process, the method for constructing an uncertainty attack resource graph is based on original data of gang attack behaviors, obtains association relationship data between attack resource entities, processes the association relationship data according to a preset confidence algorithm to obtain confidence information, and constructs an uncertainty graph based on the confidence information and the association relationship data. Thus, the attack resource graph is constructed by introducing uncertainty, and the problem of missing attack information caused by constructing the attack resource graph based on a deterministic relationship or by setting a threshold is solved. Therefore, the method for constructing an uncertainty attack resource graph can retain as much effective information as possible without affecting the relationship between attack resources, improves the expression ability and information quantity of the attack resource graph, and achieves the technical effect of improving the effectiveness of gang attack analysis.
[0011] Further, the step of obtaining original data of gang attack behaviors includes:
[0012] One or more of alarm event data, knowledge data, and threat intelligence data is obtained to generate the original data.
[0013] In the implementation process, attack resource entities are extracted and relationship extraction is performed from various types of original data, such as alarm event data, knowledge data, and threat intelligence data.
[0014] Further, the preset confidence algorithm includes a first confidence algorithm, a second confidence algorithm, and a third confidence algorithm, and the step of processing the association relationship data according to the preset confidence algorithm to obtain confidence information includes:
[0015] A plurality of attack resource entity data of the original data is obtained;
[0016] The plurality of attack resource entity data is matched two by two, and the two matched attack resource entity data is processed as follows:
[0017] The two attack resource entity data is denoted as first attack resource entity data and second attack resource entity data;
[0018] When the original data is alarm event data, the first attack resource entity data and the second attack resource entity data are processed according to the first confidence algorithm to generate first confidence information;
[0019] The original data is knowledge data, and the first attack resource entity data and the second attack resource entity data are processed according to the second confidence algorithm to generate second confidence information.
[0020] The original data is threat intelligence data, and the first attack resource entity data and the second attack resource entity data are processed according to the third confidence algorithm to generate third confidence information.
[0021] The confidence information is generated according to one or more of the first confidence information, the second confidence information, and the third confidence information.
[0022] In the implementation process, when extracting the confidence relationship between attack resource entities, different data types need to be extracted and the confidence of the extracted relationship needs to be calculated, so as to improve the expression ability and information quantity of the attack resource graph.
[0023] Further, the original data is alarm event data, and the first attack resource entity data and the second attack resource entity data are processed according to the first confidence algorithm to generate first confidence information, including:
[0024] According to the first attack resource entity data, a first set of data of key elements is obtained, and according to the second attack resource entity data, a second set of data of key elements is obtained.
[0025] The coincidence degree between the first set of data and the second set of data is calculated to obtain first confidence information.
[0026] In the implementation process, if the original data is alarm event data, the set data of key elements can be obtained according to the attack resource entity data, and the first confidence information can be obtained according to the coincidence degree of the set data. The alarm event data takes distributed denial of service (ddos, Distributed denial of service attack) attack data as an example. In order to extract the association relationship of each control end IP (corresponding to attack resource entity data) in ddos attack data, the control end IP, chicken IP (corresponding to key elements) and time fields involved in ddos attack data are extracted, the set of chicken IP used by the first control end IP (first attack resource entity data) and the second control end IP (second attack resource entity data) within a time range is calculated, and the association analysis and confidence between the control end IP are obtained according to the coincidence degree of the set.
[0027] Further, the original data is knowledge data, and the step of generating second confidence information according to the first attack resource entity data and the second attack resource entity data based on the second confidence algorithm comprises:
[0028] generating a first correlation confidence according to the registration time of the first attack resource entity data and the registration time of the second attack resource entity data;
[0029] generating a second correlation confidence according to the registration entity information of the first attack resource entity data and the registration entity information of the second attack resource entity data;
[0030] obtaining second confidence information according to the first correlation confidence and the second correlation confidence.
[0031] In the above implementation process, if the original data is knowledge data, the second confidence information can be obtained according to the registration time and the registration entity information of the attack resource entity data; taking whois data (whois data is a database of domain name registration information) as an example, when an attacker uses a malicious domain name to attack, the attacker needs to register a large number of domain names to carry out attack activities, the relationship of the registered domain names and the correlation confidence thereof are extracted, the registration time and the registration entity information of the domain names are extracted, and the correlation analysis and the confidence thereof between the domain names are obtained according to the registration time and the registration entity information.
[0032] Further, the original data is threat intelligence data, and the step of generating third confidence information according to the first attack resource entity data and the second attack resource entity data based on the third confidence algorithm comprises:
[0033] obtaining first attack code data according to the first attack resource entity data and first attack code data of key elements according to the second attack resource entity data;
[0034] calculating the similarity of the calling sequence of the first attack code data and the calling sequence of the second attack code data to generate third confidence information.
