Advanced persistent threat attack detection method, device and electronic equipment
By extracting behavioral characteristic indicators from the host log information and mapping them to the entity status bitmap, and using detection classifiers and encoder decoders to identify APT attacks, the problem of inability to effectively detect APT attacks in the prior art is solved, and efficient APT attack detection and defense are achieved.
Patent Information
- Application Number
- CN202310539179.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-12
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2043-05-12
AI Technical Summary
Existing cyberattack detection systems are unable to effectively deal with the long duration and hidden problems of advanced sustainability threat (APT) attacks, making it difficult to detect and defend in a timely manner.
By obtaining host log information, determining behavioral characteristic indicators, and mapping them into entity status bitmap, a pre-trained detection classifier is used to identify potential malicious attacks, and combining encoder and decoder to process unknown samples, the identification and early warning of APT attacks is achieved.
Effectively detect and defend APT attacks, reduce memory overhead, be able to identify out-of-distributed samples, adapt to the characteristics of long-term APT attacks, and provide timely early warning processing.
Smart Images

Figure CN116633604B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method, device, and electronic device for detecting advanced persistent threat attacks. Background Art
[0002] Today, all walks of life are highly dependent on the internet. While this has improved productivity and living efficiency, cybersecurity threats are also spreading faster, more widely, and with more severe consequences. Illegal actors launch cyberattacks to compromise access rights, steal data, and disrupt services. These attacks employ a variety of methods, requiring significant human, material, and financial resources to defend against.
[0003] APT (Advanced Persistent Threat) attacks are targeted, slow, persistent, and difficult to detect. Current network attack detection systems typically target short-term, transient attacks and are unable to address the long-lasting nature of APT attacks. When attackers remain dormant in victim systems for extended periods and then suddenly strike at a critical moment, they can cause unpredictable losses and disasters. Therefore, detecting APT attacks has become a pressing technical challenge. Summary of the Invention
[0004] In order to solve the above technical problems, the present application provides an advanced persistent threat attack detection method, device, electronic device and storage medium.
[0005] According to a first aspect of the present application, a method for detecting an advanced persistent threat attack is provided, comprising:
[0006] Acquire host log information and determine a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set; wherein the behavior characteristic indicator is used to describe the status of a system entity;
[0007] Determine, according to a mapping relationship between the behavior characteristic indicator and the entity state bitmap and the bits in the entity state bitmap, a target bit corresponding to the target behavior characteristic indicator in the entity state bitmap corresponding to the target behavior characteristic indicator;
[0008] According to the target behavior characteristic indicator, the value of the target bit is set to obtain a target entity state bitmap;
[0009] In the case where the target entity state bitmap changes, inputting the target entity state bitmap into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap;
[0010] If the category corresponding to the target entity status bitmap belongs to a malicious attack, corresponding warning processing is performed according to the category corresponding to the target entity status bitmap.
[0011] Optionally, after obtaining the category corresponding to the target entity state bitmap, the method further includes:
[0012] If the category corresponding to the target entity status bitmap is an out-of-distribution sample, storing the target entity status bitmap and the host log information;
[0013] Determining a category corresponding to the target entity status bitmap based on the host log information;
[0014] The detection classifier is updated based on the target entity state bitmap and the category corresponding to the target entity state bitmap.
[0015] Optionally, the detection classifier includes a first branch module and a second branch module, and the second branch module includes an encoder and a decoder;
[0016] Inputting the target entity state bitmap into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap includes:
[0017] Inputting the target entity state bitmap into a pre-trained detection classifier, classifying the target entity state bitmap through the first branch module to obtain a category corresponding to the target entity state bitmap;
[0018] The method further comprises:
[0019] If the category corresponding to the target entity state bitmap is an out-of-distribution sample, extracting potential features of the target entity state bitmap by the encoder;
[0020] Selecting a target latent feature that is closest to the latent feature of the target entity state bitmap from the latent features corresponding to the sample state bitmap;
[0021] Determining the category corresponding to the target entity state bitmap according to the category of the sample state bitmap corresponding to the target potential feature;
[0022] Decoding the target potential features by the decoder to obtain a pseudo-entity state bitmap;
[0023] By comparing the target entity state bitmap and the pseudo entity state bitmap, the behavior corresponding to the host log information is analyzed.
[0024] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: description information and index information of the behavior characteristic indicator;
[0025] The method further comprises:
[0026] Determine the entity to which the behavior characteristic indicator belongs based on the description information of each behavior characteristic indicator in the characteristic indicator set, each entity having a corresponding entity state bitmap;
[0027] Establish a mapping relationship between behavioral characteristic indicators and entity state bitmaps;
[0028] According to the index information of each behavior characteristic indicator in the characteristic indicator set, the corresponding bit of the behavior characteristic indicator in the entity state bitmap corresponding to the behavior characteristic indicator is set to establish a mapping relationship between the behavior characteristic indicator and the entity state bitmap, and the bits in the entity state bitmap.
[0029] Optionally, determining a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set includes:
[0030] Parsing the host log information to obtain key information;
[0031] Matching the key information with the description information of each behavior characteristic indicator in the behavior characteristic indicator set to obtain target description information that matches the key information;
[0032] The behavior characteristic indicator corresponding to the target description information is determined as the target behavior characteristic indicator.
[0033] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: level information of the behavior characteristic indicator, each behavior characteristic indicator corresponds to S bits in the entity state bitmap corresponding to the behavior characteristic indicator, where S is an integer greater than 1;
[0034] The setting of the target bit value according to the target behavior characteristic indicator includes:
[0035] The S bits included in the target bit are set to a value equal to the level information of the target behavior feature indicator.
[0036] Optionally, the method further includes:
[0037] After acquiring the host log information, storing the host log information and index information of the host log information in a database;
[0038] If the category corresponding to the target entity status bitmap belongs to malicious attack, determining the index information of the hit behavior feature indicator and the level information of the index information of the hit behavior feature indicator according to the value of each bit in the target entity status bitmap;
[0039] Based on the mapping relationship among the entity identification information, the index information of the behavior characteristic indicator, the level information of the behavior characteristic indicator and the index information of the log information, the target index information corresponding to the entity identification information corresponding to the target entity state bitmap, the index information of the hit behavior characteristic indicator and the level information of the hit behavior characteristic indicator is determined;
[0040] The host log information corresponding to the target index information is obtained from the database.
[0041] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: key identification information of the behavior characteristic indicator;
[0042] The storing of the host log information and the index information of the host log information in a database includes:
[0043] In a case where the critical identification information of the target behavior characteristic indicator corresponding to the host log information is critical, the host log information and the index information of the host log information are stored in a database.
