A threat source portrait analysis method and system based on identity mapping

Through the threat source image analysis method based on identity mapping, threat source information is collected and identified, threat source image is constructed and associated clue matching is performed, the problem of inaccurate threat source analysis is solved, and the accuracy of threat source image and network threat identification effect is improved.

CN116192521BActive Publication Date: 2025-07-25BEIJING CYBERYEON TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310192870.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-03
Publication Date
2025-07-25
Estimated Expiration
2043-03-03

AI Technical Summary

Technical Problem

The analysis of threat sources in the prior art is not accurate enough, resulting in insufficient accuracy of the threat source image analysis results and poor network threat identification results.

Method used

Through the threat source image analysis method based on identity mapping, a collection of threat source information is collected, a threat source image is constructed, and an identity feature is identified using the portrait analysis model, and a threat source identity feature is obtained. The candidate threat source collection is traversed through the candidate threat source collection through big data technology to collect historical action and match the associated clues to determine the target threat source.

Benefits of technology

It improves the accuracy of threat source image analysis, realizes timely early warning of network threats, and ensures network security operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192521B_ABST
    Figure CN116192521B_ABST
Patent Text Reader

Abstract

The present disclosure provides a threat source portrait analysis method and system based on identity mapping, which relates to the technical field of data processing. The method includes: obtaining a threat source information set; constructing a threat source portrait; inputting the threat source portrait into a portrait analysis model to obtain threat source identity features; performing data retrieval based on the threat source identity features to obtain a candidate threat source set; traversing the candidate threat source set to collect historical actions to obtain a historical action set; performing associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result; and obtaining a target threat source based on the associated clue matching result. It solves the technical problems in the prior art that due to inaccurate analysis of threat sources and poor threat portrait analysis effect, the accuracy of threat source portrait analysis results is insufficient and the network threat recognition effect is poor.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, and in particular, to a threat source portrait analysis method and system based on identity mapping. Background Art

[0002] With the development of threat intelligence, the security analysis field has begun to use threat intelligence data to perform portrait analysis on various network attacks. Portrait analysis is based on a portrait model and portrait data, and uses threat source data to draw a threat map, forming a threat portrait based on threat source characteristics.

[0003] Currently, in the prior art, there are technical problems that due to inaccurate analysis of threat sources and poor threat portrait analysis effect, the accuracy of threat source portrait analysis results is insufficient, and the network threat recognition effect is poor. Summary of the Invention

[0004] The present disclosure provides a threat source portrait analysis method and system based on identity mapping to solve the technical problems in the prior art that due to inaccurate analysis of threat sources and poor threat portrait analysis effect, the accuracy of threat source portrait analysis results is insufficient, and the network threat recognition effect is poor.

[0005] According to a first aspect of the present disclosure, there is provided a threat source portrait analysis method based on identity mapping, including: collecting threat source information based on a target network to obtain a threat source information set; constructing a threat source portrait based on the threat source information set; inputting the threat source portrait into a portrait analysis model, and performing identity feature recognition on the threat source portrait through the portrait analysis model to obtain threat source identity features; performing data retrieval based on the threat source identity features to obtain a candidate threat source set; collecting historical actions by traversing the candidate threat source set based on big data to obtain a historical action set, wherein the candidate threat source set and the historical action set have a corresponding relationship; performing associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result; and obtaining a target threat source based on the associated clue matching result.

[0006] According to a second aspect of the present disclosure, there is provided a threat source portrait analysis system based on identity mapping, including: a threat source information collection module configured to collect threat source information based on a target network to obtain a threat source information set; a threat source portrait construction module configured to construct a threat source portrait based on the threat source information set; an identity feature recognition module configured to input the threat source portrait into a portrait analysis model, and perform identity feature recognition on the threat source portrait through the portrait analysis model to obtain threat source identity features; a data retrieval module configured to perform data retrieval based on the threat source identity features to obtain a candidate threat source set; a historical action collection module configured to traverse the candidate threat source set based on big data to collect historical actions to obtain a historical action set, wherein the candidate threat source set and the historical action set have a corresponding relationship; an associated clue matching module configured to perform associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result; and a target threat source obtaining module configured to obtain a target threat source based on the associated clue matching result.

