A one-touch attack event identification method
By acquiring security alert data in real time from network security devices and automatically identifying dial-up attack events using a sliding time window and a dial-up attack index, the technology solves the problem of lack of automated identification in existing technologies, achieving efficient and accurate dial-up attack identification and reducing enterprise costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-31
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies lack automated methods for identifying instant dialing attacks, resulting in insufficient objectivity in identification and increased labor costs for enterprises.
By acquiring security alarm data from network security devices in real time, and using a sliding time window approach, the system counts the IP addresses of attack sources and the number of attacks. It then uses the sliding window and the instant dialing attack index to automatically identify instant dialing attack events and dynamically adjusts parameters to improve the objectivity and accuracy of the identification.
It achieves automated identification of dial-up attack events, reduces labor costs, and improves the objectivity and accuracy of identification. It is applicable to dial-up attack events of different durations.
Smart Images

Figure CN116743444B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a second dialing attack event identification method. BACKGROUND
[0002] In early attack and defense, attackers usually use fixed IP addresses to launch network attacks on target units. Enterprises can block all attacks from the IP address by setting up an IP blacklist. In order to bypass the IP blocking rules of enterprises, attackers have developed "second dialing" technology. Second dialing attack is a new concept that appeared in the form of a prototype in 2018 and was officially proposed in 2021.
[0003] After mastering a large number of broadband line resources, using the principle of automatic IP switching when the home broadband dial-up connection is disconnected, any IP in the IP address pool can be switched within seconds. The second dialing IP address pool usually has hundreds to hundreds of thousands of available IP addresses. By using second dialing technology, after launching a small number of attacks using a certain IP, the attacker quickly switches to any other IP address in the IP address pool and launches the same type of attack again. The essential feature of second dialing attack is that the attacker can use second dialing technology to attack specific target IP address information system assets through thousands of IP addresses, and each IP address only performs a small number of network attacks on the target system before switching to a new IP address. Among them, information system assets include hardware assets or software assets; hardware assets include but are not limited to computers, servers, network devices, security devices, etc.; software assets include but are not limited to system software, application software, business platform, etc.
[0004] The technical core of second dialing attack is to use distributed proxy servers to disperse the attack behavior of a single attacker to hundreds of thousands of proxy IP addresses, thereby destroying the traditional protection system that blocks attacks by banning IP addresses. The traditional IP blocking strategy mainly targets IP addresses that launch a large number of attacks at the same time. In order to evade the IP blocking strategy of enterprises, attackers use second dialing IP to launch attacks; after launching a small number of attacks using a certain IP, the attacker quickly switches to another IP for attack. Its typical feature is that in a short period of time, a small number of the same type of attacks are launched on the same asset from a large number of different random IP addresses.
[0005] That is, second dialing is carried out by using the principle that each time the home broadband dial-up connection (PPPoE) is disconnected and reconnected, a new random IP is automatically obtained. After deploying automatic disconnection and reconnection IP switching and attack tools, the attacker can have tens of thousands of random IP address pools by renting a large number of broadband line resources. After launching an attack, the attacker can quickly switch to any other IP address in the IP address pool to launch an attack again. Since it is difficult for enterprises to put tens of thousands of random IP addresses into the blacklist, second dialing attack can bypass the normal defense of enterprises.
[0006] The issue of "difficulty in obtaining evidence" in cases of dial-up attacks stems from the fact that such attacks are typically identified manually by experienced security personnel. Currently, Chinese patent document CN114172677A discloses a method, apparatus, and system for identifying dial-up IPs. This method includes receiving a first access request from a browser, wherein the first access request carries an access IP address and is used to request access to a website server; transferring the first access request to a verification server, wherein the verification server identifies whether the access IP address is a dial-up IP address; and if the access IP address is not a dial-up IP address, establishing a data transmission channel between the browser and the website server.