[0044] According to a second aspect of the present application, there is provided an advanced persistent threat attack detection device, comprising:
[0045] Host log information acquisition module, used to obtain host log information;
[0046] A target behavior characteristic indicator determination module is used to determine a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set; wherein the behavior characteristic indicator is used to describe the state of the system entity;
[0047] A target bit determination module is used to determine the target bit corresponding to the target behavior characteristic indicator in the entity state bitmap corresponding to the target behavior characteristic indicator according to the mapping relationship between the behavior characteristic indicator and the entity state bitmap and the bits in the entity state bitmap;
[0048] a target entity state bitmap determination module, configured to set the value of the target bit according to the target behavior characteristic indicator to obtain a target entity state bitmap;
[0049] a classification module, configured to input the target entity state bitmap into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap when the target entity state bitmap changes;
[0050] The early warning processing module is used to perform corresponding early warning processing according to the category corresponding to the target entity status bitmap if the category corresponding to the target entity status bitmap belongs to a malicious attack.
[0051] Optionally, the advanced persistent threat attack detection device further includes:
[0052] a host log information storage module, configured to store the target entity state bitmap and the host log information if the category corresponding to the target entity state bitmap is an out-of-distribution sample;
[0053] A first category determination module, configured to determine a category corresponding to the target entity status bitmap based on the host log information;
[0054] A detection classifier updating module is configured to update the detection classifier based on the target entity state bitmap and the category corresponding to the target entity state bitmap.
[0055] Optionally, the detection classifier includes a first branch module and a second branch module, and the second branch module includes an encoder and a decoder;
[0056] The classification module is specifically configured to input the target entity state bitmap into a pre-trained detection classifier when the target entity state bitmap changes, and classify the target entity state bitmap through the first branch module to obtain a category corresponding to the target entity state bitmap;
[0057] The advanced persistent threat attack detection device further includes:
[0058] a potential feature extraction module, configured to extract potential features of the target entity state bitmap through the encoder if the category corresponding to the target entity state bitmap is an out-of-distribution sample;
[0059] A target potential feature determination module is used to select a target potential feature that is closest to the potential feature of the target entity state bitmap from the potential features corresponding to the sample state bitmap;
[0060] A second category determination module, configured to determine the category corresponding to the target entity state bitmap according to the category of the sample state bitmap corresponding to the target potential feature;
[0061] a pseudo-entity state bitmap determination module, configured to decode the target potential features through the decoder to obtain a pseudo-entity state bitmap;
[0062] The behavior analysis module is used to analyze the behavior corresponding to the host log information by comparing the target entity state bitmap and the pseudo entity state bitmap.
[0063] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: description information and index information of the behavior characteristic indicator;
[0064] The advanced persistent threat attack detection device further includes:
[0065] A corresponding entity determination module, configured to determine the entity to which the behavior characteristic indicator belongs based on the description information of each behavior characteristic indicator in the characteristic indicator set, wherein each entity has a corresponding entity state bitmap;
[0066] A first mapping relationship establishing module, configured to establish a mapping relationship between a behavior characteristic indicator and an entity state bitmap;
[0067] The second mapping relationship establishment module is used to set the corresponding bit of the behavior characteristic indicator in the entity state bitmap corresponding to the behavior characteristic indicator according to the index information of each behavior characteristic indicator in the characteristic indicator set, so as to establish a mapping relationship between the behavior characteristic indicator and the entity state bitmap, and the bits in the entity state bitmap.
[0068] Optionally, the target behavior characteristic indicator determination module is specifically used to parse the host log information to obtain key information; match the key information with the description information of each behavior characteristic indicator in the behavior characteristic indicator set to obtain target description information that matches the key information; and determine the behavior characteristic indicator corresponding to the target description information as the target behavior characteristic indicator.
[0069] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: level information of the behavior characteristic indicator, each behavior characteristic indicator corresponds to S bits in the entity state bitmap corresponding to the behavior characteristic indicator, where S is an integer greater than 1;
[0070] The target entity state bitmap determination module is specifically configured to set the S bits included in the target bitmap to a value equal to the level information of the target behavior feature indicator to obtain a target entity state bitmap.
[0071] Optionally, the advanced persistent threat attack detection device further includes:
[0072] A host log information storage module, configured to store the host log information and index information of the host log information in a database;
[0073] A hit behavior characteristic indicator determination module is used to determine the index information of the hit behavior characteristic indicator and the level information of the index information of the hit behavior characteristic indicator according to the value of each bit in the target entity state bitmap if the category corresponding to the target entity state bitmap belongs to a malicious attack;
[0074] a target index information determination module, configured to determine target index information corresponding to the entity identification information corresponding to the target entity state bitmap, the index information of the hit behavior characteristic indicator, and the level information of the hit behavior characteristic indicator based on a mapping relationship among entity identification information, index information of the behavior characteristic indicator, level information of the behavior characteristic indicator, and index information of the log information;
[0075] The host log information search module is used to obtain the host log information corresponding to the target index information from the database.
[0076] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: key identification information of the behavior characteristic indicator;
[0077] The host log information storage module is specifically configured to store the host log information and index information of the host log information in a database when the key identification information of the target behavior characteristic indicator corresponding to the host log information is key.
[0078] According to a third aspect of the present application, an electronic device is provided, comprising: a processor, wherein the processor is configured to execute a computer program stored in a memory, wherein the computer program implements the method described in the first aspect when executed by the processor.
[0079] According to a fourth aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the method described in the first aspect is implemented.
[0080] According to a fifth aspect of the present application, a computer program product is provided. When the computer program product is run on a computer, the computer is caused to execute the method described in the first aspect.
[0081] The technical solution provided by the embodiments of the present application has the following advantages compared with the prior art:
[0082] By introducing a behavioral characteristic indicator for describing the state of a system entity, the behavior of the entity is extracted from the host log information, that is, the target behavioral characteristic indicator corresponding to the host log information is determined. Further, the target bit corresponding to the target behavioral characteristic indicator in the entity state bitmap (a data structure that can retain entity information for a long time) corresponding to the target behavioral characteristic indicator is determined, and the value of the target bit is set according to the target behavioral characteristic indicator to obtain the target entity state bitmap. In this way, the behavioral characteristic indicator can be converted into structured data. After mapping the host log information to the target behavioral characteristic indicator and mapping the target behavioral characteristic indicator to the target entity state bitmap, the category corresponding to the target entity state bitmap can be determined by detecting a classifier. If the category corresponding to the target entity state bitmap belongs to a malicious attack, an early warning process can be performed. In an embodiment of the present application, by utilizing a special data structure such as a state bitmap, it is possible to spend as little memory overhead as possible to save the system entity state information for a long time to cope with the long duration of APT attacks, thereby effectively detecting APT attacks and defending against APT attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0083] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0084] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0085] Figure 1 A flowchart of an advanced persistent threat attack detection method in an embodiment of the present application;
[0086] Figure 2 A schematic diagram of an advanced persistent threat attack detection method according to an embodiment of the present application;
[0087] Figure 3 This is another flow chart of the advanced persistent threat attack detection method in the embodiment of the present application;
[0088] Figure 4 This is another flow chart of the advanced persistent threat attack detection method in the embodiment of the present application;
[0089] Figure 5 This is another flow chart of the advanced persistent threat attack detection method in the embodiment of the present application;
[0090] Figure 6This is a structural diagram of an advanced persistent threat attack detection device in an embodiment of the present application;
[0091] Figure 7 This is a structural diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION
[0092] In order to more clearly understand the above-mentioned objectives, features and advantages of the present application, the scheme of the present application will be further described below. It should be noted that, in the absence of conflict, the embodiments of the present application and the features therein can be combined with each other.
