A network attack path generation method, device, equipment and storage medium

By calculating the weights of network topology edges and the probability of node vulnerability attacks, constructing a Bayesian network, and dynamically updating the attack path, the problem of single evaluation of network-related events is solved, and the accurate calculation of attack paths and effective display of network security status are achieved.

CN116112251BActive Publication Date: 2025-09-05GCI SCI & TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310088989.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-06
Publication Date
2025-09-05
Estimated Expiration
2043-02-06

AI Technical Summary

Technical Problem

The existing technology has a single method for evaluating network-related events, which leads to inaccurate calculation of the attacker's attack path and inability to effectively display the network security situation.

Method used

By obtaining the number of edges of each node in the network topology, calculating the weight of the edge, combining the vulnerability hazard score of the node and the destructive computing vulnerability attack probability, an initial Bayesian network is constructed, the joint probability is optimized, and the Bayesian network is dynamically updated to generate the maximum probability attack path.

Benefits of technology

It improves the calculation accuracy of attack paths, effectively displays network security situation, can identify attackers' circuitous paths, and realize dynamic assessment of network security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116112251B_ABST
    Figure CN116112251B_ABST
Patent Text Reader

Abstract

The present invention discloses a network attack path generation method, apparatus, device, and storage medium. The method includes obtaining the number of edges of each node in the network topology and calculating the weight of each edge of the network topology based on the number of edges; calculating the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities, and destructiveness of each node; constructing an initial Bayesian network between the vulnerabilities based on the successful attack probabilities of pre-acquired historical vulnerabilities to obtain the initial joint probability of each attack behavior; optimizing the initial joint probability based on the weight of each edge and the vulnerability attack probability faced by each node to obtain the predicted joint probability of each attack behavior; updating the probability of the Bayesian network based on dynamic vulnerability data, and then updating the predicted joint probability of each attack behavior to obtain the maximum probability attack path. This method can accurately calculate the attacker's attack path and effectively display the network security situation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network attack path generation method, device, equipment and storage medium. Background Art

[0002] Currently, existing network attacks have evolved from single-step attacks to multi-step attacks. To achieve their goals, attackers typically compromise vulnerable hosts, gaining high-level privileges, and then launch attacks through multiple hops towards the target host. Therefore, many seemingly isolated security incidents often have connections. Many large-scale network security incidents are a combination of smaller incidents. This suggests that there is a correlation between single-step attacks. Many researchers believe that this correlation lies in the distance between nodes and the vulnerability probability of the vulnerability itself. These researchers often consider the local topology of the network. This local structure not only considers information about the node itself and its neighbors, but also information about the neighbors' neighborhoods. Because neighborhood information determines the proximity of a host (especially the target host) to surrounding hosts, it explains, to some extent, why attackers can achieve their goal of attacking the target host through multiple hops.

[0003] In the prior art, a static security event correlation method is adopted, and a data mining method is used to realize the causal correlation of vulnerabilities, thereby discovering the attacker's attack path. Vulnerability correlation generally executes the dependency between vulnerabilities and attacks based on the network topology relationship and vulnerability attributes and generates an attack path, which serves as the main basis for vulnerability correlation. However, as the complexity of vulnerability attacks increases, attackers often use roundabout tactics to attack some vulnerabilities with low complexity, and use a multi-step jump method to attack the target host. This static correlation method is no longer suitable for the existing network environment with changing attack behaviors. In addition, the existing method of treating network topology only considers the situations where nodes are directly connected and not directly connected, and does not consider the closeness of local node connections, thereby ignoring the attacker's use of roundabout attacks to attack the target host, resulting in inaccurate speculation on the attack path.

[0004] In summary, the existing technology has a single means of evaluating network-related events, which results in inaccurate calculation of the attacker's attack path and an inability to effectively display the network security situation. Summary of the Invention

[0005] The present invention provides a network attack path generation method, device, equipment and storage medium to solve the technical problem that the existing technology has a single means of evaluating network-related events, resulting in inaccurate calculation of the attacker's attack path and inability to effectively display the network security situation.