[0007] According to a third aspect of the present disclosure, there is provided an electronic device, including:

[0008] at least one processor; and

[0009] a memory communicatively connected to the at least one processor; wherein,

[0010] the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method according to the first aspect.

[0011] A threat source portrait analysis method based on identity mapping adopted according to the present disclosure collects threat source information based on a target network to obtain a threat source information set; constructs a threat source portrait based on the threat source information set; inputs the threat source portrait into a portrait analysis model, and performs identity feature recognition on the threat source portrait through the portrait analysis model to obtain threat source identity features; performs data retrieval based on the threat source identity features to obtain a candidate threat source set; traverses the candidate threat source set based on big data to collect historical actions to obtain a historical action set, wherein the candidate threat source set and the historical action set have a corresponding relationship; performs associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result; and obtains a target threat source based on the associated clue matching result. The present disclosure constructs a threat source portrait by analyzing data based on threat source information, inputs the threat source portrait into a portrait analysis model for identity feature recognition, outputs threat source identity features, and then uses identity mapping to search for threat source objects with the threat source identity features as an index to determine a candidate threat source set. Based on big data technology, with historical actions as the search target, traverses the candidate threat sources to collect historical actions to obtain multiple historical action sets. Furthermore, performs associated clue matching on the multiple historical action sets and threat source information to obtain a matching result, and determines the target threat source according to the matching result, achieving the technical effects of improving the accuracy of threat source portrait analysis, giving timely warnings about threat behaviors in the network, and ensuring the secure operation of the network.

[0012] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the technical solutions in the present disclosure or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings described below are only exemplary, and those of ordinary skill in the art can obtain other drawings according to the provided drawings without creative efforts.

[0014] Figure 1 It is a flowchart of a threat source portrait analysis method based on identity mapping provided by an embodiment of the present disclosure;

[0015] Figure 2 It is a structural diagram of a threat source portrait analysis system based on identity mapping provided by an embodiment of the present disclosure;

[0016] Figure 3 It is a structural diagram of an electronic device provided by an embodiment of the present disclosure.

[0017] Explanation of the accompanying drawings: threat source information collection module 11, threat source portrait construction module 12, identity feature recognition module 13, data retrieval module 14, historical action collection module 15, associated clue matching module 16, target threat source acquisition module 17, electronic device 800, processor 801, memory 802, bus 803. DETAILED DESCRIPTION

[0018] The following is a description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0019] In order to solve the technical problems in the prior art that the analysis of threat sources is not accurate enough and the threat profile analysis effect is not good, which leads to insufficient accuracy of threat source profile analysis results and poor network threat identification effect, the inventors of the present invention have obtained a threat source profile analysis method and system based on identity mapping through creative work.

[0020] Embodiment 1

[0021] Figure 1 A threat source profile analysis method based on identity mapping is provided in an embodiment of the present application, such as Figure 1 As shown, the method includes:

[0022] Step S100: collecting threat source information based on the target network to obtain a threat source information set;

[0023] Wherein, the step S100 of obtaining the threat source information set in the embodiment of the present application further includes:

[0024] Step S110: Collect threat behavior information of the target network to obtain a threat behavior data set;

[0025] Step S120: Collect threat target information of the target network to obtain a threat target data set;

[0026] Step S130: Collect attack point information of the target network to obtain an attack point data set;

[0027] Step S140: obtaining a threat source information database based on the threat behavior data set, the threat target data set and the attack point data set;

[0028] Step S150: performing principal component analysis based on the threat source information database to obtain the threat source information set.