[0093] In the following description, many specific details are set forth to facilitate a full understanding of the present application, but the present application can also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present application, not all of the embodiments.
[0094] Since the time span of an advanced persistent threat attack is long, the logs generated by the system during this period are difficult to estimate, and it is unrealistic to use massive logs for anomaly analysis in a short period of time. Based on the long duration of APT attacks, the extracted log features need to have cumulative (additive) properties. Only log features with cumulative properties can truly model long-term system behavior information and accurately capture APT attack behavior information. Therefore, an embodiment of the present application provides a log behavior modeling method that can use a message queue to process streaming host log information to express richer state semantics with as little memory overhead as possible.
[0095] Furthermore, the increasing stealthiness of advanced persistent threat attacks means that intrusion detection systems often miss novel, unknown attacks in the open world. Existing intrusion detection systems cannot address the problem of real attack data and known attack data not belonging to the same distribution, and therefore are ineffective in defending against open-world attacks. To effectively defend against advanced persistent threat attacks, embodiments of the present application provide an advanced persistent threat attack detection method, apparatus, electronic device, and storage medium that can identify out-of-distribution samples, that is, novel, unknown attacks.
[0096] The following first introduces in detail the advanced persistent threat attack detection method according to an embodiment of the present application.
[0097] See also Figure 1 , Figure 1 This is a flow chart of the advanced persistent threat attack detection method in an embodiment of the present application, which may include the following steps:
[0098] Step S110 : acquiring host log information, and determining a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set.
[0099] During the attack, corresponding host log information can be generated. Host log information refers to multi-level host log information, including but not limited to file system log information, process log information, network connection log information, call stack log information, registry log information, and so on. Host log information can be obtained through the operating system without relying on other applications. For example, for Windows systems, host log information can be obtained through ETW (Event Tracing for Windows), which is an efficient kernel-level event tracing tool suitable for most deployed Windows systems. For Linux systems, host log information can be obtained through Auditd, which is a good user-space component for tracking kernel events. Host log information can be stored in a message queue in chronological order. During the detection of advanced persistent threat attacks, each host log information can be obtained from the message queue in a streaming manner and processed. The processing process for each host log information is similar, and this is explained using one host log information as an example.
[0100] Before detecting advanced persistent threat attacks, we can analyze multi-layered host log information, extracting the behaviors and characteristics of all entities (e.g., processes, files, etc.) in both normally operating and attacked systems, and constructing a set of behavioral signature indicators. Each behavioral signature indicator in the set includes descriptive information, describing the state of a system entity. For example, descriptions in behavioral signature indicators might include "process deleting file" or "process renaming file."
[0101] In an embodiment of the present application, the host log information can be first mapped to a behavioral characteristic indicator, and then the behavioral characteristic indicator can be mapped to an entity state bitmap, so that a richer state semantics can be expressed with less memory overhead. Optionally, the host log information can be parsed to obtain key information, which refers to the key content in the host log information, including keywords, key phrases, etc. The key information is matched with the description information of each behavioral characteristic indicator in the behavioral characteristic indicator set to obtain target description information that matches the key information, and the behavioral characteristic indicator corresponding to the target description information is determined as the target behavioral characteristic indicator.
[0102] Step S120 , determining a target bit corresponding to the target behavior characteristic indicator in the entity state bitmap corresponding to the target behavior characteristic indicator according to a mapping relationship between the behavior characteristic indicator and the entity state bitmap and bits in the entity state bitmap.
[0103] The entity state bitmap is a data structure that can retain entity information over a long period of time. A mapping relationship can be established between the entity state bitmap and behavioral characteristic indicators. For example, every M bits in the entity state bitmap point to a behavioral characteristic indicator, where M is a positive integer. It should be noted that different types of entities can correspond to one entity state bitmap, meaning there can be only one entity state bitmap. In this case, a direct mapping relationship can be established between the bits in the entity state bitmap and the behavioral characteristic indicators.
[0104] Alternatively, each entity has a corresponding entity state bitmap. In this case, a mapping relationship between the behavioral characteristic indicator and the entity state bitmap can be established first, and then a mapping relationship between the behavioral characteristic indicator and the bits in the entity state bitmap can be established, and finally a mapping relationship between the behavioral characteristic indicator and the entity state bitmap, and the bits in the entity state bitmap can be established.
[0105] Optionally, each behavior characteristic indicator may include not only the description information of the behavior characteristic indicator but also the index information of the behavior characteristic indicator. According to the description information of each behavior characteristic indicator in the characteristic indicator set, the entity to which the behavior characteristic indicator belongs is determined. Since each entity has a corresponding entity state bitmap, a mapping relationship between the behavior characteristic indicator and the entity state bitmap can be established. Furthermore, according to the index information of each behavior characteristic indicator in the characteristic indicator set, the corresponding bit of the behavior characteristic indicator in the entity state bitmap corresponding to the behavior characteristic indicator is set to establish a mapping relationship between the behavior characteristic indicator and the entity state bitmap, and the bits in the entity state bitmap. For example, every M bits point to a behavior characteristic indicator. When the index information is 0, it corresponds to the 1st to Mth bits in the entity state bitmap; when the index information is 1, it corresponds to the M+1 to 2Mth bits in the entity state bitmap; when the index information is 2, it corresponds to the 2M+1 to 3Mth bits in the entity state bitmap, and so on.
[0106] After determining the target behavior characteristic indicator corresponding to the host log information, the entity state bitmap corresponding to the target behavior characteristic indicator and the corresponding target bit in the entity state bitmap can be determined according to the above mapping relationship.
[0107] Step S130 : setting the value of the target bit according to the target behavior characteristic index to obtain a target entity state bitmap.
[0108] In an embodiment of the present application, each behavioral characteristic indicator in the behavioral characteristic indicator set may further include: level information of the behavioral characteristic indicator. For the same behavioral characteristic indicator, if the level information of the behavioral characteristic indicator is different, the corresponding description information may also be different, but describe the same content. For example, the behavioral characteristic indicator with index information of 0 includes three level information of 1, 2, and 3. The description information corresponding to level information 1 is "process deletes files", the description information corresponding to level information 2 is "process deletes many files (10-100)", and the description information corresponding to level information 3 is "process deletes a large number of files (more than 100)". The behavioral characteristic indicators in the behavioral characteristic indicator set can be found in Table 1.
