A method for APT attack detection and analysis based on connected subgraphs
By constructing a graph showing the relationship between attack sources and targets, and combining it with attack behavior analysis, the information gap problem in existing APT attack identification methods has been solved, enabling a global assessment and correlation analysis of APT attack events.
Patent Information
- Application Number
- CN202310285281.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-22
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2043-03-22
AI Technical Summary
In the existing field of mobile network security, APT attack identification methods lack the ability to analyze the correlation between attack events and cannot provide a comprehensive global description of the attack source and the attack target, resulting in information gaps.
By constructing an attack source relationship diagram and an attack target relationship diagram, the organization and hostility of the attack source, the importance and directionality of the attack target are calculated. Combined with the cost and harm of the attack behavior, an APT attack element diagram is formed to comprehensively assess the likelihood of APT attack behavior.
It enables correlation analysis of APT attack events, comprehensively assesses the multi-point correspondence between attack source groups and target groups, and provides a comprehensive judgment capability for APT attack behavior.
Smart Images

Figure CN116319008B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mobile network security technology, and in particular to an APT attack detection and analysis method based on connected subgraphs. Background Technology
[0002] Currently, attacks targeting or exploiting the mobile internet are occurring constantly. However, their attack methods and intentions differ significantly from those of the traditional internet. Among these, mobile internet APT attacks pose a significant threat, and identifying suspicious APT attacks from a large number of mobile internet attack incidents is of paramount importance.
[0003] In the current field of mobile network security, existing APT identification methods are basically based on the characteristics of each independent attack event. While these methods clearly demonstrate the attack events themselves, they do not address the relationships between attack events, nor do they provide any global description of the attack source or target. Therefore, it can be said that existing APT identification methods, apart from displaying information about the attack events themselves, leave all other information as unknown gaps, and they cannot provide a comprehensive analysis of APT attack events.
[0004] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0005] The purpose of this invention is to overcome the shortcomings of the prior art and provide an APT attack detection and analysis method based on connected subgraphs, which solves the deficiencies of existing APT detection methods.
[0006] The objective of this invention is achieved through the following technical solution: an APT attack detection and analysis method based on connected subgraphs, the detection and analysis method comprising:
[0007] Attack source relationship graph construction steps: Extract attack source information of attack behavior from attack events and construct attack source relationship network, and calculate the attack source value of comprehensive attack source organization and hostility;
[0008] Attack object relationship graph construction steps: Extract attack object information from attack events and construct an attack object relationship network, and calculate the attack object value that combines the importance and directionality of the attack objects;
[0009] APT attack element graph construction steps: Construct an APT attack element graph by attack behavior, attack source relationship graph and attack target relationship graph, and calculate the attack behavior value of comprehensive attack behavior cost and harm.
[0010] Judgment steps: Based on the weights of the attack source value, attack target value, and attack behavior value, the final evaluation value of the attack event is obtained, and the likelihood of it being an APT attack behavior is determined.
[0011] The specific steps for constructing the attack source relationship graph include:
[0012] A1. Extract the attack source information of the attack behavior from a set of attack events, and mine the attribute information of the attack source through the data center based on the attack source information.
[0013] A2. Analyze the attribute information of the attack sources, find the common attributes among the attack sources, connect the independent attack sources through attributes, and construct an attack source relationship diagram.
[0014] A3. Based on the parameters in the attack source relationship diagram, calculate the attack source value that combines the organization and hostility of the attack source.
[0015] 3. The APT attack determination and analysis method based on connected subgraphs according to claim 1, characterized in that: the attack object relationship graph construction step specifically includes:
[0016] B1. Extract the attack target information from a set of attack events, and mine the attribute information of the attack target through the data center based on the attack target information;
[0017] B2. Analyze the attribute information of the attack targets, compare the related attributes, find the common attributes between the attack targets, and construct the attack target relationship diagram;
[0018] B3. Based on the parameters in the attack target relationship diagram, calculate the attack target value that combines the importance and directionality of the attack target.
[0019] The specific steps for constructing an APT attack feature map include:
[0020] C1. By connecting the vertices in the attack source relationship graph and the attack target relationship graph through the edges represented by the attack behavior, a complete APT attack element graph is constructed.
[0021] C2. Based on the parameters in the APT attack element diagram, calculate the attack behavior value that combines the attack cost and harm of the overall attack behavior.
