Attack Tree Construction Method, Device, Electronic Device and Readable Storage Medium
By obtaining network attack data and selecting the target attack matrix framework according to its application object type, determining attack information and building an attack tree, the problem of high limitations in the use of attack trees in the existing technology is solved, and the uniqueness and universality of the attack tree are achieved.
Patent Information
- Application Number
- CN202310155916.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-13
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2043-02-13
AI Technical Summary
In the prior art, the use of attack trees is relatively limited, and the attack trees constructed by different professionals in the same network attack data are relatively different, resulting in higher versatility and usage limitations.
By obtaining cyber attack data, selecting the target attack matrix framework according to its application object type, determining the attack information, and building an attack tree based on this information. This method ensures that cyberattack data of the same application object type performs a unified attack matrix framework, thereby building a unique attack tree.
The uniqueness and universality of the attack tree are realized, the limitations of the use of the attack tree are reduced, and the problem of excessive differences in the attack tree constructed by different professionals is avoided.
Smart Images

Figure CN116232715B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly to a method, device, electronic device and readable storage medium for constructing an attack tree. Background Art
[0002] With the rapid development of technology, network security technology has also become more and more mature. The attack tree is a commonly used method for guiding network security testing. Currently, professional personnel usually manually construct attack trees based on network attack data. However, due to certain differences in the professional technical levels and cognitive abilities of different people, it is easy to construct significantly different attack trees from the same network attack data by different professional personnel, resulting in relatively low generality of the constructed attack trees for network security testing (for example, an attack tree constructed by a certain professional personnel can only be used by that professional personnel or the organization where that professional personnel belongs to conduct network security testing. Due to the differences in attack tree construction methods, other professional personnel who do not belong to the organization where that professional personnel belongs may not be able to conduct network security testing or the reference value for conducting network security testing is relatively low), thus leading to relatively high limitations in the use of attack trees. Summary of the Invention
[0003] The main purpose of this application is to provide a method, device, electronic device and readable storage medium for constructing an attack tree, aiming to solve the technical problem of relatively high limitations in the use of attack trees in the prior art.
[0004] To achieve the above object, this application provides an attack tree construction method, and the attack tree construction method includes:
[0005] Obtain network attack data;
[0006] Select a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data;
[0007] Determine the attack information corresponding to the network attack data according to the target attack matrix framework;
[0008] Construct an attack tree for the network attack data according to the attack information.
[0009] Optionally, the attack information includes at least one of attack target, attack tactic, attack profile, attack point, attack action and attack weapon.
[0010] The step of determining the attack information corresponding to the network attack data includes:
[0011] Determine the attack target corresponding to the network attack data according to the application object type corresponding to the network attack data; and / or,
[0012] Query the attack tactics corresponding to each of the attack targets in the target attack matrix framework according to the attack targets corresponding to the network attack data; and / or,
[0013] Construct an attack profile for each of the attack tactics according to the network attack data, where at least one attack point is included in the attack profile; and / or,
[0014] Generate at least one attack action for each of the attack points according to the target attack matrix framework; and / or,
[0015] Determine at least one attack weapon corresponding to each of the attack actions.
[0016] Optionally, the step of generating at least one attack action for each of the attack points according to the target attack matrix framework includes:
[0017] Read the attack attributes corresponding to each of the attack points, where the attack attributes include state flow attributes and non-state flow attributes;
[0018] If the attack attribute is the state flow attribute, generate the attack action according to the technologies in each of the attack points;
[0019] If the attack attribute is the non-state flow attribute, query the target attack matrix framework according to the attack point to obtain a query result, and generate the attack action according to the query result.
[0020] Optionally, the query result includes an existing classification mapping and a non-existing classification mapping,
[0021] The step of generating the attack action according to the query result includes:
[0022] If the query result is the existing classification mapping, extract the technical names and technical identifiers of each of the attack points, and generate the attack action according to the technical names and the technical identifiers;
[0023] If the query result is the non-existing classification mapping, display the attack point for a professional to judge the human judgment attack action according to the attack point, and use the human judgment attack action as the attack action.
[0024] Optionally, the step of determining at least one attack weapon corresponding to each of the attack actions includes:
[0025] Obtain the mapping relationship between the preset attack actions and the preset attack weapons;
[0026] Map each of the attack actions to an attack weapon through the mapping relationship.