[0007] However, this method can only effectively identify IPs that are dialed instantly; there is still a lack of quantitative and automated methods for identifying such attacks in the market. This makes the identification of such attacks less objective, and its heavy reliance on manual labor increases labor costs for enterprises, while also hindering automated forensics. Summary of the Invention
[0008] Based on this, in order to address the above-mentioned technical problems, a method for identifying instant dialing attack events is provided to solve the technical problem of the lack of automated instant dialing attack event identification methods in the existing technology.
[0009] To achieve the above objectives, this application provides the following technical solution:
[0010] A method for identifying instant dialing attack events includes:
[0011] S1, real-time acquisition of security alarm data on asset access collected by network security devices, and extraction of the real-time attack source IP address of each asset from the security alarm data;
[0012] S2, establish a sliding time window with a window length of x; initialize the current time window (t1, t'1], and initialize the time set of the second-dial attack event. Initialize the dial-up event time list L S = [];
[0013] S3, for each asset, based on the extracted real-time attack source IP addresses, statistics are compiled within the current time window (t). i ,t' i The total number of attacked IP addresses for this asset and the average number of attacks per attacking IP address;
[0014] S4, for each asset, based on the current time window (t) i ,t' iThe total number of attacked IP addresses and the average number of attacks per attacking IP address within the current time window (t) are used to determine the impact of attacks on the asset. i ,t' i Check if the asset is subject to a dial-up attack; if so, proceed to step S5; if not, proceed to step S6.
[0015] S5, if the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 for Set the current time window (t) i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) i ,t' i ]; Execute step S7;
[0016] If the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t' k ], set the current time window (t) i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) j ,t' i ]; Execute step S7;
[0017] S6, if the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 for Current time window (t) i ,t' i The corresponding time set of second-dial attack events S i for Execute step S7;
[0018] If the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t' k ], determine the current time window (t) i ,t' i ] and the previous time window (t i-1,t' i-1 The corresponding time set of second-dial attack events S i-1 =(t j ,t' k Does the intersection exist?
[0019] When there is an intersection, the current time window (t) will be used. i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) j ,t' k ]; Execute step S7;
[0020] When there is no intersection, S i-1 =(t j ,t' k Add to the second dialing event time list L S =[…,S i-1 ],(t j ,t' k This refers to the duration of a single, rapid attack on a specific asset; the current time window (t) represents this duration. i ,t' i The corresponding time set of second-dial attack events S i Updated to Execute step S7;
[0021] S7, the sliding window slides to the right at sliding intervals, moving the current time window (t) i ,t' i Updated to (t) i+1 ,t' i+1 Repeat steps S3-S7.
[0022] Optionally, the sliding interval is less than or equal to x / 2.
[0023] Optionally, in step S4, for each asset, if in the current time window (t) i ,t' i If the total number of attacked IP addresses of the asset within the specified time window is greater than or equal to a preset threshold y for the total number of attacked IP addresses, and the average number of attacks per attacked IP address is less than a preset threshold z for the average number of attacks per attacked IP address, then it is determined that within the current time window (t... i ,t' i This asset was found to be vulnerable to a dial-up attack.
[0024] Optionally, in step S4, for each asset, based on the current time window (t... i ,t' i The total number of attacked IP addresses for this asset. and the average number of attacks per attacking IP address Calculate the instant attack index of this asset. If the asset's instant attack index Reaching the preset dialing threshold V ref Then it is determined that within the current time window (t) i ,t' i This asset is susceptible to instant-call attacks; if the instant-call attack index of this asset... The preset dialing threshold V was not reached. ref Then it is determined that within the current time window (t) i ,t' i There are no instances of instant dialing attacks on this asset.
[0025] Further optional, instant attack index The specific calculation formula is as follows:
[0026]
[0027] Where, α i β i and γ i These are preset coefficients.
[0028] Optionally, the method further includes:
[0029] After manually reviewing all the instant dialing attack events, if the review results show that there are multiple records of the instant dialing attack events, the window length x of the time window will be increased; if the review results show that there are few records of the instant dialing attack events, the window length x of the time window will be decreased.