[0022] Constructing the attack source relationship graph involves: using a set of attack events detected over a period of time as an attack event database; acquiring and mining attack source intelligence information from the attack event database to provide correlation characteristics between attack sources; using attack sources and attack source attributes as vertices and the relationships between attack sources and attack source attributes as edges; mining potential connections between attack sources by analyzing attack behavior characteristics; identifying common attributes among attack sources by analyzing attack source attributes; and connecting independent attack sources through attributes to obtain the attack source relationship graph.
[0023] Constructing the attack object relationship graph involves: using attack objects, object attributes, and key objects as vertices, and the relationships between object attributes as edges; mining the relationships between ordinary objects and key objects in the attack event database; comparing the associated attributes of ordinary objects and key objects; finding the same attributes; and thus establishing mutual associations to ultimately form the attack object relationship graph.
[0024] Constructing a complete APT attack element graph involves connecting vertices in the attack source relationship graph and vertices in the attack target relationship graph, and connecting the attack source relationship graph and the attack target relationship graph through edges representing attack events to form a complete APT attack element graph.
[0025] The calculated attack source values, which combine the organizational and hostile aspects of the attack source, include:
[0026] Set the total number of attack sources to The number of attribute associations between attack sources is The attribute correlation strength evaluation value is The formula for calculating the attack source organization index is as follows: ,in, ; The coefficients used for normalization;
[0027] The attack source is weighted according to the probability that it belongs to the opposing camp and the degree of hostility of the camp, resulting in different levels of hostility values. The calculation formula for the attack source value is obtained by combining hostility and organization: .
[0028] The calculated attack target values, which combine the importance and direction of the attack target, include:
[0029] Set the number of directly included important objects to The number of important related objects is The direct importance level value is The relevant important object level value is The formula for calculating the importance value of the attack target is as follows: ;
[0030] Set the total number of attack targets to The number of attribute associations between attack targets is The attribute correlation strength evaluation value is The formula for calculating the target orientation value is: ,in, ;
[0031] The following can be obtained by combining the importance value and the targeting value of the target: .
[0032] This invention has the following advantages: an APT attack determination and analysis method based on connected subgraphs, which can analyze the multi-point correspondence between the attack source group and the target group, establish an attack correlation graph, propose a comprehensive evaluation method to determine APT attack behavior, and solve the needs for correlation analysis of APT attack events and the needs for analysis of organized and targeted attacks in APT attacks. Attached Figure Description
[0033] Figure 1 This is a schematic diagram illustrating the attack source relationship of the present invention;
[0034] Figure 2 Example diagram of the relationship between attack sources;
[0035] Figure 3 An example diagram illustrating an attack source;
[0036] Figure 4 This is a schematic diagram illustrating the relationship between the attack targets of the present invention;
[0037] Figure 5 This is a complete schematic diagram of the APT attack elements of this invention. Detailed Implementation
[0038] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of this application provided below with reference to the accompanying drawings is not intended to limit the scope of protection of the claimed application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application. The present invention will be further described below with reference to the accompanying drawings.
[0039] This invention proposes an analytical method for APT attack identification using graph theory. It analyzes the multi-point correspondence between the attack source group and the target group, establishes an attack correlation graph, and proposes a comprehensive evaluation method to determine APT attack behavior. Specifically, it includes the following:
[0040] S1: Extract the attack source information of the attack behavior from a set of attack events. Based on the attack source information, mine the attribute information of the attack source through the data center and transfer to S2.
[0041] S2: By comprehensively analyzing the attribute information of the attack sources and identifying the same, similar, and close attributes among the attack sources, the independent attack sources can be linked together through attributes to construct an attack source relationship diagram. Proceed to S3.
[0042] S3: Based on the parameters of the attack source relationship network in S2, calculate the comprehensive attack source value of the attack source organization and hostility, and then proceed to S4;
[0043] S4: Extract the attack target information from a set of attack events, and based on the attack target information, mine the attribute information of the attack target through the data center, and then transfer to S5;
[0044] S5: Analyze the attribute information of the attack targets, compare the related attributes, find the same, similar and close attributes, construct the attack target relationship diagram, and go to S6;
[0045] S6: Based on the parameters of the attack target relationship network in S5, calculate the comprehensive attack target value of the importance and direction of the attack target, and then proceed to S7;
[0046] S7: Connect the vertices in the attack source relationship graph and the attack target relationship graph through the edges represented by the attack behavior to construct a complete APT attack element graph, then proceed to S8;
[0047] S8: Based on the APT attack element diagram in S7, calculate the comprehensive attack behavior value, including attack cost and harm, and proceed to S9:
[0048] S9: Based on the weights of the attack source value, attack target value, and attack behavior value, the final evaluation value of this group of attack events is obtained, and the probability of it being an APT attack behavior is determined.