[0035] In the above implementation process, if the original data is threat intelligence data, the third confidence information can be obtained according to the attack code data of the attack resource entity data; taking a sample file obtained by threat intelligence data as an example, the attack code in the sample file can be extracted to calculate the correlation analysis and the confidence thereof existing between the sample files.
[0036] Further, after the step of constructing an uncertainty graph according to the correlation relationship data and the confidence information, the method further comprises:
[0037] The certainty graph of the association relationship data is compared and analyzed with the uncertainty graph to obtain a graph comparison result.
[0038] In a second aspect, the embodiments of the present application provide a construction system based on an uncertainty attack resource graph, comprising:
[0039] An original data module is configured to acquire original data of gang attack behavior.
[0040] An association relationship module is configured to perform data extraction of the gang attack according to the original data to obtain association relationship data between attack resource entities.
[0041] A confidence module is configured to process the association relationship data according to a preset confidence algorithm to obtain confidence information.
[0042] An uncertainty graph module is configured to construct an uncertainty graph according to the association relationship data and the confidence information.
[0043] Further, the original data module is specifically configured to acquire one or more of alarm event data, knowledge data, and threat intelligence data to generate the original data.
[0044] Further, the confidence module is specifically configured to:
[0045] Acquire a plurality of attack resource entity data of the original data.
[0046] Match the plurality of attack resource entity data two by two, and perform the following processing on the two matched attack resource entity data:
[0047] The two attack resource entity data are denoted as first attack resource entity data and second attack resource entity data.
[0048] When the original data is alarm event data, the first attack resource entity data and the second attack resource entity data are processed according to the first confidence algorithm to generate first confidence information.
[0049] When the original data is knowledge data, the first attack resource entity data and the second attack resource entity data are processed according to the second confidence algorithm to generate second confidence information.
[0050] When the original data is threat intelligence data, the first attack resource entity data and the second attack resource entity data are processed according to the third confidence algorithm to generate third confidence information.
[0051] The confidence information is generated according to one or more of the first confidence information, the second confidence information, and the third confidence information.
[0052] Further, the confidence module is further configured to: obtain first set data of key elements according to the first attack resource entity data, and obtain second set data of key elements according to the second attack resource entity data; and calculate coincidence degree between the first set data and the second set data to obtain first confidence information.
[0053] Further, the confidence module is further configured to: generate first association confidence according to registration time of the first attack resource entity data and registration time of the second attack resource entity data; generate second association confidence according to registration entity information of the first attack resource entity data and registration entity information of the second attack resource entity data; and obtain second confidence information according to the first association confidence and the second association confidence.
[0054] Further, the confidence module is further configured to: obtain first attack code data according to the first attack resource entity data, and obtain first attack code data of key elements according to the second attack resource entity data; and calculate similarity of calling sequences of the first attack code data and the second attack code data to generate third confidence information.
[0055] Further, the construction system based on the uncertainty attack resource graph further includes a graph comparison module configured to: compare and analyze the deterministic graph and the uncertainty graph of the association relationship data to obtain a graph comparison result.
[0056] In a third aspect, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory and capable of running on the processor, and the processor implements the steps of the method according to any one of the first aspect when executing the computer program.
[0057] In a fourth aspect, a computer readable storage medium is provided, and instructions are stored on the computer readable storage medium, and when the instructions run on a computer, the computer is caused to execute the method according to any one of the first aspect.
[0058] In a fifth aspect, a computer program product is provided, and when the computer program product runs on a computer, the computer is caused to execute the method according to any one of the first aspect.
[0059] Other features and advantages of the present application will be set forth in the following description, in part in terms of the descriptions of the application and in part will become apparent to those skilled in the art upon examination of the following or can be learned from the practice of the application. The features and advantages of the present application can be realized and attained by means of the instrumentalities and combinations particularly pointed out in the appended claims.
[0060] In order to make the above objectives, features and advantages of the present application more apparent, the following will specifically describe a preferred embodiment in combination with the accompanying drawings, and make a detailed description as follows. BRIEF DESCRIPTION OF DRAWINGS
[0061] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some of the embodiments of the present application, and therefore should not be considered as a limitation to the scope, and for those skilled in the art, other related drawings can also be obtained without paying creative labor on the basis of these drawings.
[0062] Figure 1 A flowchart of a construction method of an uncertainty attack resource graph provided by the embodiments of the present application;
[0063] Figure 2 A flowchart of another construction method of an uncertainty attack resource graph provided by the embodiments of the present application;
[0064] Figure 3 A schematic diagram of a deterministic graph and an uncertainty graph provided by the embodiments of the present application;
[0065] Figure 4 A structure block diagram of a construction system of an uncertainty attack resource graph provided by the embodiments of the present application;
[0066] Figure 5 A structure block diagram of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION
[0067] The technical solutions in the embodiments of the present application will be described below in combination with the drawings in the embodiments of the present application.