[0027] Optionally, before the step of obtaining the mapping relationship between the preset attack actions and the preset attack weapons, the method further includes:
[0028] Obtaining an attack mode enumeration and classification database;
[0029] Parsing the technologies and sub - technologies in the attack mode enumeration and classification database, and using each of the technologies and each of the sub - technologies as the preset attack actions;
[0030] Determining the preset attack weapons corresponding to each of the preset attack actions, and constructing the mapping relationship between the preset attack actions and the preset attack weapons.
[0031] Optionally, the attack information includes an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon.
[0032] The step of constructing an attack tree of the network attack data according to the attack information includes:
[0033] Constructing a first connection channel between the attack target and the attack tactic corresponding to the attack target, constructing a second connection channel between each attack tactic and the attack profile corresponding to each attack tactic, constructing a third connection channel between each attack profile and the attack points included in each attack profile, constructing a fourth connection channel between each attack point and the attack action corresponding to each attack point, and constructing a fifth connection channel between each attack action and the attack weapon corresponding to each attack action, to obtain the attack tree of the network attack data.
[0034] To achieve the above object, the present application further provides an attack tree construction device, and the attack tree construction device includes:
[0035] An acquisition module, configured to acquire network attack data;
[0036] A selection module, configured to select a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data;
[0037] A determination module, configured to determine the attack information corresponding to the network attack data according to the target attack matrix framework;
[0038] A construction module, configured to construct an attack tree of the network attack data according to the attack information.
[0039] Optionally, the attack information includes at least one of an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon, and the determination module is further configured to:
[0040] Determine the attack target corresponding to the network attack data according to the type of application object corresponding to the network attack data; and / or,
[0041] Query the target attack matrix framework according to the attack target corresponding to the network attack data to obtain the attack tactics corresponding to each attack target; and / or,
[0042] Construct an attack profile for each attack tactic, where the attack profile includes at least one attack point; and / or,
[0043] Generate at least one attack action for each attack point according to the target attack matrix framework; and / or,
[0044] Determine at least one attack weapon corresponding to each attack action.
[0045] Optionally, the determination module is further configured to:
[0046] Read the attack attributes corresponding to each attack point, where the attack attributes include state flow attributes and non-state flow attributes;
[0047] If the attack attribute is the state flow attribute, generate the attack action according to the technology in each attack point;
[0048] If the attack attribute is the non-state flow attribute, query the target attack matrix framework according to the attack point to obtain a query result, and generate the attack action according to the query result.
[0049] Optionally, the query result includes an existing classification mapping and a non-existing classification mapping, and the determination module is further configured to:
[0050] If the query result is the existing classification mapping, extract the technical name and technical identifier of each attack point, and generate the attack action according to the technical name and the technical identifier;
[0051] If the query result is the non-existing classification mapping, display the attack point for a professional to judge the human judgment attack action according to the attack point, and use the human judgment attack action as the attack action.
[0052] Optionally, the determination module is further configured to:
[0053] Obtain the mapping relationship between the preset attack actions and the preset attack weapons;
[0054] Map each attack action to an attack weapon through the mapping relationship.
[0055] Optionally, before the step of obtaining the mapping relationship between the preset attack actions and the preset attack weapons, the attack tree construction device is further configured to:
[0056] Obtain an attack mode enumeration and classification database;
[0057] Parse the technologies and sub - technologies in the attack mode enumeration and classification database, and use each of the technologies and each of the sub - technologies as the preset attack actions;
[0058] Determine the preset attack weapons corresponding to each of the preset attack actions, and construct the mapping relationship between the preset attack actions and the preset attack weapons.
[0059] Optionally, the attack information includes an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon. The attack tree construction device is further configured to:
[0060] Construct a first connection channel between the attack target and the attack tactic corresponding to the attack target, construct a second connection channel between each attack tactic and the attack profile corresponding to each attack tactic, construct a third connection channel between each attack profile and the attack points included in each attack profile, construct a fourth connection channel between each attack point and the attack action corresponding to each attack point, and construct a fifth connection channel between each attack action and the attack weapon corresponding to each attack action, to obtain the attack tree of the network attack data.