[0049] Furthermore, such as Figure 1As shown, the attack sources in the graph are represented by two types of vertices: attack sources and attack source attributes. The relationships between attack sources and their attributes are represented by edges. Attack sources in the attack event database (a set of attack events detected over a period of time) are all independent objects. Then, specialized methods are used to acquire and mine attack source intelligence information to provide information on attack source correlation characteristics. Besides mining information about the attack sources themselves, analyzing attack behavior characteristics can also uncover potential connections between attack sources. By analyzing attack source attributes and identifying the common, similar, and related attributes among the attack sources, independent attack sources can be linked together through these attributes, thus constructing an attack source relationship graph.
[0050] The mineable information of attack source intelligence is referenced in Table 1. Attack source intelligence mining involves obtaining relevant attributes from data centers, network monitoring agencies, network security agencies, or exposed attack source information. The aim is to link different attack sources through similar or related attributes. Based on the actual attack source-related data obtained, the depth of intelligence detection can be adjusted to discover clues linking attack sources, such as... Figure 2 As shown in the example, this is a schematic diagram of a two-layer depth attack source intelligence detection based on the attack source email. Attack source A is an email, and different relevant information is obtained through different channels according to its usage characteristics.
[0051] Table 1. Attack Source Information Mining
[0052]
[0053] Information can be mined from attack behavior characteristics, as shown in Table 2. Analyzing these characteristics can uncover potential connections between attack sources. Some key characteristics can even directly indicate the shared identity of the attackers, such as different attacks employing a unique attack technique. Attack behavior characteristics are often analyzed during the attack detection phase and are readily available. As shown in Figure 3, the attack source exploited the same vulnerability in both attacks. This vulnerability can serve as a key characteristic of this attack method, thus establishing a connection with other attack sources.
[0054] Table 2. Characteristics of Attack Behavior
[0055]
[0056] By acquiring the attributes of attack sources and analyzing their attack behavior characteristics, and identifying the common, similar, and related attributes among the attack sources, independent attack sources can be linked together through these attributes, thereby constructing an attack source relationship graph, such as... Figure 1 As shown, the attack source is influenced by two factors: organization and hostility, when making a comprehensive judgment.
[0057] Organization refers to the interrelationships between multiple attack sources, reflecting the planning and organization of the attack. Higher levels of planning and organization increase the likelihood of an APT attack. The total number of attack sources. The number of attribute associations between attack sources. The formula for calculating the attack source organization value index, which is the attribute association tightness evaluation value, is as follows:
[0058]
[0059] in, ; These are the coefficients used for normalization, which are used to adjust the growth rate of the normalization curve. The larger the value, the slower the function value grows. The value can be adjusted according to specific circumstances, and its impact on the function value is as follows: , The larger the value, the closer the relationship and the higher the consistency between the two sources. When it is determined that the two sources are the same object, , The value is given by the evaluation value of the relevant attributes. Attributes with obvious uniqueness are assigned a value of 1, key attributes 0.75, ordinary attributes 0.5, and attributes with uncertain performance are assigned a value of 0.25. Hostility refers to the probability that the attack source belongs to an opposing faction and the degree of hostility between the factions. The stronger the hostility, the greater the likelihood of an APT attack. Hostility is determined by known background knowledge: a value of 1 for a known faction with very high hostility; 0.7 for a known moderately hostile faction; 0.3 for weak hostility; 0 for a known non-hostile faction; and a default value of 0.5 for unknown hostility. The hostility index for multiple attack sources is determined by the maximum value of the hostility of each attack source.
[0060] The combined hostility and organization indicators yielded the quantified APT (Aggressive Persistent Threat) index of the attack source:
[0061]
[0062] like Figure 4As shown, the attack targets in the graph are represented by three types of vertices: attack targets, object attributes, and key targets. The relationships between object attributes are represented by edges. While obtaining information about attack targets is relatively easy, it also significantly increases the amount of data. Therefore, it is necessary to select and control the depth of the mining. Attack target mining is divided into ordinary object mining and key object mining. Ordinary objects refer to all attacked objects in the attack event database; without any specific designation, ordinary objects can be considered to have low importance. Key object mining includes not only the object itself but also its related personnel and resources, thereby discovering APT attacks that attempt to approach but have not yet touched key targets. After object relationship mining and key object relationship mining, the associated attributes of objects and key objects are compared to identify their identical, similar, and near-identical attributes, thus establishing mutual relationships and ultimately forming an attack target relationship graph. The comprehensive judgment is influenced by two factors: importance and directionality.