[0029] Among them, principal component analysis is performed based on the threat source information library to obtain the threat source information set. Step S150 of the embodiment of the present application further includes:

[0030] Step S151: Obtain a first characteristic threat source data set according to the threat source information library;

[0031] Step S152: Perform a decentralization process on the first characteristic threat source data set to obtain a second characteristic threat source data set;

[0032] Step S153: Obtain a covariance matrix of the first threat source information according to the second characteristic threat source data set;

[0033] Step S154: Obtain a first threat source information eigenvalue and a first threat source information eigenvector according to the covariance matrix of the first threat source information;

[0034] Step S155: Obtain the threat source information set according to the first threat source information eigenvalue and the first threat source information eigenvector.

[0035] Specifically, the embodiment of the present application provides a threat source portrait analysis method based on identity mapping for preventing network attacks or network threats. The target network refers to the network for which threat source portrait analysis needs to be performed, such as the service system of a certain enterprise. Collecting threat source information according to the target network means analyzing the possible threats to the target network, such as possible threat behaviors, threat purposes, and attack points, and obtaining a threat source information set based on this.

[0036] Specifically, collect the threat behavior information of the target network. The threat behavior information refers to the actions of network attacks. There may be multiple attack actions on the target network, and all attack actions together constitute the threat behavior data set. Collect the threat purpose information of the target network. The threat purpose information refers to the purposes that illegal personnel want to achieve through network threat behaviors, such as network monitoring and denial-of-service attacks. Based on this, obtain the threat purpose data set. Collect the attack point information of the target network. The attack point information refers to the machines that conduct network attacks, specifically the IP addresses of the hosts. Based on this, obtain the attack point data set. The threat behavior data set, the threat purpose data set, and the attack point data set together constitute the threat source information library. Based on the threat source information library, perform principal component analysis to obtain the threat source information set. Principal component analysis is the most commonly used linear dimensionality reduction method. Its goal is to map high-dimensional data to a low-dimensional space through a certain linear projection and expect the information volume of the data to be the largest (the variance is the largest) on the projected dimension. In this way, use fewer data dimensions while retaining the characteristics of more original data points. The threat source information set includes the data after dimensionality reduction, achieving the effect of providing basic data for subsequent threat source profiling analysis.

[0037] Specifically, based on the threat source information library, perform principal component analysis to obtain the threat source information set. First, according to the threat source information library, numerically process the characteristic data in the threat source information library and construct a characteristic data set matrix to obtain the first characteristic threat source data set. Then, perform a centering process on each characteristic data in the first characteristic threat source data set. First, solve the average value of each characteristic in the first characteristic threat source data set, and then for all data, subtract the mean value of each characteristic from itself, and then obtain new characteristic values. The new characteristic data set constitutes the second characteristic threat source data set, and the second characteristic threat source data set is a data matrix. Calculate the covariance matrix of the first threat source information through the covariance formula, and then through matrix operations, find the first threat source information eigenvalues and the first threat source information eigenvectors of the covariance matrix, and each eigenvalue corresponds to an eigenvector. Based on the first threat source information eigenvalues and the first threat source information eigenvectors, obtain the threat source information set. Specifically, select the top K largest first threat source information eigenvalues and their corresponding first threat source information eigenvectors, and project the original characteristics in the first characteristic threat source data set onto the selected eigenvectors to obtain the threat source information set after dimensionality reduction. It should be noted that the first threat source information refers to any threat information in the threat source information library, and the first threat source information eigenvalues and the first threat source information eigenvectors correspond to the first threat source information. Obtain the threat source information set through principal component analysis, achieving the effect of removing redundant data while ensuring the information volume, reducing the sample size of the characteristic data in the database, and minimizing the information loss after dimensionality reduction.

[0038] Step S200: Construct a threat source portrait based on the threat source information set;

[0039] Specifically, the threat source information set includes a threat behavior data set, a threat purpose data set, and an attack point data set. A threat source portrait refers to a threat map containing threat source features drawn based on the threat behavior data set, the threat purpose data set, and the attack point data set in the threat source information set.