[0030] Optionally, the method further includes:
[0031] After manually reviewing all the reported second-dial attack events, if the review results show that multiple instances account for P% of all second-dial attack events. l The percentage of cases where data is underreported in all instant dialing attacks is P. s According to the first preset formula x new =f x (x old ,P l ,P s Adjust the window length x of the time window;
[0032] The first preset formula x new =f x (x old ,P l ,P s Specifically:
[0033]
[0034] Optionally, after manually reviewing all the obtained instant dialing attack events, if the review result shows that an instant dialing attack event exists in a certain time window, but step S4 determines that no instant dialing attack event exists in that time window, the preset threshold for the total number of attacked IP addresses y is reduced and / or the preset threshold for the average number of attacks per attacking IP address z is increased; if the review result shows that no instant dialing attack event exists in a certain time window, but step S4 determines that an instant dialing attack event exists in that time window, the preset threshold for the total number of attacked IP addresses y is increased and / or the preset threshold for the average number of attacks per attacking IP address z is reduced.
[0035] Further, optionally, the method further includes:
[0036] Count the total number of attacking IP addresses for each dipping attack event to obtain the total set L of attacking IP addresses for all dipping attacks. y =[y i ,y i+1 …,y i+n ];
[0037] According to the second preset formula y new =f y (y old ,min(L y ),L y The preset threshold value y for the total number of attacked IP addresses is adjusted.
[0038] The average number of attacks per attack IP address for each dial-up attack event is calculated to obtain the set L of average attack counts per attack IP address for all dial-up attack events. z =[z i ,z i+1 …,z i+n ];
[0039] According to the third preset formula z new =f z (z old ,max(L z ),L z The threshold value z for the average number of attacks per preset attack IP address is adjusted.
[0040] Further optionally, the second preset formula y new =f y (y old ,min(L y ),L y Specifically:
[0041] ynew =f y (y old ,min(L y ),L y )=α y y old +β y min(L y )+γ y avg(L y )
[0042] Where, α y β y γ y These are preset coefficients;
[0043] The third preset formula z new =f z (z old ,max(L z ),L z Specifically:
[0044] z new =f z (z old ,max(L z ),L z )=α z z old +β z min(L z )+γ z avg(L z )
[0045] Where, α z β z γ z These are preset coefficients.
[0046] The present invention has at least the following beneficial effects:
[0047] In the instant dialing attack event identification method provided in this embodiment of the invention, by inputting security alarm data from network security devices and using a sliding window approach, instant dialing attack events can be automatically extracted from several time window segments. Instant dialing attack events of unknown duration are divided and reflected in numerous time segments, which is applicable to instant dialing attack events of different durations. This instant dialing attack event identification method can automatically identify whether an enterprise has been subjected to an instant dialing attack, avoid subjective identification by humans, reduce the enterprise's labor costs, and improve the degree of automated evidence collection.
[0048] In the instant dialing attack event identification method provided in the embodiments of the present invention, the instant dialing attack behavior within a time window is characterized by "within a unit x time period, there are more than or equal y attacking IP addresses that launch attack behaviors against the same asset, and each attacking IP address generates less than z attack behaviors within this time period". Using three parameters to quantitatively characterize the instant dialing attack behavior, it is easy to objectively determine whether the asset has been subjected to an instant dialing attack within the current time window.
[0049] In the instant dialing attack event identification method provided in the embodiments of the present invention, the values of each parameter used to determine the instant dialing attack within the time window and the sliding interval of the time window can also be dynamically adjusted according to the actual situation of the instant dialing attack event, making the method highly scalable, forming a more objective instant dialing event judgment, and reducing the error of instant dialing attack identification. Attached Figure Description
[0050] Figure 1 This is a flowchart illustrating a method for identifying instant dialing attack events according to an embodiment of the present invention.