[0063] The importance of an attack target reflects the targeting of the attack; the higher the target's importance, the stronger the targeting, and the higher the probability of an APT attack. The importance of an attack target is determined by the number of important targets within the target group, the number of related important targets within the target group, and the importance level of the targets. Let the number of targets directly containing important targets be denoted as... The number of important related objects is The direct importance level value is The relevant important object level value is The expression for calculating the object importance value index is:
[0064]
[0065] The importance levels are divided into four categories: meaningless objects (value 0), ordinary objects (value 0.25), less important objects (value 0.5), important objects (value 0.75), and very important objects (value 1).
[0066] The targeting of attacks reflects the directionality of multiple attack events. Attack events revolve around related groups of targets. The closer the relationship between these groups, the more consistent the direction of the attacks, the stronger the purposefulness of the attacks, and the higher the likelihood of an APT attack. The quantification method is consistent with the organization of the attack source. The total number of targets attacked. The number of attribute associations between attack targets. The attribute association tightness evaluation value and the attack target directionality index value are:
[0067]
[0068] Combining the importance and targeting values of the attack target:
[0069]
[0070] like Figure 5 As shown, attack behaviors represent the relationships between sources and objects, which are represented by edges connecting source vertices and object vertices in the graph. Once the attack source relationship graph and object relationship graph are constructed, connecting the two graphs with edges representing attack events forms a complete APT attack element graph. Each attack source in the attack source relationship network is associated with a corresponding object in the object relationship network through its attack behaviors, establishing a connection between the two networks. The comprehensive judgment is influenced by two factors: attack cost and severity.
[0071] The cost of an attack reflects its purposefulness, including its duration, frequency, variety of attack methods, and technical difficulty. Duration reflects the attacker's time cost, frequency reflects the attacker's implementation cost, and variety (i.e., the types of attack methods) and technical difficulty reflect the attacker's preparation and planning costs.
[0072]
[0073]
[0074] Duration refers to the number of days between the first and last attacks. Duration and number of attacks together represent attack frequency, calculated using a linear formula, with a proportionality coefficient of [value missing]. The technical difficulty is determined by experience analysis, with a value ranging from 0 to 1. The value can be set to 1 for very high difficulty, 0.75 for relatively high difficulty, 0.5 for average difficulty, and 0.25 for low difficulty.
[0075] The harmfulness of an attack is assessed based on the maximum potential damage it may cause to the target, determined by the target's attributes. The minimum harmfulness is 0, indicating no harm; the maximum is 1, indicating serious harm; 0.25 indicates minor harm; 0.5 indicates moderate harm; and 0.75 indicates serious harm.
[0076] The overall cost and harm of the attack behavior are considered in the attack behavior value:
[0077]
[0078] When assessing an APT attack on a set of attack events (considering each individual attack as a special case), i.e., determining the probability that the set of events constitutes an APT attack, the degree to which the overall attack events conform to APT characteristics can be determined by comprehensively evaluating the influencing factors of the three attack elements: attack source, attack behavior, and attack target. By limiting the weights and value ranges of the indicators to [0, 1], the weights and values of the second-level indicators for attack source, attack event, and attack target are calculated using the method described above, thus obtaining the first-level indicator values. Then, expert experience is used to assign weights to the first-level indicators, and the values for attack source, attack event, and attack target are calculated. Finally, the overall assessment value is calculated using the weights assigned by expert experience.
[0079] .
[0080] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.