[0109] Table 1
[0110]
[0111]
[0112] When the behavior characteristic indicator includes level information, each behavior characteristic indicator corresponds to S bits in the entity state bitmap corresponding to the behavior characteristic indicator, where S is an integer greater than 1. The S bits contained in the target bitmap are set to a value equal to the level information of the target behavior characteristic indicator. When S is 2, it can represent 4 levels, and when S is 3, it can represent 8 levels. As the number of levels increases, the value of S can be increased.
[0113] It should be noted that the initial value of each bit in each entity status bitmap is 0. Assume that S is 2, the level information is 0, and the value of the two bits is 00; the level information is 1, and the value of the two bits is 01; the level information is 2, and the value of the two bits is 10; the level information is 3, and the value of the two bits is 11.
[0114] In the embodiment of the present application, pre-designed state transition rules can also be used to assist in updating the entity state bitmap. For example, for the two behavioral characteristic indicators of the process having external network communication (index information is 4) and the parent process having external network communication (index information is 6), when an operation log of the parent process creating a child process appears, the value of the bit corresponding to index information 6 will be determined by determining whether the value of the bit corresponding to index information 4 has been set.
[0115] Each host log information can be mapped to a corresponding entity status bitmap in the above manner, and the value of the corresponding target bit is set in the corresponding entity status bitmap to obtain a target entity status bitmap.
[0116] Step S140 : When the target entity state bitmap changes, the target entity state bitmap is input into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap.
[0117] When setting the value of a bit in the entity status bitmap, the value of the bit may or may not change. For example, for the aforementioned behavioral characteristic indicator of a process deleting a file, when the content of the process deleting a file appears in the host log information for the first time, the level information of the behavioral characteristic indicator is 1, and the corresponding bit is updated from the initial value 00 to 01. When the content of the process deleting a file appears again in the subsequent host log information, the value of the corresponding bit is still set to 01. At this time, the value of the bit has not changed, that is, the target entity status bitmap has not changed. When the number of times the content of the process deleting a file appears in the host log information reaches 10, the level information changes from 1 to 2, and the value of the corresponding bit is set to 10. At this time, the value of the bit has changed, that is, the target entity status bitmap has changed.
[0118] When the target entity state bitmap changes, the pre-trained detection classifier is used to classify the target entity state bitmap to obtain the category corresponding to the target entity state bitmap. The category corresponding to the target entity state bitmap refers to the various attack stages of the APT attack.
[0119] When training a detection classifier, in order to adapt to various APT attack scenarios, the embodiment of the present application collects a large data set containing behavioral feature information of entities after being attacked by APT. According to the above method, the behavioral feature information is mapped to the entity state bitmap to obtain a sample entity state bitmap, and the sample entity state bitmap is annotated to obtain label data. For example, under the guidance of a security expert, all sample state bitmap samples are grouped into clearly defined attack stages. The total number of attack stages corresponding to different entities can be different. For example, for a process entity, the attack stages can include 10, namely:
[0120] 1) Benign: Various activities performed by ordinary users during daily use, and this process only has normal behavior;
[0121] 2) Initial access: This process allows the attacker to gain an initial foothold on the target system.
[0122] 3) Execution: This process allows an attacker to run malicious code on the target system.
[0123] 4) Persistence: The process allows the attacker to maintain access to the target system;
[0124] 5) Privilege escalation: This process allows an attacker to gain higher privileges on the target system.
[0125] 6) Credential access: This process allows an attacker to gain access to the target system's legitimate credentials.
[0126] 7) Discovery: This process allows attackers to obtain information about the target system host or intranet.
[0127] 8) Lateral Movement: This process involves the attacker expanding their base into the target system's intranet.
[0128] 9) Command and Control: This process allows attackers to establish network control and communication channels on the target system.
[0129] 10) Impact: This process allows an attacker to achieve their ultimate goal (theft, destruction, etc.) on the target system.
[0130] For file entities, the attack phases can include four:
[0131] 1) Benign: The file has only normal features;
[0132] 2) Initial access: The file contains characteristics that indicate an attacker has gained an initial foothold on the target system.
[0133] 3) Execution: The file contains characteristics that allow an attacker to run malicious code on the target system;
[0134] 4) Impact: This file contains characteristics that allow the attacker to achieve the ultimate goal (theft, destruction, etc.) on the target system.
[0135] It should be noted that, for process entities and file entities, the above attack stages, except for the benign ones, are different stages of malicious attacks.
[0136] Using the sample entity state bitmap and the label data corresponding to the sample entity state bitmap, a detection classifier can be trained and generated. After the target entity state bitmap is input into the detection classifier, the corresponding category can be output, that is, the attack stage.
[0137] Step S150: If the category corresponding to the target entity status bitmap belongs to a malicious attack, corresponding warning processing is performed according to the category corresponding to the target entity status bitmap.
[0138] If the target entity status bitmap corresponds to a benign category, no action is taken. If the target entity status bitmap corresponds to a malicious attack, an alert can be provided to security personnel. For example, the target entity status bitmap category can be provided to inform security personnel of the current attack phase, allowing them to perform different actions based on the attack phase.
[0139] See also Figure 2, Figure 2 This is a schematic diagram of the advanced persistent threat attack detection method in the embodiment of the present application. By introducing a behavioral characteristic indicator for describing the state of a system entity, the behavior of the entity is extracted from the host log information, that is, the host log information is mapped to a target behavioral characteristic indicator corresponding to the host log information. Furthermore, the target behavioral characteristic indicator is mapped to a target entity state bitmap. Afterwards, the category corresponding to the target entity state bitmap can be determined by detecting a classifier. If the category corresponding to the target entity state bitmap belongs to a malicious attack, an early warning process can be performed. In the embodiment of the present application, by utilizing a special data structure such as a state bitmap, as little memory overhead as possible can be spent to save the system entity state information for a long time to cope with the long duration of APT attacks, thereby effectively detecting APT attacks and defending against APT attacks.
[0140] In an embodiment of the present application, the detection classifier may include a first branch module and a second branch module. The first branch module is used to classify the entity state bitmap, and the second branch module is used to reconstruct the state bitmap when an unknown sample is identified and further identify the category of the unknown sample. The second branch module includes an encoder and a decoder. The encoder is used to encode the entity state bitmap x to obtain the potential feature z of the entity state bitmap.
