An attack detection method, device, medium and machine based on abnormal states

By building an attack status migration information collection and monitoring machine behavior, the shortcomings in accuracy and efficiency of existing attack detection technologies are solved, and efficient identification and timely response to unknown attacks are achieved.

CN116389122BActive Publication Date: 2025-07-22NANJING UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310371707.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-10
Publication Date
2025-07-22
Estimated Expiration
2043-04-10

AI Technical Summary

Technical Problem

The existing attack detection technology has insufficient accuracy and efficiency, especially the inability to effectively combine rules-based and abnormal positioning methods, resulting in insufficient recognition of unknown attacks and prone to false alarms.

Method used

By obtaining the text of the attack defect description, parsing and building a collection of attack status migration information, monitoring machine behavior and matching with predefined attack status information, issuing exception status warnings, tracking attack behavior and software vulnerabilities in real time, and updating attack models to deal with new attack methods.

Benefits of technology

It improves the accuracy of attack detection, reduces false alarms, can respond to new attack methods in a timely manner, and achieves effective identification of unknown attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389122B_ABST
    Figure CN116389122B_ABST
Patent Text Reader

Abstract

The present invention discloses an attack detection method, device, medium and machine based on abnormal states. The attack detection method of the present invention is as follows: First, capture the attack defect description text from the Internet, then parse the attack defect description text to obtain a set of attack state transition information. When monitoring the behaviors of the machine executing the operating system and application programs, determine whether the machine is in an abnormal state according to whether the behavior results are consistent with the attack state information in the set of state transition information. When an abnormal state occurs, give a warning of the abnormal state. The present invention has a very high judgment accuracy for determining whether there is an attack by monitoring the transitions between attack states and basically does not generate false alarm problems. In addition, the present invention can track and download the current attack behaviors, attack means, and software vulnerabilities or defects exploited in real time, so that the machine attack model graph samples are kept up-to-date, enabling the machine to timely respond to new attack means.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to computer security technology. Background Art

[0002] With the popularization of the Internet, a large number of devices are connected to the network and use cloud resources, making online services more and more convenient. However, this also brings more threats of cyber attacks to user privacy and enterprise operations. In the current network environment, traditional passive defense technologies such as antivirus software can no longer meet the network security requirements. Especially in recent years, attackers have launched more and more APT (Advanced Persistent Threat) attacks against specific targets. Due to the high degree of participation of attackers, APT attacks are characterized by a long duration of the attack process, high concealment, and fast formation of variants. Therefore, dealing with APT attacks is highly challenging. Thus, active defense measures have emerged to cope with various cyber attacks. Active defense includes strengthening network security management, improving network security prevention capabilities, establishing a perfect security monitoring and early warning mechanism, etc. In contrast, passive defense mainly takes countermeasures after network threats appear. Therefore, active defense has become an essential means to cope with network threats and can more effectively reduce the network security risks of enterprises and individuals.

[0003] Attack detection is an essential part of active defense. At present, attack detection technologies are mainly divided into two categories: rule-based attack detection and anomaly localization-based attack detection. Rule-based attack detection identifies and intercepts known attacks through pre-defined rules. The advantage of this method is that it can quickly and accurately detect known attacks, but it lacks effective defense against unknown attacks. Anomaly localization-based attack detection, on the other hand, discovers abnormal behaviors in network behaviors by establishing a normal network behavior model to identify unknown attacks. The advantage of this method is that it can effectively identify unknown attacks, but it is also prone to false alarms. Existing work lacks an organic combination of the advantages of the two schemes and cannot complete collaborative work to maximize the accuracy and efficiency of attack detection. Summary of the Invention

[0004] The problem to be solved by the present invention: to improve the accuracy of attack detection.

[0005] To solve the above problem, the following solution is adopted in the present invention:

[0006] An attack detection method based on abnormal states according to the present invention includes the following steps:

[0007] Step S1: Obtain an attack defect description text;

[0008] Step S2: Parse the attack defect description text to obtain a set of attack state transition information;

[0009] The attack state transition information includes a first attack state information set and a second attack state information set; both the first attack state information set and the second attack state information set are sets of the attack state information;

[0010] The attack state information consists of an associated action and an action object;

[0011] Step S3: By merging the same matches between the attack state information, the attack state information in each set of attack state transition information is incorporated into the global attack state transition information set one by one;

[0012] Step S4: Monitor the behavior of the machine executing the operating system and application programs, and determine whether the machine is in an abnormal state according to whether the behavior result is consistent with the attack state information in the global attack state transition information set. When an abnormal state occurs, an early warning of the abnormal state is issued;

[0013] The step S2 includes the following steps:

[0014] Step S21: According to the preset regular expression and the domain-specific entity noun table, label the entity nouns in the attack defect description text;

[0015] Step S22: Segment the attack defect description text into short sentences, and then decompose the short sentences into a subject, a predicate, and an object according to the labeled entity names to obtain short sentence node information. According to the dependency relation word table and the front-back relationship of the short sentences, extract the dependency relationships between the short sentences, so as to obtain the node transition relationships between the short sentence node information corresponding to the short sentences;

[0016] Step S23: By similar and inclusive matching between the short sentence node information, merge the short sentence node information with the same semantics or an inclusive relationship, and adjust the node transition relationship after merging;

[0017] Step S24: Perform attack state information mapping according to the subject, predicate, and object of the short sentence node information, and construct the corresponding attack state transition information according to the node transition relationship of the short sentence node information corresponding to the attack state information. When the short sentence node information is mapped into attack state information, if the short sentence node information cannot be mapped into attack state information, delete the corresponding short sentence node information, modify the node transition relationship according to the node transition relationship, and construct the attack state transition information based on the modified node transition relationship.