Claims
1. A method for identifying and analyzing APT attacks based on connected subgraphs, characterized in that: The determination and analysis method includes: Attack source relationship graph construction steps: Extract attack source information of attack behavior from attack events and construct attack source relationship network, and calculate the attack source value of comprehensive attack source organization and hostility; Attack object relationship graph construction steps: Extract attack object information from attack events and construct an attack object relationship network, and calculate the attack object value that combines the importance and directionality of the attack objects; APT attack element graph construction steps: Construct an APT attack element graph by attack behavior, attack source relationship graph and attack target relationship graph, and calculate the attack behavior value of comprehensive attack behavior cost and harm. Judgment steps: Based on the weights of the attack source value, attack target value, and attack behavior value, the final evaluation value of the attack event is obtained, and the probability of it being an APT attack behavior is determined. The calculated attack source value, which combines the organization and hostility of the attack source, includes: Set the total number of attack sources to The number of attribute associations between attack sources is The attribute correlation strength evaluation value is The formula for calculating the attack source organization index is as follows: ,in, ; The coefficients used for normalization; The attack source is weighted according to the probability that it belongs to the opposing camp and the degree of hostility of the camp, resulting in different levels of hostility values. The calculation formula for the attack source value is obtained by combining hostility and organization: ; The calculated attack target values, which combine the importance and direction of the attack target, include: Set the number of directly included important objects to The number of important related objects is The direct importance level value is The relevant important object level value is The formula for calculating the importance value of the attack target is as follows: ; Set the total number of attack targets to The number of attribute associations between attack targets is The attribute correlation strength evaluation value is The formula for calculating the target orientation value is: ,in, ; The following can be obtained by combining the importance value and the targeting value of the target: ; , ; Duration refers to the number of days between the first and last attacks. Duration and number of attacks together represent attack frequency, calculated using a linear formula, with a proportionality coefficient of [value missing]. ; The harmfulness of an attack is assessed based on the maximum damage caused to the target, which is determined by the target's attributes. The minimum harmfulness is 0, indicating no harm; the maximum is 1, indicating serious harm; 0.25 indicates mild harm, 0.5 indicates moderate harm, and 0.75 indicates severe harm. The overall cost and harm of the attack behavior are considered in the attack behavior value: .
2. The APT attack detection and analysis method based on connected subgraphs according to claim 1, characterized in that: The steps for constructing the attack source relationship graph specifically include: A1. Extract the attack source information of the attack behavior from a set of attack events, and mine the attribute information of the attack source through the data center based on the attack source information. A2. Analyze the attribute information of the attack sources, find the common attributes among the attack sources, connect the independent attack sources through attributes, and construct an attack source relationship diagram. A3. Based on the parameters in the attack source relationship diagram, calculate the attack source value that combines the organization and hostility of the attack source.
3. The APT attack detection and analysis method based on connected subgraphs according to claim 1, characterized in that: The steps for constructing the attack target relationship graph specifically include: B1. Extract the attack target information from a set of attack events, and mine the attribute information of the attack target through the data center based on the attack target information; B2. Analyze the attribute information of the attack targets, compare the related attributes, find the common attributes between the attack targets, and construct the attack target relationship diagram; B3. Based on the parameters in the attack target relationship diagram, calculate the attack target value that combines the importance and directionality of the attack target.
4. The APT attack detection and analysis method based on connected subgraphs according to claim 1, characterized in that: The APT attack element graph construction steps specifically include: C1. By connecting the vertices in the attack source relationship graph and the attack target relationship graph through the edges represented by the attack behavior, a complete APT attack element graph is constructed. C2. Based on the parameters in the APT attack element diagram, calculate the attack behavior value that combines the attack cost and harm of the overall attack behavior.
5. The APT attack detection and analysis method based on connected subgraphs according to claim 2, characterized in that: The construction of the attack source relationship graph includes: taking the set of attack events detected within a certain period as an attack event library, acquiring and mining attack source intelligence information in the attack event library to provide the correlation characteristics between attack sources, taking attack sources and attack source attributes as vertices, and the correlation between attack sources and attack source attributes as edges, mining potential connections between attack sources by analyzing attack behavior characteristics, identifying common attributes between attack sources by analyzing attack source attributes, and connecting independent attack sources through attributes to obtain the attack source relationship graph.
6. The APT attack detection and analysis method based on connected subgraphs according to claim 3, characterized in that: The construction of the attack object relationship graph includes: taking the attack object, object attributes, and key objects as vertices, and the relationships between object attributes as edges; mining the relationships between ordinary objects and key objects in the attack event database; comparing the associated attributes of ordinary objects and key objects; finding the same attributes; and thus establishing mutual associations to finally form the attack object relationship graph. Among them, ordinary objects are all attacked objects in the attack event database, and key objects are those that, in addition to the object itself, also include its related personnel and resources.
7. The APT attack detection and analysis method based on connected subgraphs according to claim 4, characterized in that: The construction of a complete APT attack element graph includes: connecting vertices in the attack source relationship graph and vertices in the attack target relationship graph, and connecting the attack source relationship graph and the attack target relationship graph through edges representing attack events to form a complete APT attack element graph.
Citation Information
Patent Citations
Threat source relevance identification processing method and device, electronic equipment and storage medium
CN114024736A
APT attack detection method and device based on knowledge graph
CN114172701A