[0006] In a first aspect, in order to solve the above technical problems, the present invention provides a method for generating a network attack path, comprising:

[0007] Obtaining the number of edges of each node in the network topology, and calculating the weight of each edge of the network topology based on the number of edges;

[0008] Calculate the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities, and destructiveness of each node;

[0009] Based on the successful attack probabilities of historical vulnerabilities obtained in advance, an initial Bayesian network between the vulnerabilities is constructed to obtain the initial joint probability of each attack behavior;

[0010] Optimizing the initial joint probability according to the weight of each edge and the vulnerability attack probability faced by each node to obtain a predicted joint probability of each attack behavior;

[0011] The probability of the Bayesian network is updated according to the dynamic vulnerability data, and then the predicted joint probability of each attack behavior is updated to obtain the maximum probability attack path.

[0012] Preferably, calculating the weight of each edge of the network topology according to the number of edges includes:

[0013] Obtain the neighbor nodes of each node, and obtain the connection relationship between each node and other neighbor nodes according to the number of edges;

[0014] The weight of each edge is calculated based on the connection relationship.

[0015] Preferably, the calculation of the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities, and destructiveness of each node includes:

[0016]

[0017] Among them, P C represents the vulnerability attack probability faced by node C, f i represents the vulnerability hazard score of each node, n represents the number of vulnerabilities, D j represents destructiveness, and l represents the number of paths.

[0018] Preferably, the method of constructing an initial Bayesian network between vulnerabilities based on the previously acquired successful attack probabilities of historical vulnerabilities to obtain the initial joint probability of each attack behavior includes:

[0019]

[0020] in, Indicates that through the vulnerability Vulnerabilities and vulnerabilities The initial joint probability of an attack behavior.

[0021] Preferably, the initial joint probability is optimized according to the weight of each edge and the vulnerability attack probability faced by each node to obtain the predicted joint probability of each attack behavior, including:

[0022] Get the vulnerability Vulnerabilities and vulnerabilities Location in the network topology to identify vulnerabilities The order of nodes that occur;

[0023] Based on the node order, the weight of each edge, and the vulnerability attack probability faced by each node, the initial joint probability is updated to obtain a predicted joint probability of each attack behavior.

[0024] Preferably, the predicted joint probability includes:

[0025]

[0026] in, Indicates that through the vulnerability Vulnerabilities and vulnerabilities The predicted joint probability of an attack behavior.

[0027] In a second aspect, the present invention provides a network attack path generation device, comprising:

[0028] A weight calculation module is used to obtain the number of edges of each node in the network topology and calculate the weight of each edge of the network topology based on the number of edges;

[0029] The attack probability calculation module is used to calculate the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities and destructiveness of each node;

[0030] The initial probability module is used to build an initial Bayesian network between vulnerabilities based on the successful attack probabilities of historical vulnerabilities obtained in advance, and obtain the initial joint probability of each attack behavior;

[0031] A probability optimization module is used to optimize the initial joint probability according to the weight of each edge and the vulnerability attack probability faced by each node to obtain a predicted joint probability of each attack behavior;

[0032] The path generation module is used to update the probability of the Bayesian network according to the dynamic vulnerability data, and then update the predicted joint probability of each attack behavior to obtain the maximum probability attack path.

[0033] Preferably, the weight calculation module includes:

[0034] a relationship calculation unit, configured to obtain neighbor nodes of each node and obtain a connection relationship between each node and other neighbor nodes according to the number of edges;

[0035] The weight calculation unit is used to calculate the weight of each edge according to the connection relationship.

[0036] In a third aspect, the present invention also provides a terminal device comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the network attack path generation method described in any one of the above is implemented.

[0037] In a fourth aspect, the present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the network attack path generation methods described above.

[0038] Compared with the prior art, the present invention has the following beneficial effects:

[0039] The present invention provides a network attack path generation method, comprising: obtaining the number of edges of each node in a network topology, and calculating the weight of each edge of the network topology according to the number of edges; calculating the vulnerability attack probability faced by each node according to the vulnerability hazard score, the number of vulnerabilities and the destructiveness of each node; constructing an initial Bayesian network between the vulnerabilities based on the successful attack probabilities of historical vulnerabilities obtained in advance, and obtaining the initial joint probability of each attack behavior; updating the initial joint probability according to the weight of each edge and the vulnerability attack probability faced by each node, and obtaining the predicted joint probability of each attack behavior; and obtaining the maximum probability attack path of the network attack according to the predicted joint probability.