[0141] The decoder is used to decode the potential features and reconstruct the potential features into a pseudo-entity state bitmap
[0142] Since the target entity state bitmap is a sequence of 0s and 1s, and the behavioral characteristics of system entities are uncertain, the target entity state bitmap is usually sparse, with most of the content being 0. A large number of 0s can easily cause the gradient to vanish during the backpropagation process of deep learning model training, leading to failure in neural network modeling. To avoid this, three layers of one-dimensional convolution can be used as an encoder during the latent feature extraction process. Each layer contains N filters, and the convolution kernel size, stride, and dilation of each filter can all be 1, where N represents the total number of categories. For the entity state bitmap, any reduction in information is intolerable. The encoder can maintain the data length at L, and the sensitive features of N categories are extracted by N filters.
[0143] Similar to the encoder, the decoder uses three layers of one-dimensional convolution. The first two layers contain N filters, designed to learn features for N categories. The final output layer aggregates the features and reconstructs the entity state bitmap, resulting in a pseudo entity state bitmap. To ensure the semantic integrity of the target entity state bitmap, the decoder must not destroy its shape. Therefore, the convolution kernel size, stride, and dilation of all layers can be set to 1.
[0144] To optimize the reconstruction process, for a batch of size m, the decoder uses the mean square loss function of formula (1) as a constraint:
[0145]
[0146] In an embodiment of the present application, the accuracy of the detection classifier in classifying the entity state bitmap can be improved by reducing the intra-class distance and increasing the inter-class distance. The classifier accepts a potential feature z of size N×L, where N represents the total number of categories and L represents the length of the entity state bitmap, which is related to the total number of behavioral feature indicators in the behavioral feature indicator set. Each 1×L vector represents the characteristics of a specific category. For each 1×L vector, a one-dimensional convolutional layer and a fully connected layer with shared weights are used for further feature extraction. Maximum pooling is used to capture the most critical features and output a perceptual feature tensor v of size N×K, where K represents the length of the critical feature. The present application expects the vector v representing the i-th class in the perceptual feature tensor v to be i Therefore, the center loss is used as a metric, as shown in formula (2):
[0147]
[0148] Among them, ω i Represents class C i The mean center of the i-th class C i The kind of heart.
[0149] Finally, a fully connected layer receives the perceptual feature tensor v and outputs the activation vector y. As shown in formula (3):
[0150]
[0151] Softmax is used to calculate the probability of each classification, and the cross entropy loss function is used as the classification loss, as shown in formula (4):
[0152]
[0153] In summary, the total loss of the detection classifier is and The sum of is shown in formula (5):
[0154]
[0155] in, The weight is low, and The weights of are higher and can be the same, so α=γ=1, β=0.1.
[0156] The detection classifier of the embodiment of the present application can detect out-of-distribution samples, thereby avoiding misclassification of out-of-distribution samples (i.e., unknown samples) as known samples. Unknown samples can be identified by Openmax, which is an extension of Softmax in real-world data. In the existing classification model, the length of the activation vector y is the same as the number of categories, so unknown categories cannot be identified. In the embodiment of the present application, a new unknown category can be added, and y can be expanded to And calculate the probability, as shown in formula (6) and formula (7):
[0157]
[0158]
[0159] Among them, x represents the input entity state bitmap, w i Indicates that x belongs to the known category C i Confidence, that is, x belongs to the known category C i The probability of N is the total number of known categories, C N+1 Indicates an unknown category.
[0160] w i It can be expressed as P(x∈C i ), based on the Wilbur distribution, P(x∈C i ) is shown in formula (8):
[0161]
[0162] η i and m i According to C i The parameters of the Weibull distribution estimated from the training data set, dis(x, C i ) represents x and C i The closeness is shown in formula (9):
[0163] dis(x,C i )=|[y,v i ]-ω i |2 (9)
[0164] ω i Represents class C i The mean center, v i Denotes the i-th class in v, where i is the true known class index in the training data and the predicted class in the test unknown data. F(α,i) is a penalty function governed by the hyperparameter α, which gives a greater penalty to classes with higher confidence, as shown in formula (10):
[0165]
[0166] Here, rank(i) is the index list of y in descending order.
[0167] See also Figure 3 , Figure 3 This is another flow chart of the advanced persistent threat attack detection method in the embodiment of the present application, which may include the following steps:
[0168] Step S302 : acquiring host log information, and determining a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set; wherein the behavior characteristic indicator is used to describe the status of a system entity.
[0169] Step S304: determining a target bit corresponding to the target behavior characteristic indicator in the entity state bitmap corresponding to the target behavior characteristic indicator according to a mapping relationship between the behavior characteristic indicator and the entity state bitmap and bits in the entity state bitmap.
[0170] Step S306: setting the target bit value according to the target behavior characteristic index to obtain a target entity state bitmap.
[0171] The above steps S302 to S306 are Figure 1 The same embodiment, see Figure 1 The description in the embodiment is sufficient and will not be repeated here.
[0172] Step S308 , when the target entity state bitmap changes, the target entity state bitmap is input into a pre-trained detection classifier, and the target entity state bitmap is classified by the first branch module to obtain a category corresponding to the target entity state bitmap.
[0173] The detection classifier can specifically classify the target entity state bitmap through the first branch module to obtain the category corresponding to the target entity state bitmap. In the embodiment of the present application, the structure of the first branch module is not limited.
[0174] Step S310: If the category corresponding to the target entity status bitmap belongs to a malicious attack, corresponding warning processing is performed according to the category corresponding to the target entity status bitmap.
[0175] Step S312: If the category corresponding to the target entity state bitmap is an out-of-distribution sample, extract the potential features of the target entity state bitmap through an encoder.
[0176] If the category corresponding to the target entity state bitmap is an out-of-distribution sample, the target entity state bitmap can be processed by the second encoding module to analyze the category corresponding to the target entity state bitmap and the behavior corresponding to the host log information. First, the encoder can be used to extract the potential features of the target entity state bitmap.
[0177] Step S314 : selecting a target latent feature that is closest to the latent feature of the target entity state bitmap from the latent features corresponding to the sample state bitmap.
[0178] The sample state bitmap refers to an entity state bitmap whose corresponding category is a known category, for example, it may include a sample entity state bitmap used when training a detection classifier, and an entity state bitmap of a corresponding category that has been detected during real-time detection.
[0179] Similar to the target entity state bitmap, the encoder can be used to extract the latent features of each sample state bitmap. By comparing the latent features of the target entity state bitmap with the corresponding latent features of each sample state bitmap, the closest target latent feature can be obtained. For example, the distance between the latent features of the target entity state bitmap and the latent features corresponding to each sample state bitmap can be calculated, and the latent feature with the smallest distance can be used as the target latent feature.
[0180] Step S316 , determining the category corresponding to the target entity state bitmap according to the category of the sample state bitmap corresponding to the target potential feature.