[0061] This application further provides an electronic device, which includes: a memory, a processor, and a program of the attack tree construction method stored on the memory and executable on the processor. When the program of the attack tree construction method is executed by the processor, the steps of the attack tree construction method as described above can be implemented.
[0062] This application further provides a computer - readable storage medium, on which a program for implementing the attack tree construction method is stored. When the program of the attack tree construction method is executed by a processor, the steps of the attack tree construction method as described above are implemented.
[0063] This application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the attack tree construction method as described above are implemented.
[0064] The present application provides a method, apparatus, electronic device, and readable storage medium for constructing an attack tree. Compared with the method of manually constructing an attack tree by professionals based on network attack data, the present application obtains network attack data; selects a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data; determines attack information corresponding to the network attack data according to the target attack matrix framework; constructs an attack tree of the network attack data according to the attack information, realizes the execution of a unified attack matrix framework for network attack data of the same application object type, thereby determining attack information according to the attack matrix framework, and then constructing an attack tree according to the attack information, so that the constructed attack tree is always unique, avoiding the technical defect that different professionals may construct significantly different attack trees for the same network attack data, and thus reducing the usage limitations of the attack tree. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application and, together with the specification, are used to explain the principles of the present application.
[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present application or in the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0067] Figure 1 It is a schematic flowchart of the first embodiment of the attack tree construction method of the present application;
[0068] Figure 2 It is a tabular representation form of an attack profile in an embodiment of the present application;
[0069] Figure 3 It is a flow example diagram for generating an attack action in an embodiment of the present application;
[0070] Figure 4 It is a mapping diagram between each attack point in the attack type enumeration and classification database and the attack point identifier and attack point name in an embodiment of the present application;
[0071] Figure 5 It is an example mapping diagram when the mapping relationship between the preset attack action and the preset attack weapon is a mapping table in an embodiment of the present application;
[0072] Figure 6 It is a schematic structural diagram of an attack tree in an embodiment of the present application;
[0073] Figure 7This is a schematic diagram of the device structure of the hardware operating environment involved in the attack tree construction method in the embodiments of the present application.
[0074] The implementation, functional characteristics, and advantages of the present application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. Detailed implementation manners
[0075] To make the above objects, features, and advantages of the present application more clearly understood, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0076] Embodiment 1
[0077] The embodiments of the present application provide an attack tree construction method. In the first embodiment of the attack tree construction method of the present application, with reference to Figure 1 , the attack tree construction method includes:
[0078] Step S10, obtaining network attack data;
[0079] Step S20, selecting a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data;
[0080] Step S30, determining attack information corresponding to the network attack data according to the target attack matrix framework;
[0081] Step S40, constructing an attack tree of the network attack data according to the attack information.
[0082] In this embodiment, it should be noted that the network attack data is data carrying network threat event information, and the network threat event is a threat event generated by an attack on an individual or an organization. The application object type is the type corresponding to the application object of the network attack data, and the application object type can be an enterprise-level network type, an industrial control system type, a mobile Internet type, or other types. The target attack matrix framework is information carrying the attack characteristics of the network attack data selected as the attack information corresponding to the network attack data. The attack tree is a tree-shaped structure for describing the security threat information of network attack data.
[0083] Exemplarily, steps S10 to S40 include: obtaining network attack data; determining the application object type corresponding to the network attack data, and selecting the target attack matrix framework corresponding to the network attack data according to the application object type; determining the attack information corresponding to the network attack data according to the target attack matrix framework; and constructing an attack tree for the network attack data according to the attack information.
[0084] As an example, step S20 includes: obtaining an attack matrix framework library, where the attack matrix framework library includes the correspondence between each application object type and the attack matrix framework; querying the attack matrix framework library according to the application object type to obtain the target attack matrix framework corresponding to the network attack data. For example, when the application object type is an enterprise-level network type, framework A is selected as the target attack matrix framework; when the application object type is an industrial control system type, framework B is selected as the target attack matrix framework; when the application object type is a mobile Internet type, framework C is selected as the target attack matrix framework.
[0085] Among them, in step S30, the attack information includes at least one of an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon. The step of determining the attack information corresponding to the network attack data includes:
[0086] Step S31, determining the attack target corresponding to the network attack data according to the application object type corresponding to the network attack data; and / or,
[0087] Exemplarily, step S31 includes: analyzing the potential attack target of the network attack data according to the application object type corresponding to the network attack data to obtain the attack target corresponding to the network attack data.