[0040] Step S300: Input the threat source portrait into a portrait analysis model, and perform identity feature recognition on the threat source portrait through the portrait analysis model to obtain threat source identity features;

[0041] Among them, step S300 in the embodiment of this application further includes:

[0042] Step S310: Collect identity feature recognition record information of the threat source portrait based on big data to obtain a portrait recognition record data set;

[0043] Step S320: Obtain a preset data division ratio;

[0044] Step S330: Randomly divide the portrait recognition record data set based on the preset data division ratio to obtain construction feature data, where the construction feature data includes a construction feature training set and a construction feature test set;

[0045] Step S340: Based on a convolutional neural network, perform cross-supervised training on the construction feature training set to obtain the portrait analysis model;

[0046] Step S350: Update the parameters of the portrait analysis model based on the construction feature test set.

[0047] Specifically, a portrait analysis model is a functional model that obtains threat source identity features by performing identity feature recognition on a threat source portrait. Threat source identity features refer to the features existing in the attacking entity that attacks the target network, including threat behavior features, threat purpose features, and attack point features.

[0048] Specifically, based on big data, identity feature recognition record information of threat source portraits is collected to obtain a portrait recognition record data set. The portrait recognition record data set includes multiple threat portraits and their corresponding multiple identity feature recognition record information. Furthermore, a preset data division ratio is obtained. The preset data division ratio refers to the ratio for dividing the portrait recognition record data set. The portrait recognition record data set is randomly divided according to the preset data division ratio to obtain construction feature data. Among them, the construction feature data includes a construction feature training set and a construction feature test set. For example, if the preset data division ratio is set to 4:6, it means that 60% of the data in the portrait recognition record data set is used as the construction feature training set, and 40% of the data in the portrait recognition record data set is used as the construction feature test set. Based on a convolutional neural network, the network structure of the portrait analysis model is built, and cross-supervised training is performed on the construction feature training set. That is, the threat source portraits in the construction feature training set are input into the portrait analysis model, and the output of the model is supervised and adjusted through the identity feature recognition record information corresponding to the threat source portraits, so that the output result of the model continuously approaches the identity feature recognition record information until the model training converges, thereby obtaining the portrait analysis model. Further, the parameters of the portrait analysis model are updated based on the construction feature test set. That is to say, the data in the construction feature test set is used to test the output accuracy rate of the model, and the model is adjusted according to the accuracy rate to achieve the effect of ensuring the identity feature recognition accuracy rate and improving the threat source portrait analysis accuracy rate.

[0049] Step S400: Based on the threat source identity features, perform data retrieval to obtain a candidate threat source set;

[0050] Among them, step S400 of the embodiment of the present application further includes:

[0051] Step S410: Based on the threat source identity features, obtain index feature information;

[0052] Step S420: Set the threat source object as the retrieval target;

[0053] Step S430: Based on the index feature information and the retrieval target, perform big data collection to obtain the candidate threat source set.

[0054] Specifically, using the threat source identity features as an index, threat source object search is performed using identity mapping to determine a candidate threat source set. The candidate threat source set includes multiple attack subjects similar to the threat source identity features.

[0055] Specifically, based on the threat source identity features, index feature information is obtained. The threat source identity features refer to the features of the attacking entity that attacks the target network, including threat behavior features, threat purpose features, and attack point features. Correspondingly, the index feature information includes the threat behavior features, threat purpose features, and attack point features included in the threat source identity features. Using this as the index feature information, the threat source object is retrieved. The threat source object refers to the attacking entity. The threat source object is set as the retrieval target, and based on the index feature information and the retrieval target, big data collection is performed to obtain the candidate threat source set. Simply put, it is to search for threat source objects similar to the index feature information according to the index feature information. There may be multiple threat source objects found, and the multiple threat source objects form the candidate threat source set, achieving the threat source identification efficiency and ensuring the effect of network security operation.