[0068] It should be noted that: similar reference numerals and letters represent similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings. Meanwhile, in the description of the present application, the terms “first”, “second” and the like are only used for distinguishing description, and cannot be understood as indicating or implying relative importance.
[0069] The embodiment of the application provides a construction method and system of an uncertainty attack resource graph, an electronic device and a computer readable storage medium, which can be applied to the analysis process of network gang attack; the construction method of the uncertainty attack resource graph is based on original data of gang attack behavior, obtains correlation relationship data between attack resource entities, processes the correlation relationship data according to a preset confidence algorithm to obtain confidence information, and constructs an uncertainty graph based on the confidence information and the correlation relationship data; thus, the attack resource graph is constructed by introducing uncertainty, and the problem that attack information is missing when the attack resource graph is constructed based on a deterministic relationship or by setting a threshold is solved; therefore, the construction method of the uncertainty attack resource graph can retain as much effective information as possible, and does not affect the relationship between attack resources, improves the expression ability and information quantity of the attack resource graph, and achieves the technical effect of improving the effectiveness of gang attack analysis.
[0070] Please refer to Figure 1 , Figure 1 A flowchart of a construction method of an uncertainty attack resource graph is provided for the embodiment of the application, and the construction method of the uncertainty attack resource graph comprises the following steps:
[0071] S100: Obtain original data of gang attack behavior.
[0072] Exemplarily, usually, the identification of gang attack behavior is based on attack logs or alarm event data (security event data) obtained in a period of time, network security entities (attack resource entities) and their attributes in the attack logs or the alarm event data are extracted, including an Internet Protocol (IP) address, a domain name, a port, a mailbox, a sample hash, a file name, a uniform resource locator (URL), etc. Through knowledge labeling and knowledge construction, the correlation relationship between attack resource entities is extracted, and then a relationship graph between attack resource entities is constructed, and subsequently, clustering, community discovery and other aspects are used for gang division.
[0073] Exemplarily, the formation process of the attack resource graph needs to extract the correlation relationship between attack resource entities (and attack resources), and attack resource entity categories in the network space can include: an IP address (such as an IP address of an attacker), a domain name (such as a phishing domain name, a C&C domain name, etc.), a mailbox, a URL (such as a malicious connection), an md5 (such as a md5 value of a sample file), etc.
[0074] The attack resource entity exists in various types of raw data (such as alarm event data, knowledge data and intelligence data), and needs to be extracted from various types of raw data. The traditional scheme is to determine the relationship between the attack resource entity based on the determined idea, or to filter the relationship greater than the threshold value by setting the threshold value, so as to obtain the deterministic attack resource graph;
[0075] The embodiment of the present application is based on the same type of raw data, but considers uncertainty and its calculation process in the extraction process.
[0076] S200: Extracting data of gang attack from raw data to obtain associated relationship data between attack resource entities.
[0077] S300: Processing the associated relationship data according to the pre-set confidence algorithm to obtain confidence information.
[0078] Exemplarily, the confidence reflects the confidence level or uncertainty of the relationship between one attack resource entity and another attack resource entity, which is mainly due to the fact that the attributes of the same attack resource entity are often changed; for example, an IP address controlled by an attacker points to a corresponding domain name, and after a period of time, the pointing relationship of the IP address may be invalid and be referenced by another attacker; or a sample file can only be given a possibility through some probability or confidence calculation due to its public tool attribute, and thus it is difficult to be divided into a specific attacker, so it is necessary to extract and calculate the confidence of the extracted relationship according to different data types when extracting the attack resource relationship.
[0079] S400: Constructing an uncertainty graph according to the associated relationship data and the confidence information.
[0080] Exemplarily, by introducing the confidence of the associated relationship between each attack resource entity, the construction breadth of the attack resource graph can be improved, thereby improving the effectiveness of gang analysis.
[0081] In some embodiments, the construction method of the uncertainty attack resource graph is based on the raw data of gang attack behavior, obtains the associated relationship data between attack resource entities, processes the associated relationship data according to the pre-set confidence algorithm to obtain confidence information, and constructs an uncertainty graph based on the confidence information and the associated relationship data; thereby, the attack resource graph is constructed by introducing uncertainty, solving the problem of missing attack information when the attack resource graph is constructed based on deterministic relationship or by setting a threshold value; therefore, the construction method of the uncertainty attack resource graph can retain as much effective information as possible, and does not affect the relationship between attack resources, improves the expression ability and information amount of the attack resource graph, and achieves the technical effect of improving the effectiveness of gang attack analysis.