[0051] Figure 2 This is a schematic diagram of the process for determining a single-second dialing attack event according to an embodiment of the present invention;
[0052] Figure 3 This is a schematic diagram illustrating different instant dialing attack events in one embodiment of the present invention;
[0053] Figure 4 A diagram illustrating the inter-module relationships of a device for identifying instant dialing attack events, provided in one embodiment of the present invention;
[0054] Figure 5 A data flow diagram of a second-dial attack event identification device provided in one embodiment of the present invention;
[0055] Figure 6 This is an overall architecture diagram of a device for identifying instant dialing attack events according to an embodiment of the present invention;
[0056] Figure 7 A module architecture block diagram of a system for identifying instant dialing attack events provided in one embodiment of the present invention;
[0057] Figure 8 This is an internal structural diagram of a computer device provided in one embodiment of the present invention. Detailed Implementation
[0058] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0059] In one embodiment, such as Figure 1 As shown, a method for identifying instant dialing attack events is provided, including the following steps:
[0060] S1 acquires security alert data about asset access collected by network security devices in real time, and extracts the real-time attack source IP address of each asset from the security alert data.
[0061] First, real-time security alarm data on asset access status is obtained from security protection equipment and security detection equipment. Information such as the IP address of the attacked asset and the IP address of the attack source is extracted from this data. This data is the basic source data for analyzing dial-up attack events by the method provided in this embodiment.
[0062] Security protection equipment and security testing equipment include various security hardware and software, such as IDS and IPS.
[0063] S2, establish a sliding time window with a window length of x; initialize the current time window (t1, t'1], and initialize the time set of the second-dial attack event. Initialize the dial-up event time list L S =[].
[0064] S3, for each asset, based on the extracted real-time attack source IP addresses, statistics are compiled within the current time window (t). i ,t' i The total number of attacked IP addresses for this asset and the average number of attacks per attacking IP address.
[0065] The total number of attacked IP addresses represents the total number of attacking IP addresses that caused the asset to be attacked; t' i -t i Let x be the length of the time window, and t' be the time window length. i+1 -t' i =t i+1 -t i This refers to the sliding interval.
[0066] S4, for each asset, based on the current time window (t) i ,t' i The total number of attacked IP addresses and the average number of attacks per attacking IP address within the current time window (t) are used to determine the impact of attacks on the asset. i ,t' i Check if the asset is subject to a dial-up attack; if so, proceed to step S5; otherwise, proceed to step S6.
[0067] Specifically, as an optional implementation method, for each asset, if in the current time window (t... i ,t' iIf the total number of attacked IP addresses of the asset within the specified time window is greater than or equal to a preset threshold y for the total number of attacked IP addresses, and the average number of attacks per attacked IP address is less than a preset threshold z for the average number of attacks per attacked IP address, then it is determined that within the current time window (t... i ,t' i This asset was found to be vulnerable to a dial-up attack.
[0068] In other words, if within a unit of time x, there are y or more attacking IP addresses launching attacks on the same asset, and each attacking IP address generates an average of less than z attacks within this time, then it is determined that there is a dial-up attack within the unit of time x.
[0069] When calculating the total number of attacked IP addresses and the average number of attacks per IP address, only IP addresses with no more than z attacks and their attack counts are counted, while IP addresses with more than z attacks are filtered out. This is to prevent situations where two waves of attacks could amplify the average number of attacks: one wave is a normal attack, where a certain IP address launches attacks with a number of attacks far exceeding z; the other wave is a high-intensity attack, where some IP addresses launch attacks with a number of attacks less than z.
[0070] As another alternative implementation, for each asset, based on the current time window (t) i ,t' i The total number of attacked IP addresses for this asset. and the average number of attacks per attacking IP address Calculate the instant attack index of this asset. If the asset's instant attack index Reaching the preset dialing threshold V ref Then it is determined that within the current time window (t) i ,t' i This asset is susceptible to instant-call attacks; if the instant-call attack index of this asset... The preset dialing threshold V was not reached. ref Then it is determined that within the current time window (t) i ,t' i There are no instances of instant dialing attacks on this asset.
[0071] There are three moderating variables: x: the size of the time window; y: the number of attacking IP addresses within the time window; and z: the average number of attacks per attacking IP address within the time window. Based on these three moderating variables and using appropriate methods, the dial-up index V is calculated to determine whether dial-up attacks exist within a time window.