[0040] In this invention, the topological relationship of the entire network is constructed through the neighborhood structure method, and the close relationship between nodes is evaluated based on the neighborhood relationship of each node, thereby avoiding the traditional simple and crude evaluation method of direct connection and indirect connection. At the same time, considering the singleness of the evaluation method of network-related events and the unclear causal relationship of security events, this invention uses a Bayesian network to realize the dynamic adjustment of vulnerability causal relationship, thereby improving the accuracy of causal relationship, thereby achieving accurate calculation of the attacker's attack path and effectively displaying the network security situation. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1This is a flowchart of a method for generating a network attack path according to a first embodiment of the present invention;

[0042] Figure 2 This is a schematic diagram of a network topology provided by an embodiment of the present invention;

[0043] Figure 3 is a schematic diagram of an initial Bayesian network provided by an embodiment of the present invention;

[0044] Figure 4 This is a schematic diagram of the location of vulnerabilities in a network topology provided by an embodiment of the present invention;

[0045] Figure 5 is a probability diagram of the updated Bayesian network provided by an embodiment of the present invention;

[0046] Figure 6 It is a structural diagram of a network attack path generating device provided by the second embodiment of the present invention. DETAILED DESCRIPTION

[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0048] Reference Figure 1 The first embodiment of the present invention provides a method for generating a network attack path, comprising the following steps:

[0049] S11, obtaining the number of edges of each node in the network topology, and calculating the weight of each edge of the network topology according to the number of edges;

[0050] S12, calculates the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities and destructiveness of each node;

[0051] S13, based on the successful attack probabilities of historical vulnerabilities obtained in advance, construct an initial Bayesian network between the vulnerabilities to obtain the initial joint probability of each attack behavior;

[0052] S14, optimizing the initial joint probability according to the weight of each edge and the vulnerability attack probability faced by each node to obtain a predicted joint probability of each attack behavior;

[0053] S15, updates the probability of the Bayesian network according to the dynamic vulnerability data, and then updates the predicted joint probability of each attack behavior to obtain the maximum probability attack path.

[0054] It should be noted that when hackers conduct network attacks, they must not only identify the location of the target host, but also identify neighboring hosts that are closely related to the target host, as well as other hosts that are closely related to the neighboring hosts, so as to launch attacks through circuitous means and effectively conceal their true purpose. Therefore, in response to this approach, the present invention first adopts the concept of "neighborhood" structure to analyze the network topology, thereby more realistically reflecting the close relationships between nodes in the network topology. This avoids the traditional analysis of node relationships based on whether they are directly connected or not.

[0055] In step S11 , the number of edges of each node in the network topology is obtained, and the weight of each edge of the network topology is calculated according to the number of edges.

[0056] Calculating the weight of each edge of the network topology according to the number of edges includes:

[0057] Obtain the neighbor nodes of each node, and obtain the connection relationship between each node and other neighbor nodes according to the number of edges;

[0058] The weight of each edge is calculated based on the connection relationship.

[0059] For example, referring to Figure 2 , the neighbor nodes of node C are A, B, D, E. Assume that the neighbor set of node C is Γ(C)={A,B,D,E}, p CD represents the connection relationship between C and its neighbor node D, p CB and p DB Indicates the connection relationship between node C and node D and their common neighbor B. The present invention needs to consider common neighbors here, mainly because in order to observe that if a node has common neighbors with neighboring nodes, then for the attacker, its circuitous path has more options, so the direct connection will not be so important to the attacker, then to a certain extent, the importance (dependence) of directly connected nodes in the attack path is reduced, and more attention is paid to the nodes with common neighbors. Therefore, based on the concept of neighborhood, the relationship between two arbitrary nodes is defined as:

[0060] C CD =(p CD +p CB p BD +p CE p ED ) 2 (Formula 1)

[0061] Then, p CD It is calculated according to the edges of each node. Node C has 4 edges, so p CD =1 / 4. Similarly, calculate p CB=1 / 4, p BD =1 / 3, p CE =1 / 4, p ED =1 / 3, and finally calculated The fraction here indicates how many edges this node A has. If this node A has 5 nodes connected to it, it means that this node A has 5 edges, and the energy or relationship allocated by this node A to each node is 1 / 5. Set the total energy to 1 and then distribute it evenly to the 5 nodes.