[0088] Step S32, querying in the target attack matrix framework to obtain the attack tactics corresponding to each of the attack targets according to the attack target corresponding to the network attack data; and / or,
[0089] In this embodiment, it should be noted that the attack matrix framework includes the attack tactics corresponding to each attack target.
[0090] Exemplarily, step S32 includes: querying in the target attack matrix framework to obtain the attack tactics matching the attack target according to the attack target corresponding to the network attack data.
[0091] Step S33, constructing an attack profile for each of the attack tactics according to the network attack data, where the attack profile includes at least one attack point; and / or,
[0092] In this embodiment, it should be noted that the attack profile is used to characterize the attack features of attack tactics. The attack profile includes attack points, basic elements, sub-elements, and attack point identifiers. The attack point identifier is used to characterize the identity identifier of each attack point, and the attack point identifier can be an attack point ID (Identity document, identification number).
[0093] Exemplarily, step S33 includes: analyzing the application object corresponding to the network attack data according to the network attack data to obtain the basic elements, sub-elements under each basic element, and attack points in each sub-element, and querying a preset attack knowledge base according to each attack point to obtain the attack point identifier corresponding to each attack point. The preset attack knowledge base is a pre-set database containing various attack points and corresponding attack point identifiers. The preset attack knowledge base can be a CAPEC library (Common Attack Pattern Enumeration and Classification, attack pattern enumeration and classification database), or a website that collects attack data. For example, the MITRE website released by the MITRE Corporation.
[0094] As an example, referring to Figure 2 , Figure 2 is a tabular representation form of the attack profile in the embodiment of the present application, Figure 2 including: basic elements, sub-elements (illustrated element subcategories), attack points (illustrated potential attack points), and attack point identifiers (illustrated attack point IDs). The application objects corresponding to the network attack data include basic elements such as software terminals and hardware terminals. The software terminal includes sub-elements such as operating systems, databases, middleware, application software, WEB applications, and firmware. The hardware terminal includes sub-elements such as servers, routers, firewalls, VPNs, hardware interfaces, peripheral interfaces, and sensing interfaces. The operating system includes attack points such as attack point 1 and attack point 2, and the database includes attack point n.
[0095] Step S34, generating at least one attack action for each of the attack points according to the target attack matrix framework; and / or,
[0096] Exemplarily, step S34 includes: querying the target attack matrix framework according to each of the attack points to obtain at least one attack action.
[0097] Among them, in step S34, the step of generating at least one attack action for each of the attack points according to the target attack matrix framework includes:
[0098] Step A10, reading the attack attributes corresponding to each of the attack points, where the attack attributes include state flow attributes and non-state flow attributes;
[0099] Step A20: If the attack attribute is the state flow attribute, generate the attack action according to the technologies in each of the attack points.
[0100] Step A30: If the attack attribute is the non-state flow attribute, query the target attack matrix framework according to the attack point to obtain a query result, and generate the attack action according to the query result.
[0101] Exemplarily, Steps A10 to A30: Query a preset attack knowledge base according to each of the attack points to obtain the attack attribute corresponding to each of the attack points; if the attack attribute is the state flow attribute, generate the attack action according to the technologies in each of the attack points; if the attack attribute is the non-state flow attribute, query the target attack matrix framework according to the attack point to obtain a query result, and generate the attack action according to the query result.
[0102] Among them, in Step A30, the query result includes an existing classification mapping and a non-existing classification mapping. The step of generating the attack action according to the query result includes:
[0103] Step A31: If the query result is the existing classification mapping, extract the technical names and technical identifiers of each of the attack points, and generate the attack action according to the technical names and the technical identifiers.
[0104] Step A32: If the query result is the non-existing classification mapping, display the attack point for a professional to judge and obtain a human judgment attack action according to the attack point, and use the human judgment attack action as the attack action.