[0181] Since the category of the sample state bitmap corresponding to the target latent feature is known, and the target latent feature is closest to the latent feature of the target entity state bitmap, the category corresponding to the target entity state bitmap can be determined based on the category of the sample state bitmap corresponding to the target latent feature. For example, the category of the sample state bitmap corresponding to the target latent feature can be directly used as the category corresponding to the target entity state bitmap. Alternatively, based on the category of the sample state bitmap corresponding to the target latent feature, further analysis can be performed in combination with the host log information to determine the category corresponding to the target entity state bitmap.
[0182] Step S318: decoding the target potential features through a decoder to obtain a pseudo entity state bitmap.
[0183] The decoder is used to reconstruct the latent features into an entity state bitmap, and the pseudo entity state bitmap refers to the reconstructed entity state bitmap.
[0184] Step S320 : analyzing the behavior corresponding to the host log information by comparing the target entity state bitmap and the pseudo entity state bitmap.
[0185] It should be noted that by comparing the target entity state bitmap with the sample state bitmap corresponding to the target potential feature, the behavior corresponding to the host log information can also be analyzed. However, it is necessary to store all the sample state bitmaps and the potential features corresponding to the sample state bitmaps, which requires a large amount of storage space. To reduce the amount of data storage, the potential features corresponding to the sample state bitmaps can be stored. By comparing the target entity state bitmap with the pseudo-entity state bitmap, the behavior corresponding to the host log information can be analyzed.
[0186] When comparing the target entity state bitmap and the pseudo-entity state bitmap, you can search for bits where the corresponding values in the pseudo-entity state bitmap differ from those in the target entity state bitmap. For example, the target entity state bitmap matches one more behavioral characteristic indicator than the pseudo-entity state bitmap, with an index of 195 and a level of 1. The corresponding description is: "The process uses whoami to query system user information." Small differences can lead to drastically different results. The target entity state bitmap is in the discovery phase of an APT attack, while the pseudo-entity state bitmap is a benign sample. This allows analysts to quickly analyze unknown behaviors by focusing solely on the different behavioral characteristic indicators, eliminating the need to spend significant time analyzing logs line by line, thus improving the efficiency of analyzing unknown behaviors.
[0187] See also Figure 4 , Figure 4 This is another flow chart of the advanced persistent threat attack detection method in the embodiment of the present application. Figure 1 Based on the embodiment, the following steps may also be included:
[0188] Step S410: If the category corresponding to the target entity status bitmap is an out-of-distribution sample, the target entity status bitmap and host log information are stored.
[0189] If the category corresponding to the target entity status bitmap is an out-of-distribution sample, this indicates that the detection classifier has never encountered this sample during training. The target entity status bitmap and host log information can be stored to update the training sample and, in turn, the detection classifier. This way, if the same or similar host log information appears again, the updated detection classifier can identify the corresponding category.
[0190] Step S420: Determine the category corresponding to the target entity status bitmap based on the host log information.
[0191] In this embodiment of the present application, the target entity status bitmap and host log information can be stored in an unknown sample set. When the amount of data in the unknown sample set reaches a certain amount, the unknown samples can be classified through clustering, similarity calculation, or intervention by security experts, that is, label data can be set for the target entity status bitmap.
[0192] Step S430 : updating the detection classifier based on the target entity state bitmap and the category corresponding to the target entity state bitmap.
[0193] On the basis of the original training data set (sample entity state bitmap and the categories corresponding to the sample entity state bitmap), the target entity state bitmap and the categories corresponding to the target entity state bitmap are added to the training data set as new training data, and the new detection classifier is retrained so that the new detection classifier can detect more categories.
[0194] See also Figure 5 , Figure 5 This is another flow chart of the advanced persistent threat attack detection method in the embodiment of the present application. Figure 1 Based on the embodiment, the following steps may also be included:
[0195] Step S112: After acquiring the host log information, the host log information and index information of the host log information are stored in a database.
[0196] In an embodiment of the present application, since the host log information has a corresponding generation time, index information can be established for the host log information based on the generation time. After each time the host log information is obtained, the host log information and the index information can be stored in a database. In this way, when it is detected that the category of the target entity status bitmap is a malicious attack, the corresponding host log information can be found based on the target entity status bitmap, that is, the target entity status bitmap is mapped to the corresponding behavioral characteristic indicator, and then the behavioral characteristic indicator is mapped to the host log information. Storing the host log information and the index information of the host log information in the database can avoid the memory space occupied by a large amount of host log information and reduce memory overhead.
[0197] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: critical identification information of the behavior characteristic indicator. When the critical identification information of the target behavior characteristic indicator corresponding to the host log information is critical, the host log information and the index information of the host log information are stored in the database. When the critical identification information of the target behavior characteristic indicator corresponding to the host log information is not critical, the host log information and the index information of the host log information are not stored in the database, thereby avoiding storing all the host log information.
[0198] Step S510 : If the category corresponding to the target entity status bitmap belongs to malicious attack, the index information of the hit behavior feature indicator and the level information of the index information of the hit behavior feature indicator are determined according to the value of each bit in the target entity status bitmap.
[0199] According to the mapping relationship between the behavior feature indicator and the entity state bitmap, and the bits in the entity state bitmap, the index information and level information of the hit behavior feature indicator can be determined according to the value of each bit in the target entity state bitmap.
[0200] Assume that two bits in the entity state bitmap point to a behavior characteristic indicator. The first 8 bits of the target entity state bitmap are <11, 10, 01, 00>, indicating the first 4 behavior characteristic indicators. Combined with Table 1, from left to right, every 2 bits represent:
[0201] <11> : Hit, level 3, indicating that the process has deleted more than 100 files.
[0202] <10> : Hit, level 2, indicating that the number of files with the same name as the process exceeds 10 but does not exceed 100.
[0203] <01> : Hit, level 1, indicating that the process accessed data from the network.
[0204] <00> : Missed, level 0, indicating that the process has no intranet communication.
[0205] Step S520, based on the mapping relationship among entity identification information, index information of behavior characteristic indicators, level information of behavior characteristic indicators and index information of log information, determine the target index information corresponding to the entity identification information corresponding to the target entity status bitmap, the index information of the hit behavior characteristic indicators and the level information of the hit behavior characteristic indicators.
[0206] The mapping relationship between entity identification information, index information of behavior characteristic indicators, level information of behavior characteristic indicators and index information of log information can be expressed in the form of a quadruple.<entity_uuid,bfi_index,bfi_level,log_index> , where entity_uuid is the entity identifier, used to locate the entity; bfi_index represents the index of the hit behavior feature indicator; bfi_level represents the level of the hit behavior feature indicator; and log_index represents the index of the host log information, used to locate the host log information. These four elements enable reversibility from behavior feature indicators to host log information.
[0207] Step S530: Obtain host log information corresponding to the target index information from the database.