[0056] Step S500: Based on big data, traverse the candidate threat source set to collect historical actions and obtain a historical action set. Among them, there is a corresponding relationship between the candidate threat source set and the historical action set;

[0057] Specifically, based on big data, traverse the candidate threat source set to collect historical actions and obtain a historical action set. The historical action set contains the historical threat actions corresponding to each candidate threat source, and there is a corresponding relationship between the candidate threat source set and the historical action set.

[0058] Step S600: Perform associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result;

[0059] Among them, step S600 of the embodiment of the present application further includes:

[0060] Step S610: Based on the historical action set, perform action frequency statistics on the candidate threat source set to obtain an action frequency statistics result;

[0061] Step S620: Based on the historical action set, perform action impact assessment on the candidate threat source set to obtain an action impact assessment result;

[0062] Step S630: Add the action frequency statistics result and the action impact assessment result to the associated clue matching result.

[0063] Specifically, perform associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result. Simply put, it is to determine the relevance between the candidate threat sources in the candidate threat source set and the threat actions in the historical action set and the target network, and use this as the associated clue matching result.

[0064] Specifically, according to the historical action set, the action frequency of the candidate threat source set is statistically analyzed to obtain the action frequency statistical result, which includes the number of occurrences of threat behaviors in the candidate threat source set. According to the historical action set, the action impact of the candidate threat source set is evaluated, that is, to evaluate the impact degree of the threat behavior on the network security of the target network, and the impact degree is used as the action impact evaluation result. Different weights are set for the action frequency statistical result and the action impact evaluation result, and weighted calculation is performed according to the weight distribution result to obtain the associated clue matching result, so as to provide data support for the determination of the target threat source, ensure the secure operation of the network, and improve the accuracy of threat source identification.

[0065] Step S700: Based on the associated clue matching result, obtain the target threat source.

[0066] Specifically, according to the associated clue matching result, the target threat source is obtained from the candidate threat source set, and the target threat source is the object that poses a threat to the target network.

[0067] After obtaining the target threat source, step S800 of the embodiment of the present application includes:

[0068] Step S810: Evaluate the threat level of the target threat source to obtain the target threat level;

[0069] Step S820: Obtain the threat level threshold;

[0070] Step S830: Determine whether the target threat level meets the threat level threshold;

[0071] Step S840: If the target threat level meets the threat level threshold, obtain the threat warning information.

[0072] Specifically, multiple threat levels are set in advance, and then the threat level of the target threat source is evaluated to obtain the target threat level corresponding to the target threat source. Further, the threat level threshold is obtained. The threat level threshold is a judgment index for threat warning, that is, warning is required when the threat level threshold is reached. Determine whether the target threat level meets the threat level threshold. If the target threat level meets the threat level threshold, obtain the threat warning information. The threat warning information is information for warning network threats to staff and assisting staff in network security maintenance, so as to achieve the effect of timely warning and ensuring the secure operation of the network.

[0073] Based on the above analysis, the present disclosure provides a threat source portrait analysis method based on identity mapping. In this embodiment, a threat source portrait is constructed by analyzing data based on threat source information, and the threat source portrait is input into a portrait analysis model for identity feature recognition to output threat source identity features. Then, using the threat source identity features as an index, threat source objects are searched through identity mapping to determine a candidate threat source set. Based on big data technology, with historical actions as the search target, the candidate threat sources are traversed to collect historical actions, obtaining multiple historical action sets. Furthermore, the multiple historical action sets are matched with threat source information for associated clue matching to obtain a matching result, and the target threat source is determined according to the matching result, achieving the technical effect of improving the accuracy of threat source portrait analysis, timely warning of threat behaviors in the network, and ensuring the secure operation of the network.