[0072] In other words, step S4 mainly addresses the determination of a second-dial attack event within a single time window. The determination process for a second-dial attack event within a single time window is as follows:
[0073] ① Initialize three adjustment variables: time window length x, threshold for the number of attacked IP addresses y, and threshold for the number of attacks initiated by each attacking IP address z. (These values are usually the factory default values provided by the device manufacturer. The specific values are not important. Eventually, these values will be adjusted through feedback to gradually approach the actual situation of the user, and thus eventually stabilize on the user's side.)
[0074] ② Obtain the attack status of each asset from the real-time data reading module. Taking asset a as an example, within the i-th time window, asset a suffered attacks from... The attacks were launched from different IP addresses. Second attack.
[0075] ③ The instant attack index of asset a within the i-th time window is calculated using a certain formula.
[0076]
[0077] The initial calculation method for the instant attack index of asset a is as follows:
[0078] Optionally, the instant attack index The specific calculation formula is as follows:
[0079]
[0080] Where, α i β i and γ i These are preset coefficients.
[0081] ④ Based on the dialing index Determine whether a dial-up attack event exists within this time window.
[0082] The situation of a second-diversion attack suffered by asset a in each time window can be described as follows:
[0083] The time window x is related to the time required for a single dial-up attack and should not be less than the time required for such an attack. The initial values of the three adjustment variables in this process can be manually set to describe the initial dial-up attack situation. They can be dynamically adjusted subsequently based on actual dial-up attack behavior, historical dial-up indices, and historical adjustment variable values.
[0084] A threshold V for dialing can be set. refAssist in determining whether a dial-up attack event exists in the i-th time window. If the dial-up index V in the time window reaches the dial-up threshold V... ref This indicates that a second-call attack exists within the time window; if the second-call index V within the time window does not reach the second-call threshold V... ref They stated that no dial-up attacks occurred within the time window.
[0085] S5, if the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 for Set the current time window (t) i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) i ,t' i ]; Execute step S7;
[0086] If the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t' k ], set the current time window (t) i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) j ,t' i ]; Execute step S7.
[0087] S6, if the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 for Then the current time window (t) i ,t' i The corresponding time set of second-dial attack events S i Also for Execute step S7;
[0088] If the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t' k ], determine the current time window (t) i ,t' i ] and the previous time window (ti-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 =(t j ,t' k Does the intersection exist?
[0089] When there is an intersection, the current time window (t) will be used. i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) j ,t' k ]; Execute step S7;
[0090] When there is no intersection, S i-1 =(t j ,t' k Add to the second dialing event time list L S =[…,S i-1 ],(t j ,t' k This refers to the duration of a single, rapid attack on a specific asset; the current time window (t) represents this duration. i ,t' i The corresponding time set of second-dial attack events S i Updated to Proceed to step S7.
[0091] S7, the sliding window slides to the right at sliding intervals, moving the current time window (t) i ,t' i Updated to (t) i+1 ,t' i+1 Repeat steps S3-S7.
[0092] The sliding interval is set based on the size of the time window. Generally speaking, the sliding interval is less than or equal to x / 2, which means it should not be greater than 1 / 2 of the time window.
[0093] In other words, this embodiment employs a sliding window-based timed detection mechanism, primarily addressing the differentiation of a single dial-up attack event within any given time period. For example... Figure 2 As shown, the process for determining a single instant dialing attack event is as follows:
[0094] ① Initialize the current time window (t1, t'1], where t' i -t i Let x be the length of the time window, and t' be the time window length. i+1 -t' i =t i+1 -t i The sliding interval. Initialize the set of time intervals for second-dial attack events. Second dialing event time list L S =[].
[0095] ② Determine the current time window (t) i ,t' i If a dial-up attack occurs within the specified range, execute step ③; otherwise, execute step ④.
[0096] ③If the time set S at this time i If it is empty, then the current time window is directly updated to the time set, i.e., S. i =(t i ,t' i If the time set S is at this time i If not empty, update the time set to get S. i =(t j ,t' i ], execute ⑤.