[0018] Furthermore, according to the attack detection method based on abnormal state of the present invention, the issuing of the abnormal state early warning in the step S4 includes recording the abnormal state through a log, reporting the abnormal state through the network, and sending the abnormal state to the defense processing module.

[0019] Further, according to the attack detection method based on abnormal states of the present invention, in step S1, the attack behavior reports, attack means reports, and software vulnerability defect reports of a specified website are tracked. When a new attack behavior report, attack means report, or software vulnerability defect report is tracked, the text content of the attack behavior report, attack means report, or software vulnerability defect report is captured as the attack defect description text.

[0020] An attack detection device based on abnormal states according to the present invention includes the following modules:

[0021] Module M1, for: obtaining the attack defect description text;

[0022] Module M2, for: obtaining a set of attack state transition information after parsing the attack defect description text;

[0023] The attack state transition information includes a first set of attack state information and a second set of attack state information; both the first set of attack state information and the second set of attack state information are sets of the attack state information;

[0024] The attack state information is composed of an associated action and an action object;

[0025] Module M3, for: merging the attack state information in each set of attack state transition information into the global attack state transition information set one by one through the merging of identical matches between the attack state information;

[0026] Module M4, for: monitoring the behaviors of the machine in executing the operating system and application programs, and judging whether the machine is in an abnormal state according to whether the behavior results are consistent with the attack state information in the global attack state transition information set, and issuing a warning of the abnormal state when the abnormal state occurs;

[0027] The module M2 includes the following modules:

[0028] Module M21, for: annotating the entity nouns in the attack defect description text according to a preset regular expression and a domain-specific entity noun table;

[0029] Module M22, for: splitting the attack defect description text into short sentences, then decomposing the short sentences into a subject, a predicate, and an object according to the annotated entity names to obtain short sentence node information, and extracting the dependency relationships between the short sentences according to the dependency relationship word table and the front-back relationship of the short sentences, so as to obtain the node transition relationships between the short sentence node information corresponding to the short sentences;

[0030] Module M23 is used to: merge short sentence node information with the same semantics or inclusive relationship through similarity and inclusive matching between short sentence node information, and adjust the migrated relationship of the merged nodes;

[0031] Module M24 is used to: map attack status information based on the subject, predicate, and object of short sentence node information, and construct corresponding attack status migration information according to the migrated relationship of the short sentence node information corresponding to the attack status information; when the short sentence node information is mapped into attack status information, if the short sentence node information cannot be mapped into attack status information, the corresponding short sentence node information is deleted, and according to the migrated relationship, the migrated relationship is modified, and the attack status migration information is constructed based on the modified migrated relationship.

[0032] Furthermore, for the attack detection device based on abnormal status according to the present invention, the issuing of the abnormal status warning in the module M4 includes recording the abnormal status through logs, reporting the abnormal status through the network, and sending the abnormal status to the defense processing module.

[0033] Furthermore, for the attack detection device based on abnormal status according to the present invention, module M1 is used to: track the attack behavior report, attack means report, and software vulnerability defect report of a specified website, and when a new attack behavior report, attack means report, or software vulnerability defect report is tracked, capture the text content of the attack behavior report, attack means report, or software vulnerability defect report as the attack defect description text.

[0034] A medium according to the present invention; the medium stores a program instruction set that can be read by a machine; characterized in that when the program instruction set stored in the medium is read and executed by the machine, the above-mentioned attack detection method based on abnormal status can be realized.

[0035] A machine according to the present invention; the machine includes a processor and a memory; the memory stores a program instruction set; characterized in that when the program instruction set stored in the memory is loaded and executed by the processor, the above-mentioned attack detection method based on abnormal status can be realized.

[0036] The technical effects of the present invention are as follows:

[0037] Under the traditional method, it is easy to have false alarms in monitoring attacks themselves, while the present invention monitors the migration between attack statuses, and its accuracy is much higher, and basically no false alarm problems will occur.

[0038] The present invention can track and download current attack behaviors, attack means, and software vulnerabilities and defects utilized in real time, so that the machine attack model graph samples are kept up-to-date, and thus new attack means can be dealt with in a timely manner. Description of the Drawings

[0039] Figure 1 It is a flowchart of the attack detection method according to an embodiment of the present invention.