[0208] The embodiments of the present application implement forward reasoning from host log information to behavioral feature indicators, and then from behavioral feature indicators to entity state bitmaps; as well as reverse reasoning from entity state bitmaps back to behavioral feature indicators, and then from behavioral feature indicators back to host log information, together forming a three-phase reversible link. At the same time, this three-phase reversible link provides interpretability for the extracted log feature results (state bitmap).
[0209] Corresponding to the above method embodiment, the present application embodiment also provides an advanced persistent threat attack detection device, see Figure 6 The advanced persistent threat attack detection device 600 includes:
[0210] Host log information acquisition module 610, used to obtain host log information;
[0211] The target behavior characteristic indicator determination module 620 is used to determine the target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set; wherein the behavior characteristic indicator is used to describe the status of the system entity;
[0212] A target bit determination module 630 is configured to determine a target bit corresponding to the target behavior characteristic indicator in the entity state bitmap corresponding to the target behavior characteristic indicator based on a mapping relationship between the behavior characteristic indicator and the entity state bitmap and bits in the entity state bitmap;
[0213] The target entity state bitmap determination module 640 is used to set the value of the target bit according to the target behavior characteristic index to obtain the target entity state bitmap;
[0214] A classification module 650 is configured to input the target entity state bitmap into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap when the target entity state bitmap changes;
[0215] The warning processing module 660 is configured to perform corresponding warning processing according to the category corresponding to the target entity status bitmap if the category corresponding to the target entity status bitmap belongs to a malicious attack.
[0216] Optionally, the advanced persistent threat attack detection device 600 further includes:
[0217] A host log information storage module is used to store the target entity state bitmap and the host log information if the category corresponding to the target entity state bitmap is an out-of-distribution sample;
[0218] A first category determination module is used to determine the category corresponding to the target entity status bitmap based on the host log information;
[0219] The detection classifier updating module is used to update the detection classifier based on the target entity state bitmap and the category corresponding to the target entity state bitmap.
[0220] Optionally, the detection classifier includes a first branch module and a second branch module, and the second branch module includes an encoder and a decoder;
[0221] The classification module 650 is specifically configured to input the target entity state bitmap into a pre-trained detection classifier when the target entity state bitmap changes, classify the target entity state bitmap through the first branch module, and obtain a category corresponding to the target entity state bitmap;
[0222] The advanced persistent threat attack detection device 600 further includes:
[0223] a latent feature extraction module, configured to extract latent features of the target entity state bitmap through an encoder if the category corresponding to the target entity state bitmap is an out-of-distribution sample;
[0224] A target potential feature determination module is used to select a target potential feature that is closest to the potential feature of the target entity state bitmap from the potential features corresponding to the sample state bitmap;
[0225] A second category determination module is used to determine the category corresponding to the target entity state bitmap based on the category of the sample state bitmap corresponding to the target potential feature;
[0226] A pseudo-entity state bitmap determination module is used to decode the target potential features through a decoder to obtain a pseudo-entity state bitmap;
[0227] The behavior analysis module is used to analyze the behavior corresponding to the host log information by comparing the target entity state bitmap and the pseudo entity state bitmap.
[0228] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: description information and index information of the behavior characteristic indicator;
[0229] The advanced persistent threat attack detection device 600 further includes:
[0230] A corresponding entity determination module is used to determine the entity to which the behavior characteristic indicator belongs based on the description information of each behavior characteristic indicator in the characteristic indicator set, and each entity has a corresponding entity state bitmap;
[0231] A first mapping relationship establishing module, configured to establish a mapping relationship between a behavior characteristic indicator and an entity state bitmap;
[0232] The second mapping relationship establishment module is used to set the corresponding bit of the behavior characteristic indicator in the entity state bitmap corresponding to the behavior characteristic indicator according to the index information of each behavior characteristic indicator in the characteristic indicator set, so as to establish a mapping relationship between the behavior characteristic indicator and the entity state bitmap, and the bits in the entity state bitmap.
[0233] Optionally, the target behavior characteristic indicator determination module 620 is specifically used to parse the host log information to obtain key information; match the key information with the description information of each behavior characteristic indicator in the behavior characteristic indicator set to obtain target description information that matches the key information; and determine the behavior characteristic indicator corresponding to the target description information as the target behavior characteristic indicator.
[0234] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: level information of the behavior characteristic indicator, each behavior characteristic indicator corresponds to S bits in the entity state bitmap corresponding to the behavior characteristic indicator, where S is an integer greater than 1;
[0235] The target entity state bitmap determination module 640 is specifically configured to set the S bits included in the target bitmap to a value equal to the level information of the target behavior feature indicator to obtain the target entity state bitmap.
[0236] Optionally, the advanced persistent threat attack detection device 600 further includes:
[0237] A host log information storage module is used to store host log information and index information of host log information in a database;
[0238] A hit behavior characteristic indicator determination module is used to determine the index information of the hit behavior characteristic indicator and the level information of the index information of the hit behavior characteristic indicator according to the value of each bit in the target entity state bitmap if the category corresponding to the target entity state bitmap belongs to a malicious attack;
[0239] A target index information determination module is used to determine the target index information corresponding to the entity identification information corresponding to the target entity state bitmap, the index information of the hit behavior characteristic indicator, and the level information of the hit behavior characteristic indicator based on the mapping relationship between the entity identification information, the index information of the behavior characteristic indicator, the level information of the behavior characteristic indicator, and the index information of the log information;
[0240] The host log information search module is used to obtain the host log information corresponding to the target index information from the database.
[0241] Optionally, each behavior characteristic indicator in the behavior characteristic indicator set includes: key identification information of the behavior characteristic indicator;
[0242] The host log information storage module is specifically used to store the host log information and the index information of the host log information in the database when the key identification information of the target behavior characteristic indicator corresponding to the host log information is key.
[0243] The specific details of each module or unit in the above device have been described in detail in the corresponding method, so they will not be repeated here.
[0244] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiment of the application, the features and functions of two or more modules or units described above can be concretized in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.
[0245] In an exemplary embodiment of the present application, an electronic device is further provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to execute the above-mentioned advanced persistent threat attack detection method in this exemplary embodiment.
[0246] Figure 7 This is a schematic diagram of the structure of an electronic device in an embodiment of the present application. It should be noted that, Figure 7 The electronic device 700 shown is only an example and should not limit the functions and scope of use of the embodiments of the present application.
[0247] like Figure 7 As shown, electronic device 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes according to the program stored in read-only memory (ROM) 702 or the program loaded from storage portion 708 into random access memory (RAM) 703. Various programs and data required for system operation are also stored in RAM 703. Central processing unit 701, ROM 702 and RAM 703 are connected to each other via bus 704. Input / output (I / O) interface 705 is also connected to bus 704.
[0248] The following components are connected to the I / O interface 705: an input section 706 including a keyboard, a mouse, and the like; an output section 707 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 708 including devices such as a hard disk; and a communication section 709 including a network interface card such as a local area network (LAN) card or a modem. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 710 as needed, so that computer programs read therefrom can be installed into the storage section 708 as needed.