[0082] Please attend Figure 2 , Figure 2 Another flowchart of the method for constructing an uncertainty attack resource graph provided by the embodiments of the present application is shown in FIG. 3.
[0083] Exemplarily, S100: obtaining original data of gang attack behavior, including:
[0084] S110: obtaining one or more of alarm event data, knowledge data, and threat intelligence data to generate original data.
[0085] Exemplarily, attack resource entity extraction and relationship extraction are performed from various original data, such as alarm event data, knowledge data, and threat intelligence data.
[0086] Exemplarily, the pre-set confidence algorithm includes a first confidence algorithm, a second confidence algorithm, and a third confidence algorithm, and S300: processing the association relationship data according to the pre-set confidence algorithm to obtain confidence information, including:
[0087] S310: obtaining a plurality of attack resource entity data of the original data;
[0088] S320: matching the plurality of attack resource entity data two by two, and processing the two matched attack resource entity data as follows:
[0089] S321: the two attack resource entity data are denoted as a first attack resource entity data and a second attack resource entity data;
[0090] S322: the original data is alarm event data, the first attack resource entity data and the second attack resource entity data are processed according to the first confidence algorithm to generate first confidence information;
[0091] S323: the original data is knowledge data, the first attack resource entity data and the second attack resource entity data are processed according to the second confidence algorithm to generate second confidence information;
[0092] S324: the original data is threat intelligence data, the first attack resource entity data and the second attack resource entity data are processed according to the third confidence algorithm to generate third confidence information;
[0093] S330: generating confidence information according to one or more of the first confidence information, the second confidence information, and the third confidence information.
[0094] Exemplarily, when the confidence relationship between the attack resource entities is extracted, different data types need to be extracted and the confidence of the extracted relationship needs to be calculated, so as to improve the expression ability and information quantity of the attack resource graph.
[0095] Optionally, the two attack resource entity data matched in the embodiment S320 of the application are original data of different types, and the confidence of the two attack resource entity data is not processed.
[0096] Exemplarily, S322: the original data is alarm event data, the first attack resource entity data and the second attack resource entity data are processed according to the first confidence algorithm to generate the first confidence information, and the step includes:
[0097] According to the first attack resource entity data, the first set of key element data is obtained, and according to the second attack resource entity data, the second set of key element data is obtained.
[0098] The coincidence degree between the first set of data and the second set of data is calculated to obtain the first confidence information.
[0099] Exemplarily, if the original data is alarm event data, the set of key element data can be obtained according to the attack resource entity data, and the first confidence information can be obtained according to the coincidence degree of the set of data; the alarm event data takes distributed denial of service (ddos) attack data as an example, in order to extract the association relationship of each control end IP (corresponding to attack resource entity data) in the ddos attack data, the control end IP, chicken IP (corresponding to key element) and time involved in the ddos attack data are extracted, the set of chicken IP used by the first control end IP (first attack resource entity data) and the second control end IP (second attack resource entity data) in the time range is calculated, and the association analysis and the confidence between the control end IPs are obtained according to the coincidence degree of the set.
[0100] Exemplarily, S323: the original data is knowledge data, the first attack resource entity data and the second attack resource entity data are processed according to the second confidence algorithm to generate the second confidence information, and the step includes:
[0101] According to the registration time of the first attack resource entity data and the registration time of the second attack resource entity data, the first association confidence is generated.
[0102] According to the registration entity information of the first attack resource entity data and the registration entity information of the second attack resource entity data, the second association confidence is generated.
[0103] The second confidence information is obtained according to the first correlation confidence and the second correlation confidence.
[0104] Exemplarily, if the original data is knowledge data, the second confidence information can be obtained according to the registration time and the registration entity information of the attack resource entity data; taking the knowledge data as whois data (whois data is a database of domain name registration information) as an example, when an attacker uses a malicious domain name to attack, the attacker needs to register a large number of domain names to carry out attack activities, the relationship of the registered domain names and the correlation confidence associated therewith are extracted, the registration time and the registration entity information of the domain names are extracted, and the correlation analysis between the domain names and the confidence thereof are obtained according to the registration time and the registration entity information.
[0105] Optionally, the registration entity information includes general information such as a username, an email address, and a mobile phone number.
[0106] Exemplarily, S323: if the original data is threat intelligence data, the first attack resource entity data and the second attack resource entity data are processed according to a third confidence algorithm, and a step of generating third confidence information includes:
[0107] The first attack code data is obtained according to the first attack resource entity data, and the first attack code data of the key element is obtained according to the second attack resource entity data.
[0108] The similarity of the calling sequence of the first attack code data and the calling sequence of the second attack code data is calculated, and the third confidence information is generated.