[0062] Similarly, the importance of each edge is calculated according to Formula 1 to construct the weight of each edge in the network topology, forming a network topology analysis based on the "neighborhood" structure to determine the close relationship between nodes.

[0063] In step S12, the vulnerability attack probability faced by each node is calculated based on the vulnerability hazard score, number of vulnerabilities, and destructiveness of each node, including:

[0064]

[0065] Among them, P C represents the vulnerability attack probability faced by node C, f i represents the vulnerability hazard score of each node, n represents the number of vulnerabilities, D j represents destructiveness, and l represents the number of paths. j It includes available confidentiality violation D1, availability violation D2 and integrity violation D3, which are related to the number of paths l.

[0066] In specific implementations, the vulnerability level can refer to the CVSS (Common Vulnerability Scoring System) to obtain the hazard value score f for each vulnerability; the number of vulnerabilities is represented by n; the vulnerability attributes can be calculated using the vulnerability attack dependency method, which can be calculated by referring to the attack path l exploited by each vulnerability in CVSS (for example, the attack distance, the attacker can exploit the local node on which the vulnerability depends, the LAN device, or the router in three ways); the consequences of vulnerability exploitation can be measured in terms of confidentiality damage D1, availability damage D2, and integrity damage D3, which can be specifically referred to CVSS. Based on the above description, the probability formula for a node being attacked without considering the network topology and vulnerability correlation can be expressed as:

[0067]

[0068] In step S13, based on the pre-acquired successful attack probabilities of historical vulnerabilities, an initial Bayesian network between the vulnerabilities is constructed to obtain the initial joint probability of each attack behavior.

[0069] In step S14, the initial joint probability is optimized according to the weight of each edge and the vulnerability attack probability faced by each node to obtain the predicted joint probability of each attack behavior, including:

[0070] Get the vulnerability Vulnerabilities and vulnerabilities Location in the network topology to identify vulnerabilities The order of nodes that occur;

[0071] Based on the node order, the weight of each edge, and the vulnerability attack probability faced by each node, the initial joint probability is updated to obtain a predicted joint probability of each attack behavior.

[0072] In one embodiment, the successful attack probability of historical vulnerabilities is statistically analyzed to construct an initial Bayesian network between the vulnerabilities, such as Figure 3 shown.

[0073] The above is calculated based on historical attack behaviors. For example, a certain attack behavior is through a vulnerability Vulnerabilities and vulnerabilities Each box shows the probability of the vulnerability. Vulnerabilities and vulnerabilities To form an attack chain, if the vulnerabilities belong to different nodes, without considering the weight of the network topology node edge, the attack behavior based on the node consideration can be understood as a conditional probability chain to represent the initial joint probability. The initial joint probability can be expressed as:

[0074]

[0075] in, Indicates that through the vulnerability Vulnerabilities and vulnerabilities The initial joint probability of an attack behavior.

[0076] Considering the importance of network topology node edges, we need to consider These vulnerabilities are found in which locations in the network topology, such as Figure 4 As shown. Based on the above location, we can see that the vulnerability The order of the nodes that occur is: CEFG and CDFG. Based on the above node loss, combined with the weight of the edge in the network topology and the probability of each node being attacked, the predicted joint probability of each attack behavior is optimized in the form of cumulative probability:

[0077]

[0078] in, Indicates that through the vulnerability Vulnerabilities and vulnerabilities The predicted joint probability of an attack behavior.

[0079] In step S15, the probability of the Bayesian network is updated according to the dynamic vulnerability data, and then the predicted joint probability of each attack behavior is updated to obtain the maximum probability attack path.

[0080] In this embodiment, the probability of successful attack in the attack path is dynamically updated by combining the Bayesian network and dynamic data. When an attack behavior is discovered, the probability of each vulnerability in the Bayesian network will be automatically updated. Then, based on the updated probability of vulnerability occurrence in the Bayesian network, the joint probability of each attack behavior will be automatically updated. Figure 5 ,The system can continuously update the probability of the Bayesian network according to the real-time vulnerability data, and then update the probability of successful attack of each attack path in combination with Formula 4, thereby achieving real-time update of the maximum probability attack path of the network multi-source data security time.