[0074] Embodiment 2

[0075] Based on the same inventive concept as a threat source portrait analysis method based on identity mapping in the foregoing embodiment, as Figure 2 shown, the present application also provides a threat source portrait analysis system based on identity mapping, and the system includes:

[0076] A threat source information collection module 11, which is used to collect threat source information based on a target network to obtain a threat source information set;

[0077] A threat source portrait construction module 12, which is used to construct a threat source portrait based on the threat source information set;

[0078] An identity feature recognition module 13, which is used to input the threat source portrait into a portrait analysis model, and perform identity feature recognition on the threat source portrait through the portrait analysis model to obtain threat source identity features;

[0079] A data retrieval module 14, which is used to perform data retrieval based on the threat source identity features to obtain a candidate threat source set;

[0080] A historical action collection module 15, which is used to collect historical actions by traversing the candidate threat source set based on big data to obtain a historical action set, where there is a corresponding relationship between the candidate threat source set and the historical action set;

[0081] An associated clue matching module 16, which is used to perform associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result;

[0082] The target threat source acquisition module 17 is configured to obtain a target threat source based on the associated clue matching result.

[0083] Furthermore, the system further includes:

[0084] A threat behavior data acquisition module, which is configured to collect threat behavior information of a target network to obtain a threat behavior data set;

[0085] A threat purpose data acquisition module, which is configured to collect threat purpose information of a target network to obtain a threat purpose data set;

[0086] An attack point data acquisition module, which is configured to collect attack point information of a target network to obtain an attack point data set;

[0087] A data integration module, which is configured to obtain a threat source information library based on the threat behavior data set, the threat purpose data set, and the attack point data set;

[0088] A principal component analysis module, which is configured to perform principal component analysis based on the threat source information library to obtain a threat source information set.

[0089] Furthermore, the system further includes:

[0090] A first characteristic threat source data set acquisition module, which is configured to obtain a first characteristic threat source data set according to the threat source information library;

[0091] A decentralization processing module, which is configured to perform decentralization processing on the first characteristic threat source data set to obtain a second characteristic threat source data set;

[0092] A covariance matrix acquisition module, which is configured to obtain a covariance matrix of the first threat source information according to the second characteristic threat source data set;

[0093] A feature vector acquisition module, which is configured to obtain a first threat source information eigenvalue and a first threat source information eigenvector according to the covariance matrix of the first threat source information;

[0094] A threat source information set acquisition module, which is configured to obtain the threat source information set according to the first threat source information eigenvalue and the first threat source information eigenvector.

[0095] Furthermore, the system further includes:

[0096] Image recognition record dataset acquisition module, which is used to collect identity feature recognition record information of threat source images based on big data and obtain an image recognition record dataset;

[0097] Preset data division ratio acquisition module, which is used to obtain a preset data division ratio;

[0098] Constructed feature data acquisition module, which is used to randomly divide the image recognition record dataset based on the preset data division ratio to obtain constructed feature data, where the constructed feature data includes a constructed feature training set and a constructed feature test set;

[0099] Cross-supervised training module, which is used to perform cross-supervised training on the constructed feature training set based on a convolutional neural network to obtain the image analysis model;

[0100] Parameter update module, which is used to update the parameters of the image analysis model based on the constructed feature test set.

[0101] Furthermore, the system further includes:

[0102] Index feature information acquisition module, which is used to obtain index feature information based on the threat source identity features;

[0103] Retrieval target determination module, which is used to set the threat source object as the retrieval target;

[0104] Data retrieval module, which is used to perform big data collection based on the index feature information and the retrieval target to obtain the candidate threat source set.

[0105] Furthermore, the system further includes:

[0106] Action frequency statistics module, which is used to perform action frequency statistics on the candidate threat source set based on the historical action set to obtain an action frequency statistics result;

[0107] Action impact assessment module, which is used to perform action impact assessment on the candidate threat source set based on the historical action set to obtain an action impact assessment result;

[0108] Association clue matching result acquisition module, which is used to add the action frequency statistics result and the action impact assessment result to the association clue matching result.