[0040] Figure 2 It is a schematic structural diagram of a machine according to an embodiment of the present invention. Embodiment

[0041] The present invention will be further described in detail below with reference to the accompanying drawings.

[0042] Figure 2 A machine 100 is exemplified. Specifically, the machine 100 is an electronic device, including a processor 101, a memory 102, and a communication unit 103. The processor 101 is connected to the memory 101 and the communication unit 103. Among them, the processor 101 is usually a general-purpose computer processor capable of executing computer program instructions. The memory 101 is usually a medium that can store data without loss after power-off, including but not limited to disks, magnetic tapes, flash memories, etc. This medium is the medium referred to in the foregoing of the present invention. The memory 101 is usually used to store computer program instruction sets and data. The processor 101 realizes its corresponding automation functions by loading the program instruction set stored in the memory 102. In particular, it is connected to the network 300 through the communication unit 103 and interacts with other machines connected to the network 300. Specifically, in this embodiment, the processor 101 realizes the attack detection method based on abnormal states referred to in the present invention by loading and executing the program instruction set stored in the memory 102. This method is mainly used to detect attacks from other machines on the network 300, and make defense processing after detecting the attacks, so as to protect the security of the machine 100. The present invention is limited to the detection of attacks, and the defense processing after detecting the attacks is not within the scope of discussion of the present invention and will not be elaborated.

[0043] Refer to Figure 1 , the attack detection method based on abnormal states in this embodiment includes an attack defect text grabbing step, a text attack state diagramming step, an attack state diagram merging step, and a machine behavior state monitoring step.

[0044] In the attack defect text grabbing step, specifically, grab the text describing the attack defects. Corresponding to the foregoing step S1, obtain the attack defect description text. The attack defect description text in step S1 is the text describing the attack defects, which is divided into attack behavior description text, attack means description text, and software vulnerability defect description text. The obtaining in step S1 means that the attack defect description text is the input for the subsequent steps of the present invention.

[0045] The attack defect description text comes from the information published through web pages by other machines on the network 300. According to different sources, the attack defect description text is usually divided into attack behavior description text, attack means description text, and software vulnerability defect description text.

[0046] The attack behavior description text is the relevant process and some details of the attack disclosed by national security departments or security-related enterprises and laboratories through analyzing the cybersecurity threats they observed. For example, the following example description of the Log4Shell attack behavior comes from the Cybersecurity and Infrastructure Security Agency (CISA).

[0047] “The threat actors using IP 104.223.34.98 gained initial access to Victim 2’s production environment in late January 2022, or earlier. These actors likely obtained access by exploiting Log4Shell in an unpatched VMware Horizon server. On or around January 30, likely shortly after the threat actors gained access, CISA observed the actors using PowerShell scripts to call out to 109.248.150.13 via Hypertext Transfer Protocol (HTTP) to retrieve additional PowerShell scripts. Around the same period, CISA observed the actors attempt to download and execute a malicious file from 109.248.150.13. The activity started from IP address 104.155.149.103, which appears to be part of the actors’ C2 infrastructure.”

[0048] The attack method description text is an analysis and summary report of the attack methods of attack behaviors disclosed by some security organizations, which comes from the attack strategy and attack method libraries maintained by these security organizations, such as the MITRE ATT&CK framework and the CAPEC (Common Attack Pattern Enumerations and Classifications) library. The attack method description text discloses, for example, the strategies / techniques adopted by the attack behavior, the software defects and vulnerabilities exploited by the attack behavior, the attack capabilities and purposes of the attack behavior, the description of the preconditions that need to be met for the attack behavior, and the description of the cases and implementation processes related to the attack behavior. For example, the following example of an attack method description is the description of the attack method "T1059.001: Command and Scripting Interpreter: PowerShell" in the ATT&CK framework.

[0049] "Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which can be used to run an executable and the Invoke-Command cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

[0050] PowerShell can also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.

[0051] A number of PowerShell-based offensive testing tools are available, including Empire, PowerSploit, PoshC2, and PSAttack.

[0052] PowerShell commands / scripts can also be executed without directly invoking the powershell.exe binary through interfaces to PowerShell's underlying System.Management.Automation assembly DLL exposed through the.NET framework and Windows Common Language Interface (CLI).”

[0053] The software vulnerability and defect description text, that is, the text describing software vulnerabilities and defects, comes from the vulnerability and defect libraries built and maintained by authoritative security organizations, such as MITRE's CVE (Common Vulnerabilities & Exposures) vulnerability library and CWE (Common Weakness Enumeration) defect library. The CVE vulnerability library collects publicly disclosed vulnerability information worldwide, and each vulnerability has a unique identifier for easy tracking and management of vulnerabilities. The common defect types in software and systems identified by analyzing the root causes of each vulnerability will be included in the CWE defect library. The software vulnerability and defect description text contains information such as vulnerability description, vulnerability impact, name of the product to which it belongs, and name of the manufacturer. The following is an exemplary software vulnerability and defect description text about the CVE-2021-44228 Log4J arbitrary code execution vulnerability:

[0054] "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects."