[0249] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 709 and / or installed from the removable medium 711. When the computer program is executed by the central processing unit 701, the various functions defined in the apparatus of the present application are performed.
[0250] In an embodiment of the present application, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned advanced persistent threat attack detection method is implemented.
[0251] It should be noted that the computer-readable storage medium shown in this application can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device or device. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, radio frequency, etc., or any suitable combination thereof.
[0252] In an embodiment of the present application, a computer program product is further provided. When the computer program product is run on a computer, the computer is caused to execute the above-mentioned advanced persistent threat attack detection method.
[0253] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0254] The foregoing description is intended only to provide specific embodiments of the present application, which will enable those skilled in the art to understand and implement the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments described herein, but is intended to be construed in the broadest manner consistent with the principles and novel features disclosed herein.
Claims
1. A method for detecting advanced persistent threat attacks, characterized in that: include: Acquire host log information and determine a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set; wherein the behavior characteristic indicator is used to describe the status of a system entity; Determine, according to a mapping relationship between the behavior characteristic indicator and the entity state bitmap and the bits in the entity state bitmap, a target bit corresponding to the target behavior characteristic indicator in the entity state bitmap corresponding to the target behavior characteristic indicator; According to the target behavior characteristic indicator, the value of the target bit is set to obtain a target entity state bitmap; In the case where the target entity state bitmap changes, inputting the target entity state bitmap into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap; If the category corresponding to the target entity status bitmap belongs to a malicious attack, corresponding warning processing is performed according to the category corresponding to the target entity status bitmap.
2. The method according to claim 1, characterized in that After obtaining the category corresponding to the target entity state bitmap, the method further includes: If the category corresponding to the target entity status bitmap is an out-of-distribution sample, storing the target entity status bitmap and the host log information; Determining a category corresponding to the target entity status bitmap based on the host log information; The detection classifier is updated based on the target entity state bitmap and the category corresponding to the target entity state bitmap.
3. The method according to claim 1, characterized in that The detection classifier includes a first branch module and a second branch module, and the second branch module includes an encoder and a decoder; Inputting the target entity state bitmap into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap includes: Inputting the target entity state bitmap into a pre-trained detection classifier, classifying the target entity state bitmap through the first branch module to obtain a category corresponding to the target entity state bitmap; The method further comprises: If the category corresponding to the target entity state bitmap is an out-of-distribution sample, extracting potential features of the target entity state bitmap by the encoder; Selecting a target latent feature that is closest to the latent feature of the target entity state bitmap from the latent features corresponding to the sample state bitmap; Determining the category corresponding to the target entity state bitmap according to the category of the sample state bitmap corresponding to the target potential feature; Decoding the target potential features by the decoder to obtain a pseudo-entity state bitmap; By comparing the target entity state bitmap and the pseudo entity state bitmap, the behavior corresponding to the host log information is analyzed.
4. The method according to claim 1, wherein Each behavior characteristic indicator in the behavior characteristic indicator set includes: description information and index information of the behavior characteristic indicator; The method further comprises: Determine the entity to which the behavior characteristic indicator belongs based on the description information of each behavior characteristic indicator in the characteristic indicator set, each entity having a corresponding entity state bitmap; Establish a mapping relationship between behavioral characteristic indicators and entity state bitmaps; According to the index information of each behavior characteristic indicator in the characteristic indicator set, the corresponding bit of the behavior characteristic indicator in the entity state bitmap corresponding to the behavior characteristic indicator is set to establish a mapping relationship between the behavior characteristic indicator and the entity state bitmap, and the bits in the entity state bitmap.
5. The method according to claim 4, characterized in that Determining a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set includes: Parsing the host log information to obtain key information; Matching the key information with the description information of each behavior characteristic indicator in the behavior characteristic indicator set to obtain target description information that matches the key information; The behavior characteristic indicator corresponding to the target description information is determined as the target behavior characteristic indicator.
6. The method according to claim 4, characterized in that Each behavior characteristic indicator in the behavior characteristic indicator set includes: level information of the behavior characteristic indicator, each behavior characteristic indicator corresponds to S bits in the entity state bitmap corresponding to the behavior characteristic indicator, where S is an integer greater than 1; The setting of the target bit value according to the target behavior characteristic indicator includes: The S bits included in the target bit are set to a value equal to the level information of the target behavior feature indicator.
7. The method according to claim 6, characterized in that The method further comprises: After acquiring the host log information, storing the host log information and index information of the host log information in a database; If the category corresponding to the target entity status bitmap belongs to malicious attack, determining the index information of the hit behavior feature indicator and the level information of the index information of the hit behavior feature indicator according to the value of each bit in the target entity status bitmap; Based on the mapping relationship among the entity identification information, the index information of the behavior characteristic indicator, the level information of the behavior characteristic indicator and the index information of the log information, the target index information corresponding to the entity identification information corresponding to the target entity state bitmap, the index information of the hit behavior characteristic indicator and the level information of the hit behavior characteristic indicator is determined; The host log information corresponding to the target index information is obtained from the database.
8. The method according to claim 7, characterized in that Each behavior characteristic indicator in the behavior characteristic indicator set includes: key identification information of the behavior characteristic indicator; The storing of the host log information and the index information of the host log information in a database includes: In a case where the critical identification information of the target behavior characteristic indicator corresponding to the host log information is critical, the host log information and the index information of the host log information are stored in a database.
9. An advanced persistent threat attack detection device, characterized in that: The device comprises: Host log information acquisition module, used to obtain host log information; A target behavior characteristic indicator determination module is used to determine a target behavior characteristic indicator corresponding to the host log information in a pre-established behavior characteristic indicator set; wherein the behavior characteristic indicator is used to describe the state of the system entity; A target bit determination module is used to determine the target bit corresponding to the target behavior characteristic indicator in the entity state bitmap corresponding to the target behavior characteristic indicator according to the mapping relationship between the behavior characteristic indicator and the entity state bitmap and the bits in the entity state bitmap; a target entity state bitmap determination module, configured to set the value of the target bit according to the target behavior characteristic indicator to obtain a target entity state bitmap; a classification module, configured to input the target entity state bitmap into a pre-trained detection classifier to obtain a category corresponding to the target entity state bitmap when the target entity state bitmap changes; The early warning processing module is used to perform corresponding early warning processing according to the category corresponding to the target entity status bitmap if the category corresponding to the target entity status bitmap belongs to a malicious attack.
10. An electronic device, characterized in that: include: A processor, wherein the processor is configured to execute a computer program stored in a memory, wherein the computer program, when executed by the processor, implements the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Method for judging advanced persistent threat attacks
CN108229153A
Preventing advanced persistent threat attack
US20210112092A1