[0109] Exemplarily, if the original data is threat intelligence data, the third confidence information can be obtained according to the attack code data of the attack resource entity data; taking a sample file obtained by the threat intelligence data as an example, the attack code in the sample file can be extracted to calculate the correlation analysis and the confidence thereof existing between the sample files.
[0110] Exemplarily, after the step S400 of constructing the uncertainty graph according to the correlation relationship data and the confidence information, the method further includes:
[0111] S500: comparing and analyzing the certainty graph and the uncertainty graph of the correlation relationship data to obtain a graph comparison result.
[0112] In some implementation scenarios, in combination with Figures 1-2 The embodiment of the present application proposes a construction method of an uncertainty attack resource graph, which can retain as much effective information as possible and does not affect the relationship between attack resources, effectively improving the expression ability and information quantity of the graph; please refer to Figure 3 , Figure 3 The schematic diagrams of the certainty graph and the uncertainty graph provided by the embodiment of the present application; in Figure 3In the figure, the left side is a deterministic attack resource graph constructed in a traditional way, and the right side is an uncertainty attack resource graph constructed by introducing uncertainty. In the graph, the points are extracted attack resource entities, and the edges are the relationships between the extracted attack resource entities. Meanwhile, the edges of the uncertainty attack resource graph are edges with uncertainty metrics, which correspond to the confidence calculated by the above method.
[0113] Exemplarily, in combination with Figures 1-3 The embodiment of the present application proposes a construction method based on an uncertainty attack resource graph, and the specific process steps are exemplified as follows:
[0114] (1) Obtain the original data, and extract attack resource entities and relationships:
[0115] (2) Extract each type of original data, and consider the confidence of the extracted relationship:
[0116] The confidence reflects the confidence level or uncertainty of the relationship between one attack resource entity and another attack resource. This is mainly because the same attack resource attribute often changes, such as an IP controlled by an attacker pointing to a corresponding domain name, which is invalid after a period of time and is referenced by another attacker. Or a sample file is difficult to divide into a specific attacker due to its public tool attribute, and only some probability or confidence calculation can be used to give its possibility. Therefore, when extracting attack resource relationships, different data types need to be extracted and the confidence of the extracted relationship needs to be calculated, as follows:
[0117] 2.1) Attack resource relationship extraction of alarm data:
[0118] Taking ddos attack data as an example, in order to extract the association relationship of each control end IP of ddos attack, the control end IP, bot IP and time fields involved in ddos alarm data are extracted, and the set of bots used by control end IP1 and control end IP2 in the time range is calculated, respectively denoted as:
[0119] bot_ip_list1 and bot_ip_list2;
[0120] The elements in the set are the corresponding bot IPs, and the coincidence degree of the two sets, that is, the proportion of the number of common bots, is calculated:
[0121]
[0122] Let s1 be the confidence of the association relationship between control end IP1 and control end IP2.
[0123] 2.2) Attack resource relationship extraction of knowledge data:
[0124] Taking whois data (whois data is a database of domain name registration information) as an example, when an attacker uses a malicious domain name to attack, a large number of domain names need to be registered for attack activities, and the relationship of the registered domain names and the associated confidence are extracted, and the following information is extracted:
[0125] 2.21) Extract the registration time of the domain name, and calculate the association confidence between the two domain names according to the registration time;
[0126] 2.22) Extract attention information, including user name, email, mobile phone number, etc. Guangxi information, and calculate the association confidence between the two domain names according to the similarity;
[0127] 2.23) The above two results are weighted and aggregated to obtain the existence of an association relationship between the two malicious domain names and the overall confidence, denoted as s2;
[0128] 2.3) Attack resource relationship extraction of threat intelligence data:
[0129] Taking the sample file obtained from the threat intelligence data as an example, the attack code in the sample file is extracted to calculate the association analysis and its confidence between the sample files;
[0130] The code includes common delivery payload types in attacks, including: hta, exe, sfx exe, rtf, iso, js, mht, lnk, doc, rar, chm, etc. By analyzing and extracting the code, the code for stealing behavior, special processing API call processing code, loading payload method code, c2 communication behavior code, compression, polymorphism, and shell processing code are extracted; The API interface of the function call in the code is extracted, and a call sequence is formed according to the calling relationship, and the similarity between the corresponding codes in the two samples is calculated using the sequence similarity calculation method, denoted as s3;
[0131] (3) Construct an uncertain graph based on the extracted relationship and its confidence:
[0132] According to the attack resource relationship extracted above, including but not limited to s1, s2, s3, etc., an uncertain attack graph is constructed. Among them, the points in the graph are the extracted attack resource entities, and the edges are the extracted attack resource relationships. At the same time, this edge is a variable with uncertainty measurement, and the confidence calculated by the above method corresponds;
[0133] (4) Compare and analyze the constructed uncertain graph with the deterministic graph as a reference, evaluate the effect of the constructed graph, and output the results;
[0134] In the comparative analysis of uncertain and deterministic graphs, without considering the confidence level (uncertainty) relationship, each edge in the resulting deterministic graph is a definite relationship. For example, based on the sample similarity relationship extracted from threat intelligence data, the deterministic graph filters out relationships where s3 < δ by setting a similarity threshold such as δ = 0.7, and retains attack resource relationships where s3 ≥ δ. In this way, the constructed graph will only retain edges that exceed the threshold. If a sample is used by a certain gang or APT organization, then the sample is uniquely associated with a certain APT organization or gang.