[0055] In a simple implementation, the attack defect description text can be directly used as the input of the present invention. At this time, the attack defect description text is usually downloaded and sorted manually on relevant websites as the input of this implementation. Those skilled in the art understand that on the one hand, the attack defect description text comes from public websites, and on the other hand, the machine 100 is connected to the network through the communication unit 103. It is very easy for those skilled in the art to think of automatically downloading on relevant websites through the method of web crawler. Specifically in this embodiment, the aforementioned scraping means downloading and extracting valid text content on the website. Specifically, it is to track the attack behavior reports, attack means reports, and software vulnerability defect reports of the specified website. When a new attack behavior report, attack means report, or software vulnerability defect report is tracked, the text content of the attack behavior report, attack means report, or software vulnerability defect report is scraped as the attack defect description text. Here, tracking the attack behavior reports, attack means reports, and software vulnerability defect reports of the specified website in this embodiment adopts a timed method, that is, every once in a while, by accessing the attack behavior reports, attack means reports, and software vulnerability defect reports of the specified website, it is detected whether there are new attack behavior reports, attack means reports, or software vulnerability defect reports. In addition, the scraping here includes two steps: the first step is to download the web page content from the website; the second step is to extract the valid text content from the downloaded web page content. The first step of downloading the web page content from the website is familiar to those skilled in the art. The second step needs to be based on the corresponding HTML text format of different websites. Usually, each website has a fixed HTML text format for the attack behavior reports, attack means reports, or software vulnerability defect reports it publishes. Therefore, in actual implementation, only the valid text content needs to be extracted according to this fixed HTML text format, which is not difficult for those skilled in the art and will not be elaborated here.

[0056] The steps of graphically illustrating the text attack state, in simple terms, are to perform text parsing on the aforementioned text describing attack defects to construct an attack model graph. In this step, the processing procedures for the text describing attack behaviors, the text describing attack means, and the text describing software vulnerability defects are the same. Specifically in this embodiment, it is the aforementioned step S2, and after parsing the text describing attack defects, a set of attack state transition information is obtained. The attack state transition information includes a first set of attack state information and a second set of attack state information. Both the first set of attack state information and the second set of attack state information are sets of attack state information. The attack state information is used to represent the state of the machine being attacked. It should be noted that the set of attack state transition information here is the data representation of the attack model graph. The attack model graph is a directed graph composed of nodes and directed edges. In the attack model graph, the nodes correspond to the attack state information, and the directed edges are represented by the first set of attack state information and the second set of attack state information of the attack state transition information. That is to say, there can be multiple starting nodes and multiple ending nodes for the directed edges of the attack model graph. Among them, the attack state information corresponding to the starting nodes is defined in the first set of attack state information, and the attack state information corresponding to the ending nodes is defined in the second set of attack state information. In a more practical implementation process, the attack state information in the first set of attack state information and the second set of attack state information is represented by attack state identification codes, and the complete attack state information is stored in a corresponding set of attack state information.

[0057] In this embodiment, the steps of graphically illustrating the text attack state specifically include the following steps:

[0058] Step S21: Label the entity nouns in the text describing attack defects according to a preset regular expression and a domain-specific entity noun table;

[0059] Step S22: Split the text describing attack defects into short sentences, and then decompose the short sentences into a subject, a predicate, and an object according to the labeled entity names to obtain short sentence node information. And according to the dependency relation word table and the front-back relationship of the short sentences, extract the dependency relationships between the short sentences, so as to obtain the node transition relationships between the short sentence node information corresponding to the short sentences;

[0060] Step S23: Merge the short sentence node information with the same semantics or inclusive relationships through similarity and inclusion matching between the short sentence node information, and adjust the node transition relationships after merging;

[0061] Step S24: Map the attack status information according to the subject, predicate, and object of the short sentence node information, and construct the corresponding attack status transition information according to the node transition relationship of the short sentence node information corresponding to the attack status information; when the short sentence node information is mapped into the attack status information, if the short sentence node information cannot be mapped into the attack status information, delete the corresponding short sentence node information, modify the node transition relationship according to the node transition relationship, and construct the attack status transition information based on the modified node transition relationship.

[0062] In step S21, the preset regular expressions include but are not limited to: URL link regular expression, HOST host regular expression, IP address regular expression, Email mailbox regular expression, Windows registry regular expression, file name regular expression, file or folder path regular expression. The domain-specific entity noun list is a set of domain-specific entity nouns obtained by extracting nouns from the domain-specific vocabulary library. For the convenience of retrieval, the domain-specific entity noun list is usually sorted. For example, in the aforementioned description example of the Log4Shell attack behavior from CISA, the entity nouns that can be marked are: "actor", "104.223.34.98", "access", "victim", "product environment", "Log4Shell", "VMware Horizon", "CISA", "PowerShell script", "109.248.150.13", "104.155.149.103", "Hypertext Transfer Protocol", "C2 infrastructure".