[0081] In this invention, the topological relationship of the entire network is constructed through the neighborhood structure method, and the close relationship between nodes is evaluated based on the neighborhood relationship of each node, thereby avoiding the traditional simple and crude evaluation method of direct connection and indirect connection. At the same time, considering the singleness of the evaluation method of network-related events and the unclear causal relationship of security events, this invention uses a Bayesian network to realize the dynamic adjustment of vulnerability causal relationship, thereby improving the accuracy of causal relationship, thereby achieving accurate calculation of the attacker's attack path and effectively displaying the network security situation.

[0082] Among them, network topology analysis based on the "neighborhood" structure determines the close relationship between nodes. This relationship is different from the traditional relationship between nodes being directly connected or indirectly connected. The closeness of local node connections can effectively measure the possibility of attackers using circuitous methods to attack hosts, rather than the traditional fixed method of direct or indirect connection for evaluation.

[0083] The present invention considers three factors: the closeness of network nodes based on the "neighborhood" structure, the probability of nodes being attacked, and the existing attackers' preference for using a certain type of vulnerability to attack. It uses cumulative probability to represent the probability of a successful attack on a path, thereby realizing dynamic association based on the existing vulnerability state. Dynamic association is reflected in the following aspects: if the network topology changes, the closeness of the network will change accordingly, and the current network's preference for using vulnerabilities to attack will change. Then the Bayesian vulnerability dependency conditional probability will also change, and the maximum probability attack path finally obtained will also change. Therefore, when the device vulnerability state remains unchanged, the vulnerability association method proposed by the present invention is actually affected by external factors and changes, and is ultimately reflected in the calculation of the maximum probability attack path. The maximum probability attack path determined by this method can clearly view the source, destination, attacked host, and device with potential security risks of the attack, so that all hosts in the attack process can be specifically analyzed and security protection can be provided for hosts or devices that may be attacked.

[0084] Reference Figure 6 A second embodiment of the present invention provides a network attack path generation device, comprising:

[0085] A weight calculation module is used to obtain the number of edges of each node in the network topology and calculate the weight of each edge of the network topology based on the number of edges;

[0086] The attack probability calculation module is used to calculate the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities and destructiveness of each node;

[0087] The initial probability module is used to build an initial Bayesian network between vulnerabilities based on the successful attack probabilities of historical vulnerabilities obtained in advance, and obtain the initial joint probability of each attack behavior;

[0088] A probability optimization module is used to optimize the initial joint probability according to the weight of each edge and the vulnerability attack probability faced by each node to obtain a predicted joint probability of each attack behavior;

[0089] The path generation module is used to update the probability of the Bayesian network according to the dynamic vulnerability data, and then update the predicted joint probability of each attack behavior to obtain the maximum probability attack path.

[0090] Preferably, the weight calculation module includes:

[0091] a relationship calculation unit, configured to obtain neighbor nodes of each node and obtain a connection relationship between each node and other neighbor nodes according to the number of edges;

[0092] The weight calculation unit is used to calculate the weight of each edge according to the connection relationship.

[0093] It should be noted that the network attack path generation device provided in an embodiment of the present invention is used to execute all the process steps of a network attack path generation method in the above embodiment. The working principles and beneficial effects of the two correspond one to one, and thus will not be described in detail.

[0094] The embodiment of the present invention further provides a terminal device. The terminal device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a network attack path generation program. When the processor executes the computer program, the steps in the above-mentioned embodiments of the network attack path generation method are implemented, such as Figure 1 Alternatively, when the processor executes the computer program, the functions of the modules / units in the above-mentioned device embodiments are realized, such as the path generation module.

[0095] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.

[0096] The terminal device may be a computing device such as a desktop computer, laptop, PDA, or smart tablet. The terminal device may include, but is not limited to, a processor and memory. Those skilled in the art will appreciate that the aforementioned components are merely examples of terminal devices and do not constitute a limitation of the terminal device. The terminal device may include more or fewer components than those described above, or a combination of certain components or different components. For example, the terminal device may also include input / output devices, network access devices, buses, and the like.

[0097] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, connecting various parts of the entire terminal device using various interfaces and lines.

[0098] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created based on the use of the mobile phone (such as audio data, a phone book, etc.). In addition, the memory can include a high-speed random access memory and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.

[0099] If the module / unit integrated in the terminal device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention can implement all or part of the processes in the above-mentioned embodiment method by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to requirements, and the computer-readable medium does not include electric carrier signal and telecommunication signal.

[0100] It should be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art can understand and implement the present invention without inventive effort.