[0135] like Figure 3 As shown, in the subgraph of the deterministic graph on the left, S2-S4, in actual calculation, because its confidence level is 0.8, which is greater than the set threshold of 0.7, only this edge is retained in the subgraph on the left. The subgraph of the uncertain graph on the right shows that S2-S3 has an extra edge with a confidence level of 0.2, but the subgraph of the uncertain graph on the right also retains the information of S3. Therefore, the subgraph of the uncertain graph on the right introduces uncertainty, thereby enhancing the amount of information expressed in the graph.
[0136] In some implementation scenarios, this application can be applied to situational awareness projects such as big data security analysis products or regulatory agencies, involving gang analysis, advanced threat analysis, or threat hunting operations; the specific process according to the method described in detail in the embodiments of this application is as follows:
[0137] Step 1: Continuously acquire security incident data, knowledge data, or threat intelligence data;
[0138] Step 2: Extract attack resource entities and relationships using the method described above, and calculate the confidence level of the relationships;
[0139] Step 3: Construct an uncertain attack resource graph using the method described in this application;
[0140] Step 4: Conduct an uncertain comparative analysis, using the deterministic spectrum as a benchmark, and analyze the changes in its spectrum;
[0141] Step 5: Output the results and display them on the interface.
[0142] Exemplarily, in recent years, new attack means emerge in an endless stream, and advanced attack forms begin to change from single combat to organized and planned gang attack. These attacks are concealed and disguised through technical means to evade conventional detection means, especially for attacks on critical infrastructure or important industry data, which are very harmful. For an attack gang, the attack resources used by the attack gang often change dynamically, such as the control end of a DDOS attack, C2 attack resources, and the like. With the use of newly registered malicious domain names or newly controlled honeypots, the attack resources are different in different observation windows. If long-term tracking and analysis of an attack gang or organization is to be realized, an attack resource graph is often constructed, the attack resources belonging to an attack gang are associated, and long-period tracking is performed.
[0143] However, in the process of constructing the attack resource graph, uncertainty is inevitably present, mainly due to noise generated in the process of constructing the graph or the relationship between part of the attack resources being difficult to express through a deterministic manner. Such processing of retaining only the deterministic relationship will cause the loss of attack information, thereby affecting the effectiveness of the final gang analysis.
[0144] To sum up, the construction method of the attack resource graph based on uncertainty provided by the embodiments of the present application has at least the following beneficial effects:
[0145] (1) The attack resource graph constructed at present is usually based on deterministic relationship or constructed by deleting the relationship below a threshold value, which will cause the loss of attack information, thereby affecting the effectiveness of gang analysis. The present application solves this problem by introducing uncertainty to construct the attack resource graph.
[0146] (2) The relationship of some attack resources is difficult to express through a deterministic manner, such as the attribution relationship of an APT organization, which often needs a complex analysis process to draw a conclusion. The present application solves the problem of the attribution relationship between attack resources by introducing uncertainty.
[0147] Please refer to Figure 4 , Figure 4 The structure block diagram of the construction system of the attack resource graph based on uncertainty provided by the embodiments of the present application, which comprises:
[0148] The original data module 100 is used to acquire original data of gang attack behavior.
[0149] The association relationship module 200 is configured to perform data extraction of a gang attack according to the original data, and obtain association relationship data between attack resource entities.
[0150] The confidence module 300 is configured to process the association relationship data according to a preset confidence algorithm, and obtain confidence information.
[0151] The uncertainty graph module 400 is configured to construct an uncertainty graph according to the association relationship data and the confidence information.
[0152] The original data module 100 is configured to obtain one or more of alarm event data, knowledge data, and threat intelligence data, and generate original data.
[0153] The confidence module 300 is configured to:
[0154] obtain a plurality of attack resource entity data of the original data;
[0155] perform pairwise matching according to the plurality of attack resource entity data, and perform the following processing on the two matched attack resource entity data:
[0156] The two attack resource entity data are denoted as first attack resource entity data and second attack resource entity data.