[0109] Furthermore, the system further includes:

[0110] A threat level assessment module, which is used to assess the threat level of a target threat source to obtain a target threat level;

[0111] A threat level threshold acquisition module, which is used to obtain a threat level threshold;

[0112] A target threat level judgment module, which is used to judge whether the target threat level meets the threat level threshold;

[0113] A threat warning information acquisition module, which is used to obtain threat warning information if the target threat level meets the threat level threshold.

[0114] The specific example of a threat source portrait analysis method based on identity mapping in the foregoing Embodiment 1 is equally applicable to a threat source portrait analysis system based on identity mapping in this embodiment. Through the foregoing detailed description of a threat source portrait analysis method based on identity mapping, those skilled in the art can clearly know a threat source portrait analysis system based on identity mapping in this embodiment. Therefore, for the sake of simplicity of the specification, it will not be elaborated here. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0115] Embodiment 3

[0116] Figure 3 It is a schematic diagram according to the third embodiment of the present disclosure. As Figure 3 shown, the electronic device 800 in the present disclosure may include: a processor 801 and a memory 802.

[0117] A memory 802 for storing programs; the memory 802 may include volatile memory (e.g., random-access memory, such as static random-access memory (SRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDR SDRAM), etc.); the memory may also include non-volatile memory, such as flash memory. The memory 802 is used to store computer programs (such as application programs and functional modules for implementing the above methods), computer instructions, etc. The above computer programs, computer instructions, etc. can be stored in partitions in one or more memories 802. And the above computer programs, computer instructions, data, etc. can be called by the processor 801.

[0118] The above computer programs, computer instructions, etc. can be stored in partitions in one or more memories 802. And the above computer programs, computer instructions, data, etc. can be called by the processor 801.

[0119] A processor 801 for executing the computer programs stored in the memory 802 to implement the various steps in the methods involved in the above embodiments.

[0120] Specifically, reference can be made to the relevant descriptions in the foregoing method embodiments.

[0121] The processor 801 and the memory 802 may be of independent structures or integrated structures. When the processor 801 and the memory 802 are of independent structures, the memory 802 and the processor 801 may be coupled and connected through a bus 803.

[0122] The electronic device of this embodiment can execute the technical solutions in the above methods, and the specific implementation processes and technical principles are the same, so details are not described herein again.

[0123] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0124] According to an embodiment of the present disclosure, the present disclosure further provides a computer program product, the computer program product comprising: a computer program, the computer program being stored in a readable storage medium, at least one processor of the electronic device can read the computer program from the readable storage medium, and the at least one processor executing the computer program causes the electronic device to execute the solution provided in any of the above embodiments.

[0125] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps recited in the present disclosure can be executed in parallel, sequentially or in a different order,

[0126] as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, no limitations are imposed herein.

[0127] The above specific embodiments do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub - combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.

Claims

1. A threat source portrait analysis method based on identity mapping, characterized in that, The method includes: Collect threat source information based on the target network to obtain a threat source information set; Construct a threat source portrait based on the threat source information set; Input the threat source portrait into a portrait analysis model, and identify the identity characteristics of the threat source portrait through the portrait analysis model to obtain threat source identity characteristics; Perform data retrieval based on the threat source identity characteristics to obtain a candidate threat source set; Based on big data, traverse the candidate threat source set to collect historical actions to obtain a historical action set, where the candidate threat source set and the historical action set have a corresponding relationship; Perform associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result, including: Based on the historical action set, perform action frequency statistics on the candidate threat source set to obtain an action frequency statistics result; Based on the historical action set, perform action impact assessment on the candidate threat source set to obtain an action impact assessment result; Add the action frequency statistics result and the action impact assessment result to the associated clue matching result; Obtain a target threat source based on the associated clue matching result; Perform threat level assessment on the target threat source to obtain a target threat level; Obtain a threat level threshold; Determine whether the target threat level meets the threat level threshold; If the target threat level meets the threat level threshold, obtain threat warning information.