[0097] ④ Determine the current time window (t) i ,t' i With time set S i =(t j ,t' k Does there exist an intersection? If there is no intersection, then the previous time set S... i =(t j ,t' k Add to the second dialing event time list L S =[…,S i In the [], the current time set is updated to The time period (t) j ,t' k This refers to the duration of a single dial-up attack event.
[0098] ⑤ Shift the time window to the right and update the current time window to (t i+1 ,t' i+1 ], execute ②.
[0099] Ultimately, a list of dial-up event times L can be obtained. S =[S0,…,S i ,…].
[0100] The sliding interval of the time window can be based on a given fixed time, or it can be adjusted in real time according to the arrival of new alarm data. If there are no new alarms, it can be refreshed periodically.
[0101] The sliding interval is set based on the size of the time window. The time window is continuously shifted forward by the sliding interval size to determine whether a second-call attack occurs within the current time window. The time from the first occurrence of a second-call attack to the most recent time window without a second-call attack is defined as the duration of the second-call attack.
[0102] The dialing index V varies for each time window. After comparison with the dialing threshold, it is determined whether a dialing attack has occurred or not. If the time windows deemed to be subject to dialing attacks overlap within a certain period, this period is considered a single dialing attack event. If two consecutive time periods deemed to be subject to dialing attacks have a time interval exceeding a unit x, they are considered two separate dialing attack events.
[0103] like Figure 3 As shown, if the projection of a time-dipping attack is continuous during a given time period, it is considered a single time-dipping attack event; if the projection of a time-dipping attack is intermittent, they are considered different time-dipping attack events.
[0104] In other words, for identifying dial-up attacks within any time period (exceeding the size of the time window), a timed detection mechanism based on a sliding window is used. The time window is continuously slid to obtain the dial-up attack events within each time period. The time covered by the intersection of the time windows that are identified as having dial-up attack events is determined as one dial-up attack event.
[0105] Furthermore, the method also includes:
[0106] After manually reviewing all the instant dialing attack events, if the review results show that there are multiple records of the instant dialing attack events, the window length x of the time window will be increased; if the review results show that there are few records of the instant dialing attack events, the window length x of the time window will be decreased.
[0107] Furthermore, the method also includes:
[0108] After manually reviewing all the reported second-dial attack events, if the review results show that multiple instances account for P% of all second-dial attack events. l The percentage of cases where data is underreported in all instant dialing attacks is P. s According to the first preset formula x new =f x (x old ,P l ,P s Adjust the window length x of the time window;
[0109] First preset formula x new =f x (x old,P l ,P s Specifically, it can include, but is not limited to:
[0110]
[0111] Furthermore, the method also includes:
[0112] After manually reviewing all the received instant dialing attack events, if the review results show that an instant dialing attack event exists in a certain time window, but step S4 determines that there is no instant dialing attack event in that time window, the preset threshold for the total number of attacked IP addresses y is reduced and / or the preset threshold for the average number of attacks per attacking IP address z is increased; if the review results show that an instant dialing attack event does not exist in a certain time window, but step S4 determines that there is an instant dialing attack event in that time window, the preset threshold for the total number of attacked IP addresses y is increased and / or the preset threshold for the average number of attacks per attacking IP address z is reduced.
[0113] Furthermore, the method also includes:
[0114] Count the total number of attacking IP addresses for each dipping attack event to obtain the total set L of attacking IP addresses for all dipping attacks. y =[y i ,y i+1 …,y i+n ];
[0115] According to the second preset formula y new =f y (y old ,min(L y ),L y Adjust the preset threshold y for the total number of attacked IP addresses;
[0116] The average number of attacks per attack IP address for each dial-up attack event is calculated to obtain the set L of average attack counts per attack IP address for all dial-up attack events. z =[z i ,z i+1 …,z i+n ];
[0117] According to the third preset formula z new =f z (z old ,max(L z ),L z The threshold z for the average number of attacks per pre-defined attack IP address is adjusted.