[0157] When the original data is alarm event data, the first attack resource entity data and the second attack resource entity data are processed according to a first confidence algorithm to generate first confidence information.
[0158] When the original data is knowledge data, the first attack resource entity data and the second attack resource entity data are processed according to a second confidence algorithm to generate second confidence information.
[0159] When the original data is threat intelligence data, the first attack resource entity data and the second attack resource entity data are processed according to a third confidence algorithm to generate third confidence information.
[0160] The confidence information is generated according to one or more of the first confidence information, the second confidence information, and the third confidence information.
[0161] The confidence module 300 is further configured to: obtain first set data of key elements according to the first attack resource entity data, and obtain second set data of key elements according to the second attack resource entity data; calculate the coincidence degree between the first set data and the second set data to obtain the first confidence information.
[0162] Exemplarily, the confidence module 300 is further configured to: generate a first association confidence according to the registration time of the first attack resource entity data and the registration time of the second attack resource entity data; generate a second association confidence according to the registration entity information of the first attack resource entity data and the registration entity information of the second attack resource entity data; and obtain the second confidence information according to the first association confidence and the second association confidence.
[0163] Exemplarily, the confidence module 300 is further configured to: obtain the first attack code data according to the first attack resource entity data, and obtain the first attack code data of the key element according to the second attack resource entity data; calculate the similarity of the calling sequence of the first attack code data and the calling sequence of the second attack code data, and generate the third confidence information.
[0164] Exemplarily, the construction system of the uncertainty attack resource graph further comprises a graph comparison module configured to: compare and analyze the certainty graph and the uncertainty graph of the association relationship data, and obtain a graph comparison result.
[0165] It should be noted that the construction system of the uncertainty attack resource graph provided by the embodiments of the present application is not limited to the above-mentioned attack resource entity data, and can also be applied to other attack resource entity data. Figures 1-3 The method embodiments corresponding to the method embodiments shown in the above-mentioned construction system of the uncertainty attack resource graph are not repeated here.
[0166] The present application also provides an electronic device, please refer to Figure 5 , Figure 5 The structural block diagram of an electronic device provided by the embodiments of the present application. The electronic device can include a processor 510, a communication interface 520, a memory 530 and at least one communication bus 540. Wherein, the communication bus 540 is used to realize the direct connection communication of these components. Wherein, the communication interface 520 of the electronic device in the embodiments of the present application is used for signaling or data communication with other node devices. The processor 510 can be an integrated circuit chip with signal processing capability.
[0167] The processor 510 described above can be a general-purpose processor, including a central processing unit (CPU, Central Processing Unit), a network processor (NP, Network Processor) and the like; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a ready programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can realize or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor 510 can also be any conventional processor or the like.
[0168] The memory 530 can be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc. The memory 530 stores computer-readable instructions, which, when executed by the processor 510, enable the electronic device to perform the above-described Figures 1-3 The method embodiments relate to each step.
[0169] Optionally, the electronic device can further include a storage controller, an input / output unit.
[0170] The memory 530, the storage controller, the processor 510, the peripheral interface, and the input / output unit are electrically connected to each other directly or indirectly to achieve data transmission or interaction. For example, these elements can be electrically connected to each other through one or more communication buses 540. The processor 510 is configured to execute executable modules stored in the memory 530, such as software function modules or computer programs included in the electronic device.
[0171] The input / output unit is configured to provide a user with a creation task and create an optional time period or a preset execution time for the task to achieve user interaction with a server. The input / output unit can be, but is not limited to, a mouse, a keyboard, and the like.
[0172] It can be understood that Figure 5 The structure shown is only schematic, and the electronic device can include more or fewer components than those shown in the figures, or have a different configuration from that shown in the figures. Figure 5 The components shown in the figures can be implemented in hardware, software, or a combination thereof. Figure 5 The components shown in the figures can be implemented in hardware, software, or a combination thereof. Figure 5 The components shown in the figures can be implemented in hardware, software, or a combination thereof.
[0173] The embodiments of the present application also provide a storage medium, which stores instructions. When the instructions are run on a computer, the computer program is executed by a processor to implement the method of the method embodiments. To avoid repetition, details are not described here.
[0174] The present application also provides a computer program product, which, when run on a computer, causes the computer to execute the method of the method embodiments.
[0175] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can also be implemented by other means. The apparatus embodiments described above are only illustrative, for example, the flowcharts and block diagrams in the drawings show the possible implementation architecture, function and operation of the apparatus, method and computer program product according to the embodiments of the present application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment or a part of code, which contains one or more executable instructions for implementing the specified logic function. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order from that shown in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0176] In addition, the functional modules in the embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0177] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0178] The above merely provides an example of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, and thus, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.
[0179] The above merely provides an example of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, and thus, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.