[0101] The specific embodiments described above further illustrate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.

Claims

1. A network attack path generation method, characterized in that: include: Obtaining the number of edges of each node in the network topology, and calculating the weight of each edge of the network topology based on the number of edges; Calculate the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities, and destructiveness of each node; Based on the successful attack probabilities of historical vulnerabilities obtained in advance, an initial Bayesian network between the vulnerabilities is constructed to obtain the initial joint probability of each attack behavior; Optimizing the initial joint probability according to the weight of each edge and the vulnerability attack probability faced by each node to obtain a predicted joint probability of each attack behavior; The probability of the Bayesian network is updated according to the dynamic vulnerability data, and then the predicted joint probability of each attack behavior is updated to obtain the maximum probability attack path.

2. The network attack path generation method according to claim 1, characterized in that: Calculating the weight of each edge of the network topology according to the number of edges includes: Obtain the neighbor nodes of each node, and obtain the connection relationship between each node and other neighbor nodes according to the number of edges; The weight of each edge is calculated based on the connection relationship.

3. The network attack path generation method according to claim 1, characterized in that: The vulnerability attack probability faced by each node is calculated based on the vulnerability hazard score, number of vulnerabilities, and destructiveness of each node, including: Among them, P C represents the vulnerability attack probability faced by node C, f i represents the vulnerability hazard score of each node, n represents the number of vulnerabilities, D j represents destructiveness, and l represents the number of paths.

4. The network attack path generation method according to claim 1, characterized in that: The method of constructing an initial Bayesian network between vulnerabilities based on the previously acquired successful attack probabilities of historical vulnerabilities to obtain the initial joint probability of each attack behavior includes: in, Indicates that through the vulnerability Vulnerabilities and vulnerabilities The initial joint probability of an attack behavior.

5. The network attack path generation method according to claim 4, characterized in that: The initial joint probability is optimized according to the weight of each edge and the vulnerability attack probability faced by each node to obtain the predicted joint probability of each attack behavior, including: Get the vulnerability Vulnerabilities and vulnerabilities Location in the network topology to identify vulnerabilities The order of nodes that occur; Based on the node order, the weight of each edge, and the vulnerability attack probability faced by each node, the initial joint probability is updated to obtain a predicted joint probability of each attack behavior.

6. The network attack path generation method according to claim 5, characterized in that: The predicted joint probability includes: in, Indicates that through the vulnerability Vulnerabilities and vulnerabilities The predicted joint probability of an attack behavior composed of C 、P E 、P F 、P G and P D are the vulnerability attack probabilities faced by nodes C, E, F, G, and D respectively; P CE Indicates the connection relationship between node C and node E; P EF Indicates the connection relationship between node E and node F; P FG Indicates the connection relationship between node F and node G; P CD Indicates the connection relationship between node C and node D; P DF Indicates the connection relationship between node D and node F; P FG Indicates the connection relationship between node F and node G.

7. A network attack path generation device, characterized in that: include: A weight calculation module is used to obtain the number of edges of each node in the network topology and calculate the weight of each edge of the network topology based on the number of edges; The attack probability calculation module is used to calculate the vulnerability attack probability faced by each node based on the vulnerability hazard score, number of vulnerabilities and destructiveness of each node; The initial probability module is used to build an initial Bayesian network between vulnerabilities based on the successful attack probabilities of historical vulnerabilities obtained in advance, and obtain the initial joint probability of each attack behavior; A probability optimization module is used to optimize the initial joint probability according to the weight of each edge and the vulnerability attack probability faced by each node to obtain a predicted joint probability of each attack behavior; The path generation module is used to update the probability of the Bayesian network according to the dynamic vulnerability data, and then update the predicted joint probability of each attack behavior to obtain the maximum probability attack path.

8. The network attack path generation device according to claim 7, characterized in that: The weight calculation module includes: a relationship calculation unit, configured to obtain neighbor nodes of each node and obtain a connection relationship between each node and other neighbor nodes according to the number of edges; The weight calculation unit is used to calculate the weight of each edge according to the connection relationship.

9. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the network attack path generation method according to any one of claims 1 to 6 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the network attack path generation method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network security domain knowledge graph construction method and device for dynamic threat analysis

    CN110113314A

  • Network attack path prediction method and system based on probabilistic graph model

    CN115225304A