[0105] As an example, refer to Figure 3 , Figure 3This is a flowchart example for generating attack actions in an embodiment of the present application. The query results also include the existence of an attack mapping (the ATTACK mapping shown in the figure), the non - existence of an attack mapping, the existence of a relative attack pattern (the Ralated_Attack_Patterns shown in the figure), the non - existence of a relative attack pattern, a subset relationship (the ChildOf relationship shown in the figure), and a non - subset relationship. Steps A31 to A32 include: determining whether there is a classification mapping (the Taxonomy_Mapping shown in the figure) in the query results. If the query result is the existence of a classification mapping, then determining whether the query result is the existence of an attack mapping. If the query result is the existence of an attack mapping, then extracting the technical names and technical identifiers of each attack point, and generating the attack action according to the technical names and the technical identifiers. If the query result is the non - existence of a classification mapping or the non - existence of an attack mapping, then determining whether the query result is the existence of a relative attack pattern. If the query result is the existence of a relative attack pattern, then determining whether the query result is a subset relationship. If the query result is a subset relationship, then extracting the attack point identifiers of each attack point in the attack type enumeration and classification database, and returning to execute the step: reading the attack attributes corresponding to each attack point. If the query result is a non - subset relationship or the non - existence of a relative attack pattern, then displaying the attack points for professionals to judge the artificial judgment attack action according to the attack points, and using the artificial judgment attack action as the attack action.
[0106] As an example, refer to Figure 4 , Figure 4 This is a mapping diagram between each attack point, attack point identifier, and attack point name in the attack type enumeration and classification database in an embodiment of the present application. Figure 4 It includes: attack points (the attack point 1, attack point 2, attack point 3,..., attack point n shown in the figure), attack point identifiers (the Attack_Pattern_ID shown in the figure), and attack point names (the Attack_Pattern_Name shown in the figure). Attack point 1 corresponds to Name3 and ID3, attack point 1 corresponds to Name3 and ID3, attack point 1 corresponds to Name2 and ID2, attack point 2 corresponds to Name3 and ID3, and attack point 3 corresponds to Name1 and ID1.
[0107] Step S35, determining at least one attack weapon corresponding to each attack action.
[0108] Exemplarily, step S35 includes: querying the attack mode enumeration and classification database according to each attack action to obtain the corresponding at least one attack weapon.
[0109] The embodiment of the present application provides a method for constructing an attack tree. Compared with the method of manually constructing an attack tree by professionals based on network attack data, the embodiment of the present application obtains network attack data; selects a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data; determines the attack information corresponding to the network attack data according to the target attack matrix framework; constructs an attack tree for the network attack data according to the attack information, realizes the execution of a unified attack matrix framework for network attack data of the same application object type, thereby determining attack information according to the attack matrix framework, and then constructing an attack tree according to the attack information, so that the constructed attack tree is always unique, avoiding the technical defect that different professionals may construct significantly different attack trees for the same network attack data, thereby reducing the usage limitation of the attack tree.
[0110] Embodiment 2
[0111] Further, referring to Figure 2 , based on the first embodiment of the present application, in another embodiment of the present application, the same or similar content as in the above-mentioned Embodiment 1 can be referred to the above introduction and will not be repeated hereinafter. On this basis, in step S35, the step of determining at least one attack weapon corresponding to each of the attack actions includes:
[0112] Step B10, obtaining the mapping relationship between preset attack actions and preset attack weapons;
[0113] Step B20, mapping each of the attack actions to an attack weapon through the mapping relationship.
[0114] As an example, steps B10 to B20 include: obtaining the mapping relationship between preset attack actions and preset attack weapons, where the mapping relationship is a mapping table; querying the mapping table according to each of the attack actions to obtain attack weapons.
[0115] As an example, referring to Figure 5 , Figure 5 is an example diagram of the mapping relationship when the mapping relationship between preset attack actions and preset attack weapons is a mapping table in the embodiment of the present application, Figure 5 including: preset attack actions (attack action 1 shown in the figure) and preset attack weapons (attack weapons shown in the figure), and the attack weapons corresponding to attack action 1 are the attack weapon with number 1-1 and name 1, the attack weapon with number 1-2 and name 2,...
[0116] Among them, in step B10, before the step of obtaining the mapping relationship between preset attack actions and preset attack weapons, it further includes:
[0117] Step C10, obtain the attack mode enumeration and classification database;
[0118] Step C20, parse the technologies and sub - technologies in the attack mode enumeration and classification database, and use each of the technologies and each of the sub - technologies as the preset attack actions;
[0119] Step C30, determine the preset attack weapons corresponding to each of the preset attack actions, and construct a mapping relationship between the preset attack actions and the preset attack weapons.