2. The method according to claim 1, characterized in that, Regarding obtaining the threat source information set, the method further includes: Collect threat behavior information of the target network to obtain a threat behavior data set; Collect threat purpose information of the target network to obtain a threat purpose data set; Collect attack point information of the target network to obtain an attack point data set; Based on the threat behavior data set, the threat purpose data set, and the attack point data set, obtain a threat source information library; Perform principal component analysis based on the threat source information library to obtain the threat source information set.

3. The method according to claim 2, characterized in that, Regarding performing principal component analysis based on the threat source information library to obtain the threat source information set, the method further includes: Obtain a first characteristic threat source data set according to the threat source information library; Perform a de-centralization process on the first characteristic threat source data set to obtain a second characteristic threat source data set; Obtain a covariance matrix of the first threat source information according to the second characteristic threat source data set; Obtain first threat source information eigenvalues and first threat source information eigenvectors according to the covariance matrix of the first threat source information; Obtain the threat source information set according to the first threat source information eigenvalues and the first threat source information eigenvectors.

4. The method according to claim 1, characterized in that, The method further includes: Based on big data, collect identity characteristic recognition record information of the threat source portrait to obtain a portrait recognition record data set; Obtain a preset data division ratio; Perform random data division on the portrait recognition record data set based on the preset data division ratio to obtain construction feature data, where the construction feature data includes a construction feature training set and a construction feature test set; Based on a convolutional neural network, cross-supervised training is performed on the constructed feature training set to obtain the portrait analysis model; Based on the constructed feature test set, parameter updates are performed on the portrait analysis model.

5. The method according to claim 1, wherein Based on the threat source identity features, data retrieval is performed to obtain a candidate threat source set, and the method further includes: Based on the threat source identity features, index feature information is obtained; The threat source object is set as the retrieval target; Based on the index feature information and the retrieval target, big data collection is performed to obtain the candidate threat source set.

6. A threat source portrait analysis system based on identity mapping, characterized in that, The system is used to execute the method according to any one of claims 1 to 5, and the system includes: A threat source information collection module, which is used to collect threat source information based on the target network to obtain a threat source information set; A threat source portrait construction module, which is used to construct a threat source portrait based on the threat source information set; An identity feature recognition module, which is used to input the threat source portrait into the portrait analysis model, and perform identity feature recognition on the threat source portrait through the portrait analysis model to obtain threat source identity features; A data retrieval module, which is used to perform data retrieval based on the threat source identity features to obtain a candidate threat source set; A historical action collection module, which is used to traverse the candidate threat source set based on big data to collect historical actions to obtain a historical action set, where the candidate threat source set and the historical action set have a corresponding relationship; An associated clue matching module, which is used to perform associated clue matching based on the candidate threat source set and the historical action set to obtain an associated clue matching result; A target threat source obtaining module, which is used to obtain a target threat source based on the associated clue matching result; An action frequency statistics module, which is used to perform action frequency statistics on the candidate threat source set based on the historical action set to obtain an action frequency statistics result; An action impact evaluation module, which is used to perform action impact evaluation on the candidate threat source set based on the historical action set to obtain an action impact evaluation result; An associated clue matching result obtaining module, which is used to add the action frequency statistics result and the action impact evaluation result to the associated clue matching result; A threat level evaluation module, which is used to perform threat level evaluation on the target threat source to obtain a target threat level; A threat level threshold obtaining module, which is used to obtain a threat level threshold; A target threat level judgment module, which is used to judge whether the target threat level meets the threat level threshold; A threat warning information obtaining module, which is used to obtain threat warning information if the target threat level meets the threat level threshold.

7. An electronic device, characterized in that, Including: At least one processor; And A memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Attacker analysis method and device

    CN113496179A

  • Attack countering method and system

    CN115514535A