[0063] Step S22 can be decomposed into the following three steps: short sentence clause separation, subject-predicate-object decomposition, and node transition relationship construction. Taking the aforementioned description of the Log4Shell attack behavior from CISA as an example, the short sentence clause separation and subject-predicate-object decomposition are performed to obtain the following short sentence node information:

[0064] sn1_1: [Subject: "actor", Predicate: "gained", Object: "initial access"], corresponding short sentence: The threat actors using IP 104.223.34.98 gained initial access to Victim 2’s production environment in late January 2022, or earlier.;

[0065] sn1_2: [Subject: "actor", Predicate: "obtain", Object: "access"], Corresponding short sentence: These actors likely obtained access;

[0066] sn1_3: [Subject: "actor", Predicate: "exploit", Object: "Log4Shell in an unpatched VMware Horizon server"], Corresponding short sentence: by exploiting Log4Shell in an unpatched VMware Horizon server;

[0067] sn1_4: [Subject: "actor", Predicate: "gain", Object: "access"], Corresponding short sentence: after the threat actors gained access;

[0068] sn1_5: [Subject: "actor", Predicate: "use", Object: "PowerShell script"], Corresponding short sentence: the actors using PowerShell scripts;

[0069] sn1_6: [Subject: "actor", Predicate: "callout to", Object: "109.248.150.13"], Corresponding short sentence: to callout to 109.248.150.13;

[0070] sn1_7: [Subject: "", Predicate: "", Object: "Hypertext Transfer Protocol (HTTP) "], Corresponding short sentence: via Hypertext Transfer Protocol (HTTP) ;

[0071] sn1_8: [Subject: "actor", Predicate: "retrieve", Object: "additional PowerShell scripts"], Corresponding short sentence: retrieve additional PowerShell scripts;

[0072] sn1_9: [Subject: "actor", Predicate: "download and execute", Object: "malicious file from 109.248.150.13"], corresponding short sentence: the actors attempt to download and execute a malicious file from 109.248.150.13;

[0073] sn1_10: [Subject: "activity", Predicate: "started from", Object: "IP address 104.155.149.103"], corresponding short sentence: The activity started from IP address 104.155.149.103;

[0074] sn1_11: [Subject: "", Predicate: "", Object: "part of the actors’ C2 infrastructure"], corresponding short sentence: appears to be part of the actors’ C2 infrastructure;

[0075] The above sn1_1 to sn1_11 are respectively used to represent 11 short sentence node information. The above short sentence clauses are obtained based on the matching of dependency words with long sentences (ending with a full stop) as the unit. For example, in the above example, the short sentence These actors likely obtained access by exploiting Log4Shell in an unpatched VMware Horizon server. can be divided into two sub-clauses, sn1_2 and sn1_3, by the dependency word "by". In this embodiment, the dependency word list includes, for example, the following words:

[0076] be caused by, be arise from, be arise out, be rise of, be triggered by, be induced by, be the cause of, be affected by, be effect on, cause of … is …, reason of … is …, by, [v]…to[v]…, by reason that … is…, the reason for … is …, be cause for, be trigger of, if … then …, hence, therefore, thus, thereby, accordingly, consequently, in this way, that is why, cause, allow, trigger, affect, induce, reveal, lead to, bring about, appear to, bring on, give rise to, increase, result in, so that to, have effect on, in order to, for the purpose of, after, because, as a result of, due to, owning to, in view of, as a consequence of, on account of, derive from, as long as, for this reason that, for the reason that, because of, since, through, stem from, result from, thanks to, in consequence of, in that, on the ground that, as, via, begin, end,....

[0077] In the above short sentence node information:

[0078] Based on the dependency word "by" between the short sentences "These actors likely obtained access" and "by exploiting Log4Shell in an unpatched VMware Horizon server", construct the node migration relationship: sn1_3 -> sn1_2;

[0079] Based on the dependency word "after" between the short sentences "after the threat actors gained access" and "the actors using PowerShell scripts", construct the node migration relationship: sn1_4 -> sn1_5

[0080] Based on the dependency word "to" between the short sentences "the actors using PowerShell scripts" and "to callout to 109.248.150.13", construct the node migration relationship: sn1_5 > sn1_6;

[0081] Based on the dependency word "via" between the short sentences "to callout to 109.248.150.13" and "via Hypertext Transfer Protocol (HTTP)", construct the node migration relationship: sn1_7 > sn1_6;

[0082] Based on the dependency word "to" between the short sentences "to callout to 109.248.150.13" and "to retrieve additional PowerShell scripts", construct the node migration relationship: sn1_6 > sn1_8;

[0083] Based on the qualification of the dependency word "appears to" between the short sentences "The activity started from IP address 104.155.149.103" and "appears to be part of the actors’ C2 infrastructure", construct the node migration relationship: sn1_10 -> sn1_11;

[0084] Combining the front - back relationship of the short sentences in the text, the final node migration relationships are as follows:

[0085] sn1_3 -> sn1_2

[0086] sn1_4 -> sn1_5

[0087] sn1_5 -> sn1_6

[0088] sn1_7 > sn1_6

[0089] sn1_6 -> sn1_8

[0090] sn1_10 -> sn1_11

[0091] sn1_1 -> sn1_2

[0092] sn1_2 -> sn1_5

[0093] sn1_8 -> sn1_9

[0094] sn1_9 -> sn1_11

[0095] It should be noted that, compared with the dependency relationships constructed according to the aforementioned dependency relationship table, the dependency relationships constructed based on the context before and after the text are weak dependency relationships, while the dependency relationships constructed according to the dependency relationship table are strong dependency relationships.