[0120] Among them, in step S40, the attack information includes an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon. The step of constructing an attack tree for the network attack data according to the attack information includes:
[0121] Step S41, construct a first connection channel between the attack target and the attack tactic corresponding to the attack target, construct a second connection channel between each attack tactic and the attack profile corresponding to each attack tactic, construct a third connection channel between each attack profile and the attack points included in each attack profile, construct a fourth connection channel between each attack point and the attack action corresponding to each attack point, and construct a fifth connection channel between each attack action and the attack weapon corresponding to each attack action, to obtain the attack tree of the network attack data.
[0122] As an example, refer to Figure 6 , Figure 6 which is a schematic structural diagram of an attack tree in an embodiment of the present application, Figure 6 including: an attack target, an attack tactic, an attack profile, an attack point (the potential attack point shown in the figure), an attack action, and an attack weapon. There is a first connection channel between the attack target and the attack tactic, a second connection channel between the attack tactic and the attack profile, a third connection channel between the attack profile and the attack point, a fourth connection channel between the attack point and the attack action, and a fifth connection channel between the attack action and the attack weapon.
[0123] The embodiment of the present application provides a method for constructing an attack tree. Compared with the method of manually constructing an attack tree by professionals based on network attack data, the embodiment of the present application obtains network attack data; selects a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data; determines the attack information corresponding to the network attack data according to the target attack matrix framework; constructs an attack tree of the network attack data according to the attack information, realizes the execution of a unified attack matrix framework for network attack data of the same application object type, thereby determining attack information according to the attack matrix framework, and then constructing an attack tree according to the attack information, so that the constructed attack tree is always unique, avoiding the technical defect that different professionals may construct significantly different attack trees for the same network attack data, thereby reducing the usage limitations of the attack tree.
[0124] Embodiment III
[0125] The embodiment of the present application further provides an attack tree construction device, and the attack tree construction device includes:
[0126] An acquisition module, configured to acquire network attack data;
[0127] A selection module, configured to select a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data;
[0128] A determination module, configured to determine the attack information corresponding to the network attack data according to the target attack matrix framework;
[0129] A construction module, configured to construct an attack tree of the network attack data according to the attack information.
[0130] Optionally, the attack information includes at least one of an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon, and the determination module is further configured to:
[0131] Determine the attack target corresponding to the network attack data according to the application object type corresponding to the network attack data; and / or,
[0132] Query the attack tactics corresponding to each of the attack targets in the target attack matrix framework according to the attack target corresponding to the network attack data; and / or,
[0133] Construct an attack profile for each of the attack tactics according to the network attack data, where at least one attack point is included in the attack profile; and / or,
[0134] Generate at least one attack action for each of the attack points according to the target attack matrix framework; and / or,
[0135] Determine at least one attack weapon corresponding to each of the attack actions.
[0136] Optionally, the determining module is further configured to:
[0137] Read the attack attributes corresponding to each of the attack points, where the attack attributes include state flow attributes and non-state flow attributes;
[0138] If the attack attribute is the state flow attribute, generate the attack action according to the technology in each of the attack points;
[0139] If the attack attribute is the non-state flow attribute, query the target attack matrix framework according to the attack point to obtain a query result, and generate the attack action according to the query result.
[0140] Optionally, the query result includes an existing classification mapping and a non-existing classification mapping, and the determining module is further configured to:
[0141] If the query result is the existing classification mapping, extract the technology names and technology identifiers of each of the attack points, and generate the attack action according to the technology names and the technology identifiers;
[0142] If the query result is the non-existing classification mapping, display the attack point for a professional to judge an artificial judgment attack action according to the attack point, and use the artificial judgment attack action as the attack action.
[0143] Optionally, the determining module is further configured to:
[0144] Obtain the mapping relationship between the preset attack actions and the preset attack weapons;
[0145] Map each of the attack actions to an attack weapon through the mapping relationship.
[0146] Optionally, before the step of obtaining the mapping relationship between the preset attack actions and the preset attack weapons, the attack tree construction device is further configured to:
[0147] Obtain the attack mode enumeration and classification database;
[0148] Parse the technologies and sub-technologies in the attack mode enumeration and classification database, and use each of the technologies and each of the sub-technologies as the preset attack actions;
[0149] Determine the preset attack weapons corresponding to each of the preset attack actions, and construct the mapping relationship between the preset attack actions and the preset attack weapons.