[0180] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one from another entity or action without necessarily requiring or implying any actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.
Claims
1. A method for constructing a resource graph based on uncertain attack, characterized in that, include: Obtain raw data on the group's attack behavior; Based on the original data, data extraction of the gang attack is performed to obtain the correlation data between the attack resource entities; The association data is processed according to a pre-set confidence algorithm to obtain confidence information; An uncertainty map is constructed based on the correlation data and the confidence information; The steps for obtaining raw data on gang attack behavior include: Acquire alarm event data, knowledge data, and threat intelligence data to generate the raw data; The pre-set confidence algorithm includes a first confidence algorithm, a second confidence algorithm, and a third confidence algorithm. The step of processing the association data according to the pre-set confidence algorithm to obtain confidence information includes: Obtain multiple attack resource entity data from the original data; Based on the multiple attack resource entity data, perform pairwise matching, and then process the two matched attack resource entity data as follows: The two attack resource entity data are denoted as the first attack resource entity data and the second attack resource entity data. The original data is alarm event data. The first attack resource entity data and the second attack resource entity data are processed according to the first confidence algorithm to generate the first confidence information. The original data is knowledge data. The first attack resource entity data and the second attack resource entity data are processed according to the second confidence algorithm to generate second confidence information. The original data is threat intelligence data. The first attack resource entity data and the second attack resource entity data are processed according to the third confidence algorithm to generate third confidence information. The confidence information is generated based on the first confidence information, the second confidence information, and the third confidence information.
2. The method for constructing a resource graph based on uncertainty attack according to claim 1, characterized in that, The original data is alarm event data. The step of processing the first attack resource entity data and the second attack resource entity data according to the first confidence algorithm to generate the first confidence information includes: Based on the first attack resource entity data, a first set of key element data is obtained; based on the second attack resource entity data, a second set of key element data is obtained. Calculate the overlap between the first set of data and the second set of data to obtain the first confidence information.
3. The method for constructing a resource graph based on uncertainty attack according to claim 1, characterized in that, The original data is knowledge data. The step of processing the first attack resource entity data and the second attack resource entity data according to the second confidence algorithm to generate second confidence information includes: A first association confidence level is generated based on the registration time of the first attack resource entity data and the registration time of the second attack resource entity data. A second association confidence level is generated based on the registration entity information of the first attack resource entity data and the registration entity information of the second attack resource entity data. The second confidence information is obtained based on the first association confidence and the second association confidence.
4. The method for constructing a resource graph based on uncertainty attack according to claim 1, characterized in that, The original data is threat intelligence data. The step of processing the first attack resource entity data and the second attack resource entity data according to the third confidence algorithm to generate third confidence information includes: First attack code data is obtained based on the first attack resource entity data, and first attack code data of key elements is obtained based on the second attack resource entity data. Calculate the similarity between the call sequence of the first attack code data and the call sequence of the second attack code data to generate third confidence information.
5. The method for constructing a resource graph based on uncertainty attack according to claim 1, characterized in that, After the step of constructing an uncertainty map based on the correlation data and the confidence information, the method further includes: The deterministic and uncertain graphs of the correlation data are compared and analyzed to obtain graph comparison results.
6. A system for constructing a resource graph based on uncertain attack, characterized in that, include: The raw data module is used to obtain raw data on the group's attack behavior; The association module is used to extract data from the group attack based on the original data to obtain association data between attack resource entities; The confidence module is used to process the association data according to a preset confidence algorithm to obtain confidence information; An uncertainty mapping module is used to construct an uncertainty mapping based on the correlation data and the confidence information. The raw data module is specifically used to: acquire alarm event data, knowledge data, and threat intelligence data, and generate the raw data; The confidence module is specifically used for: Obtain multiple attack resource entity data from the original data; Based on the multiple attack resource entity data, perform pairwise matching, and then process the two matched attack resource entity data as follows: The two attack resource entity data are denoted as the first attack resource entity data and the second attack resource entity data. The original data is alarm event data. The first attack resource entity data and the second attack resource entity data are processed according to the first confidence algorithm to generate the first confidence information. The original data is knowledge data. The first attack resource entity data and the second attack resource entity data are processed according to the second confidence algorithm to generate second confidence information. The original data is threat intelligence data. The first attack resource entity data and the second attack resource entity data are processed according to the third confidence algorithm to generate third confidence information. The confidence information is generated based on the first confidence information, the second confidence information, and the third confidence information.
7. An electronic device, characterized in that, include: The memory, the processor, and the computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the steps of the method for constructing a resource graph based on an uncertainty attack as described in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the method for constructing a resource graph based on uncertainty attack as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Network attack path tracking method and device
CN113783896A
Web attack stage analysis method and system based on Web log
CN114915479A