[0096] In step S23, when comparing whether the short sentence node information is similar, usually the modifiers and qualifiers of the subject, predicate, and object can be deleted and then it can be determined whether the meanings of the subject, predicate, and object are similar. If they are similar, the semantics are the same. For example, for the short sentence node information sn1_1: [subject: "actor", predicate: "gain", object: "initial access"], after removing the qualifier "intial" from the object, the new short sentence node information sn1_1_V2 can be obtained: [subject: "actor", predicate: "gain", object: "access"]. The predicate "gain" in it and the predicate in sn1_2: "obtain" have the same semantic essence, and the subject and object are also the same. Therefore, the short sentence node information sn1_1 is the same as sn1_2 and sn1_4. In addition, there is also an inclusion relationship here. For example, "malicious file" in the short sentence node information sn1_9 includes "PowerShellscript" in the short sentence node information sn1_8, and the predicates "retrieve" and "download and execute" have similar meanings. Therefore, the short sentence node information sn1_8 can be absorbed by the short sentence node information sn1_9.

[0097] Thus, after the short sentence node information is re-labeled by deleting the qualifiers and modifiers and merging in step S23, it is simplified as follows:

[0098] sn2_1: [subject: "actor", predicate: "obtain", object: "access"];

[0099] sn2_2: [Subject: "actor", Predicate: "exploit", Object: "Log4Shell"];

[0100] sn2_3: [Subject: "actor", Predicate: "use", Object: "PowerShell script"];

[0101] sn2_4: [Subject: "actor", Predicate: "callout to", Object: "109.248.150.13"];

[0102] sn2_5: [Subject: "", Predicate: "", Object: "Hypertext Transfer Protocol (HTTP) "];

[0103] sn2_6: [Subject: "actor", Predicate: "download and execute", Object: "PowerShellscript or other malicious file"];

[0104] sn2_7: [Subject: "activity", Predicate: "started from", Object: "IP address104.155.149.103"];

[0105] sn2_8: [Subject: "", Predicate: "", Object: "part of the actors’ C2 infrastructure"];

[0106] The corresponding adjusted migration relationships are as follows:

[0107] sn2_2 -> sn2_1

[0108] sn2_1 -> sn2_3

[0109] sn2_3 -> sn2_4

[0110] sn2_5 > sn2_4

[0111] sn2_4 -> sn2_6

[0112] sn2_7 -> sn2_8

[0113] sn2_6 -> sn2_8

[0114] In step S24, the attack status information is the state of the attack suffered by the machine. Therefore, the attack status information is related to the behavior of the machine itself. The action subject of the short sentence node information is generally the attacker. Therefore, it is necessary to map the behavior of the attacker to the behavior of the local machine. For example, in the aforementioned short sentence node information sn2_4, [subject: "actor", predicate: "callout to", object: "109.248.150.13"], actor callout to 109.248.150.13 is equivalent to the local machine connecting to the network of 109.248.150.13 for the local machine. For the machine, the action behavior of the attacker is relatively fixed, such as network connection, creating files, modifying files, executing files or scripts, etc. In addition, since the action subject of the short sentence node information is the attacker, not all of its behaviors can be mapped to a certain attack state. For example, in the short sentence node information sn2_1 [subject: "actor", predicate: "obtain", object: "access"], its behavior actor obtain access is completely a description of the attacker itself and cannot be mapped to an attack state. Therefore, it needs to be deleted. Among the short sentence node information sn2_1 to sn2_8 in the aforementioned example, the short sentence node information sn2_1 and sn2_2 cannot be corresponding to a certain state of the machine under attack and need to be deleted. After deletion, the re-labeled short sentence node information is as follows:

[0115] sn3_1: [subject: "actor", predicate: "use", object: "PowerShell script"];

[0116] sn3_2: [subject: "actor", predicate: "callout to", object: "109.248.150.13"];

[0117] sn3_3: [subject: "", predicate: "", object: "Hypertext Transfer Protocol (HTTP) "];

[0118] sn3_4: [subject: "actor", predicate: "download and execute", object: "PowerShellscript or other malicious file"];

[0119] sn3_5: [subject: "activity", predicate: "started from", object: "IP address104.155.149.103"];

[0120] sn3_6: [Subject: "", Predicate: "", Object: "part of the actors’ C2 infrastructure"];

[0121] The corresponding adjusted migration relationships are as follows:

[0122] sn3_1 -> sn3_2

[0123] sn3_3 > sn3_2

[0124] sn3_2 -> sn3_4

[0125] sn3_5 -> sn3_6

[0126] sn3_4 -> sn3_6

[0127] The above short sentence node information is mapped to the attack state information as follows:

[0128] sn3_1 => mn_1: [Associated Action: "Excute", Action Object: "PowerShell script"];

[0129] sn3_2 => mn_2: [Associated Action: "NetConnectTo", Action Object: "109.248.150.13"]

[0130] sn3_3 => mn_3: [Associated Action: "NetConnectBy", Action Object: "Hypertext TransferProtocol (HTTP)"]

[0131] sn3_4 => mn_4: [Associated Action: "CreateFile", Action Object: "unknown file"];

[0132] sn3_5 => mn_5: [Associated Action: "NetConnectFrom", Action Object: "104.155.149.103"];

[0133] sn3_6 => mn_6: [Associated Action: "NetConnectBy", Action Object: "C2(Connect&Control, C&C)"];

[0134] The corresponding attack state migration information is as follows:

[0135] [mn_1, mn_3] -> mn_2

[0136] mn_2 -> mn_4

[0137] [mn_5,mn_4]->mn _6

[0138] The step of merging the attack state diagrams, which is the aforementioned step S3. By merging the attacks through the matching of the same attack state information, the attack state information in each set of attack state transition information is incorporated into the global attack state transition information set one by one. As previously mentioned, the set of attack state transition information represents an attack model diagram, while the global attack state transition information set is a global attack model diagram. During the processing of the aforementioned step S2, an attack model diagram can be obtained for each attack defect description text. To improve the incorporation into the global attack state transition information set, in this embodiment, usually, the sets of attack state transition information corresponding to each currently obtained attack defect description text are first merged to form a temporary attack state transition information set representing the overall attack model diagram, and then this attack state transition information set is merged with the global attack state transition information set. The matching of the same attack state information is to compare whether the associated actions and action objects are the same. In addition, for convenience of processing, the set of attack state transition information usually only includes the attack state identification codes of the attack state information contained in the attack state transition information. The complete attack state information is stored in a corresponding set of attack state information. Therefore, during the merging of this step, the corresponding sets of attack state information are first merged, and then the corresponding attack state transition information is merged according to the attack state identification codes returned after the merging of the attack state information in the set of attack state information.

[0139] In addition, further for subsequent monitoring, the attack state information usually also includes information such as the defects corresponding to the attack. For example, in the aforementioned example, the attack state information can further include the corresponding defect identifier Log4Shell. In addition, the defect identifiers of the attack state information are usually a set.

[0140] The step of monitoring the machine behavior state, which is the aforementioned step S4, monitors the behavior of the machine in executing the operating system and application programs, and determines whether the machine is in an abnormal state based on whether the behavior result is consistent with the attack state information in the global attack state transition information set. When an abnormal state occurs, a warning of the abnormal state is issued. The judgment of the consistency between the behavior result and the attack state information is to match the associated actions and action objects in the attack state information. For example, at a certain moment, it is monitored that a certain application program has established a network connection. As long as it is matched whether the target network address is the action object of the associated action NetConnectTo in the attack state information, it indicates that an abnormal state has occurred at this time.

[0141] In the present invention, issuing an abnormal state warning is a statement of a higher-level concept. Issuing an abnormal state warning generally includes, for example, recording the abnormal state through logs, reporting the abnormal state over the network, and sending the abnormal state to the defense processing module. In this embodiment, generally, an abnormal state whose behavior result is consistent with the attack state information will only output the abnormal state to the log. When a situation where the state transition conforms occurs, it will be considered an attack and an alarm will be issued. The situation where the state transition conforms means that the behavior results of two or more consecutive program behaviors are respectively consistent with the first attack state information and the second attack state information of a certain attack state transition information. The issuance of an alarm in this embodiment specifically refers to reporting the abnormal state over the network and at the same time sending the abnormal state to the defense processing module. At this time, the abnormal state represents a state where the behavior results of multiple program behaviors are respectively consistent with multiple attack state information.

[0142] It should be noted that the judgment of the consistency of attack state information in the present invention is not directed at the behavior being executed by the application program. This is the difference between the present invention and traditional attack monitoring. Traditional attack monitoring focuses on monitoring the attack behavior itself. For example, when an application program establishes a connection, traditional attack monitoring will detect it, while the attack state monitoring in the present invention will not detect it. It will only be detected by the attack state monitoring in the present invention after the application program connection is established because based on the method of the present invention, in addition to monitoring a certain behavior state, the most important thing is to monitor the transition between states.

[0143] In addition, it should also be noted that the aforementioned modules in the present invention are virtual devices corresponding to the steps in the method, which will not be elaborated here.