[0150] Optionally, the attack information includes an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon, and the attack tree construction device is further configured to:
[0151] Construct a first connection channel between the attack target and the attack tactic corresponding to the attack target, construct a second connection channel between each attack tactic and the attack profile corresponding to each attack tactic, construct a third connection channel between each attack profile and the attack points included in each attack profile, construct a fourth connection channel between each attack point and the attack action corresponding to each attack point, and construct a fifth connection channel between each attack action and the attack weapon corresponding to each attack action, to obtain an attack tree of the network attack data.
[0152] The attack tree construction device provided by this application adopts the attack tree construction method in the above embodiment, and solves the technical problem of relatively high limitations in the use of the attack tree. Compared with the prior art, the beneficial effects of the attack tree construction device provided by the embodiments of this application are the same as those of the attack tree construction method provided by the above embodiment, and other technical features in this attack tree construction device are the same as the features disclosed in the method of the above embodiment, and will not be elaborated here.
[0153] Embodiment 4
[0154] The embodiments of this application provide an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the attack tree construction method in the above embodiment.
[0155] Next, refer to Figure 7 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. The electronic device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (tablet computers), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The electronic device shown is only an example, and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0156] As Figure 7As shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the program stored in the ROM (Read-Only Memory) or the program loaded from the storage device into the RAM (Random Access Memory). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, the ROM, and the RAM are connected to each other via a bus. The input / output (I / O) interface is also connected to the bus.
[0157] Generally, the following systems may be connected to the I / O interface: input devices including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device with various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be implemented or had alternatively.
[0158] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from the network via the communication device, or installed from the storage device, or installed from the ROM. When the computer program is executed by the processing device, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0159] The electronic device provided in this application adopts the attack tree construction method in the above embodiment, and solves the technical problem of relatively high limitations in the use of the attack tree. Compared with the prior art, the beneficial effects of the electronic device provided in the embodiment of this application are the same as those of the attack tree construction method provided in the above embodiment, and the other technical features in this electronic device are the same as those disclosed in the method of the above embodiment, and will not be elaborated here.
[0160] It should be understood that each part of the present disclosure may be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in a suitable manner in any one or more embodiments or examples.
[0161] As described above, this is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.
[0162] Embodiment 5
[0163] This embodiment provides a computer-readable storage medium having computer-readable program instructions stored thereon, and the computer-readable program instructions are used to execute the method for constructing an attack tree in the above-mentioned embodiment.
[0164] The computer-readable storage medium provided by the embodiment of the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a RAM, a ROM, an EPROM (Erasable Programmable Read Only Memory), or a flash memory, an optical fiber, a CD-ROM (compact disc read-only memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0165] The above-mentioned computer-readable storage medium may be included in an electronic device; or it may exist separately without being assembled into the electronic device.
[0166] The above-mentioned computer-readable storage medium carries one or more programs. When the one or more programs are executed by an electronic device, the electronic device is caused to: obtain network attack data; select a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data; determine attack information corresponding to the network attack data according to the target attack matrix framework; and construct an attack tree for the network attack data according to the attack information.
[0167] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a LAN (Local Area Network) or a WAN (Wide Area Network), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0168] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0169] The modules described in the embodiments of the present disclosure may be implemented in software or in hardware. In some cases, the name of the module does not constitute a limitation on the unit itself.
[0170] The computer-readable storage medium provided by the present application stores computer-readable program instructions for performing the above-mentioned attack tree construction method, which solves the technical problem of relatively high limitations in the use of attack trees. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the embodiments of the present application are the same as those of the attack tree construction method provided in the above embodiments, and will not be elaborated herein.
[0171] Embodiment Six
[0172] The present application also provides a computer program product, including a computer program, which when executed by a processor, implements the steps of the attack tree construction method as described above.
[0173] The computer program product provided by the present application solves the technical problem of relatively high limitations in the use of attack trees. Compared with the prior art, the beneficial effects of the computer program product provided by the embodiments of the present application are the same as those of the attack tree construction method provided by the above embodiments, and will not be elaborated here.
[0174] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application accordingly. Any equivalent structural or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied to other related technical fields, shall be equally included in the patent scope of the present application.
Claims
1. A method for constructing an attack tree, characterized in that, The method for constructing an attack tree includes: Obtaining network attack data; Selecting a target attack matrix framework corresponding to the network attack data according to the type of application object corresponding to the network attack data; Determining attack information corresponding to the network attack data according to the target attack matrix framework, where the attack information includes attack targets, attack tactics, attack profiles, attack points, attack actions, and attack weapons; Constructing a first connection channel between the attack target and the attack tactics corresponding to the attack target, a second connection channel between each attack tactic and the attack profile corresponding to each attack tactic, a third connection channel between each attack profile and the attack points included in each attack profile, a fourth connection channel between each attack point and the attack action corresponding to each attack point, and a fifth connection channel between each attack action and the attack weapon corresponding to each attack action to obtain the attack tree of the network attack data.
2. The attack tree construction method according to claim 1, wherein The step of determining the attack information corresponding to the network attack data includes: Determining the attack target corresponding to the network attack data according to the type of application object corresponding to the network attack data; and / or, Querying the target attack matrix framework according to the attack target corresponding to the network attack data to obtain the attack tactics corresponding to each attack target; and / or, Constructing an attack profile for each attack tactic according to the network attack data, where the attack profile includes at least one attack point; and / or, Generating at least one attack action for each attack point according to the target attack matrix framework; and / or, Determining at least one attack weapon corresponding to each attack action.
3. The attack tree construction method according to claim 2, wherein, The step of generating at least one attack action for each attack point according to the target attack matrix framework includes: Reading the attack attributes corresponding to each attack point, where the attack attributes include state flow attributes and non-state flow attributes; If the attack attribute is the state flow attribute, generating the attack action according to the technology in each attack point; If the attack attribute is the non-state flow attribute, querying the target attack matrix framework according to the attack point to obtain a query result, and generating the attack action according to the query result.
4. The attack tree construction method according to claim 3, wherein The query result includes an existing classification mapping and a non-existing classification mapping. The step of generating the attack action according to the query result includes: If the query result is the existing classification mapping, extracting the technical name and technical identifier of each attack point, and generating the attack action according to the technical name and the technical identifier; If the query result is the non-existing classification mapping, displaying the attack point for professionals to judge the human judgment attack action according to the attack point, and using the human judgment attack action as the attack action.
5. The attack tree construction method according to claim 2, wherein The step of determining at least one attack weapon corresponding to each attack action includes: Obtaining the mapping relationship between preset attack actions and preset attack weapons; Mapping each attack action to an attack weapon through the mapping relationship.
6. The attack tree construction method according to claim 5, characterized in that Before the step of obtaining the mapping relationship between the preset attack actions and the preset attack weapons, the following steps are further included: Obtain an attack mode enumeration and classification database; Parse the technologies and sub-technologies in the attack mode enumeration and classification database, and use each of the technologies and each of the sub-technologies as the preset attack actions; Determine the preset attack weapons corresponding to each of the preset attack actions, and construct the mapping relationship between the preset attack actions and the preset attack weapons.
7. An attack tree construction device, characterized in that The attack tree construction device includes: An acquisition module, configured to acquire network attack data; A selection module, configured to select a target attack matrix framework corresponding to the network attack data according to the application object type corresponding to the network attack data; A determination module, configured to determine the attack information corresponding to the network attack data according to the target attack matrix framework, where the attack information includes an attack target, an attack tactic, an attack profile, an attack point, an attack action, and an attack weapon; A construction module, configured to construct a first connection channel between the attack target and the attack tactic corresponding to the attack target, construct a second connection channel between each attack tactic and the attack profile corresponding to each attack tactic, construct a third connection channel between each attack profile and the attack points included in each attack profile, construct a fourth connection channel between each attack point and the attack action corresponding to each attack point, and construct a fifth connection channel between each attack action and the attack weapon corresponding to each attack action, to obtain the attack tree of the network attack data.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the steps of the attack tree construction method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, A program for implementing the attack tree construction method is stored on the computer-readable storage medium, and the program for implementing the attack tree construction method is executed by a processor to implement the steps of the attack tree construction method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Modeling method and device of attack tree, electronic equipment and readable storage medium
CN115484105A