Claims

1. An attack detection method based on abnormal states, characterized in that, It includes the following steps: Step S1: Obtain the attack defect description text; Step S2: After parsing the attack defect description text, obtain a set of attack state transition information; The attack state transition information includes a first set of attack state information and a second set of attack state information; both the first set of attack state information and the second set of attack state information are sets of the attack state information; The attack state information consists of an associated action and an action object; Step S3: By merging the same matches between the attack state information, incorporate the attack state information in each set of attack state transition information into the global attack state transition information set one by one; Step S4: Monitor the behavior of the machine executing the operating system and application programs, and determine whether the machine is in an abnormal state based on whether the behavior result is consistent with the attack state information in the global attack state transition information set. When an abnormal state occurs, issue a warning of the abnormal state; The step S2 includes the following steps: Step S21: Annotate the entity nouns in the attack defect description text according to the preset regular expressions and domain-specific entity noun tables; Step S22: Split the attack defect description text into short sentences, and then decompose the short sentences into the subject, predicate, and object according to the annotated entity names to obtain short sentence node information. According to the dependency relation word table and the context before and after the short sentences, extract the dependency relations between the short sentences, so as to obtain the node transition relations between the short sentence node information corresponding to the short sentences; Step S23: Merge the short sentence node information with the same or inclusive semantics by similarity and inclusion matching between the short sentence node information, and adjust the node transition relations after merging; Step S24: Map the attack state information according to the subject, predicate, and object of the short sentence node information, and construct the corresponding attack state transition information according to the node transition relations of the short sentence node information corresponding to the attack state information; When the short sentence node information is mapped into the attack state information, if the short sentence node information cannot be mapped into the attack state information, delete the corresponding short sentence node information, modify the node transition relations according to the node transition relations, and construct the attack state transition information based on the modified node transition relations.

2. The attack detection method based on an abnormal state according to claim 1, wherein The issuing of the abnormal state warning in the step S4 includes recording the abnormal state through logs, reporting the abnormal state through the network, and sending the abnormal state to the defense processing module.

3. The attack detection method based on abnormal states according to claim 1, wherein, In the step S1, track the attack behavior reports, attack means reports, and software vulnerability defect reports of the specified website. When a new attack behavior report, attack means report, or software vulnerability defect report is tracked, capture the text content of the attack behavior report, attack means report, or software vulnerability defect report as the attack defect description text.

4. An attack detection device based on an abnormal state, characterized in that, It includes the following modules: Module M1, used for: obtaining the attack defect description text; Module M2, used for: after parsing the attack defect description text, obtaining a set of attack state transition information; The attack state transition information includes a first set of attack state information and a second set of attack state information; both the first set of attack state information and the second set of attack state information are sets of the attack state information; The attack state information consists of an associated action and an action object; Module M3 is used for: by merging the same matches between the attack state information, incorporating the attack state information in each set of attack state transition information into the global attack state transition information set one by one; Module M4 is used for: monitoring the behaviors of the machine in executing the operating system and application programs, and judging whether the machine is in an abnormal state according to whether the behavior results are consistent with the attack state information in the global attack state transition information set, and issuing a warning of the abnormal state when the abnormal state occurs; The module M2 includes the following modules: Module M21 is used for: annotating the entity nouns in the attack defect description text according to a preset regular expression and a domain-specific entity noun table; Module M22 is used for: splitting the attack defect description text into short sentences, then decomposing the short sentences into a subject, a predicate, and an object according to the annotated entity names to obtain short sentence node information, and extracting the dependency relationships between the short sentences according to the dependency relationship word table and the front-back relationship of the short sentences, so as to obtain the node transition relationship between the short sentence node information corresponding to the short sentences; Module M23 is used for: merging the short sentence node information with the same semantics or an inclusive relationship by similarity and inclusive matching between the short sentence node information, and adjusting the node transition relationship after merging; Module M24 is used for: performing attack state information mapping according to the subject, predicate, and object of the short sentence node information, and constructing corresponding attack state transition information according to the node transition relationship of the short sentence node information corresponding to the attack state information; When the short sentence node information is mapped into attack state information, if the short sentence node information cannot be mapped into attack state information, the corresponding short sentence node information is deleted, the node transition relationship is modified according to the node transition relationship, and the attack state transition information is constructed according to the modified node transition relationship.

5. The attack detection device based on abnormal states according to claim 4, wherein The issuing of the warning of the abnormal state in the module M4 includes recording the abnormal state through a log, reporting the abnormal state through the network, and sending the abnormal state to the defense processing module.

6. The attack detection device based on an abnormal state according to claim 4, wherein Module M1 is used for: tracking the attack behavior report, attack means report, and software vulnerability defect report of a specified website, and when a new attack behavior report, attack means report, or software vulnerability defect report is tracked, grabbing the text content of the attack behavior report, attack means report, or software vulnerability defect report as the attack defect description text.

7. A machine-readable medium; the medium stores a set of program instructions that can be read by a machine; characterized in that, When the program instruction set stored in the medium is read and executed by the machine, the attack detection method based on the abnormal state according to any one of claims 1 to 3 can be realized.

8. An electronic device; the device includes a processor and a memory; a program instruction set is stored in the memory; characterized in that, When the program instruction set stored in the memory is loaded and executed by the processor, the attack detection method based on the abnormal state according to any one of claims 1 to 3 can be realized.