[0118] Optionally, the second preset formula y new =f y (yold ,min(L y ),L y Specifically, it can include, but is not limited to:
[0119] y mew =f y (y old ,min(L y ),L y )=α y y old +β y min(L y )+γ y avg(L y )
[0120] Where, α y β y γ y These are preset coefficients;
[0121] Third preset formula z new =f z (z old ,max(L z ),L z Specifically, it can include, but is not limited to:
[0122] z new =f z (z old ,max(L z ),L z )=α z z old +β z min(L z )+γ z avg(L z )
[0123] Where, α z β z γ z These are preset coefficients.
[0124] In other words, based on the results of the dial-up event identification, the parameters can be dynamically adjusted sequentially, involving several parameters such as x, y, and z. While the parameters are still unstable, technicians should periodically or irregularly review the dial-up events. During the review, technicians should rely on the output time window judgment results and the dial-up event identification results to determine the automatically calculated dial-up events.
[0125] (1) Correct x based on feedback:
[0126] The size of the time window x directly affects the segmentation accuracy of the dial-up attack event. During manual review, there are three possible outcomes between the actual dial-up attack event and the dial-up attack event output by this invention: correct judgment, under-counting, and over-counting.
[0127] A correct judgment means that the invention's determination of a dial-up attack event is consistent with the actual situation. An undercount means that a single dial-up attack event determined by the invention should actually be considered as two or more dial-up attack events; in this case, the time window x should be reduced. An overcount means that multiple dial-up attack events determined by the invention actually belong to the same dial-up attack event; in this case, the time window x should be increased.
[0128] Let P be the percentage of recent over-reporting in all feedback. l The percentage of underreported cases in all feedback was P. s The adjustment of the time window x should be based on the proportion of underreporting and overreporting in all feedback, i.e.: x new =f x (x old ,P l ,P s ).
[0129] Take a typical formula as an example. As an example of this adjustment.
[0130] If the over-counting percentage is 100%, that is, P l =1, the underreported percentage is 0, that is, P s =0, the time window expands, that is, x new =1.5*x old .
[0131] If the over-counted percentage is 0%, that is, P l =0%, the underreporting rate is 100%, that is, P s =1, the time window shrinks, i.e., x new =0.5*x old .
[0132] As the time window x gradually converges to the actual situation, the proportions of underreporting and overreporting will be small and close in number. For example, the underreporting proportion may be about 5%, and the overreporting proportion may also be 5%. At this point, x... new ≈x old If x new and x old If the differences in the results are small (e.g., all less than 5%), no adjustment is required. To prevent repeated adjustments caused by the instability of the time window x, a small error is allowed.
[0133] The above formula is merely an example for adjusting the time window x. In actual products, this formula or other formulas can be used. There can be several formulas for changing the time window x, but their essence is to change the size of the time window by using over-counting and under-counting feedback. As long as it involves changing the size of the time window based on over-counting and under-counting feedback, it falls under the methods that should be protected by this invention.
[0134] (2) Correct y and z based on feedback:
[0135] The threshold y for the number of attacking IP addresses of assets within a time window and the number L of attacking IP addresses in recently successfully identified dial-up attacks. y =[y i ,y i+1 …,y i+n The lower limit is related to y, and should also take into account the number of attacking IP addresses in recently successfully identified dial-up attack events, i.e., y new =f y (y old ,min(L y ),L y ).
[0136] If the threshold y for the number of attacking IP addresses is too small, normal attack events are easily identified as instant dialing attack events, resulting in false alarms; if the threshold y for the number of attacking IP addresses is too large, instant dialing attack events are easily identified as normal attack events, resulting in false negatives.
[0137] The threshold z for the average number of attacks per attacking IP address within the time window and the threshold L for the average number of attacks per attacking IP address in recently successfully identified dial-up attack events. z =[z i ,z i+1 …,z i+n The upper limit is related to the number of attacks, and should also take into account the average number of attacks per attacking IP address in recently successfully identified dial-up attacks, i.e., z. new =f z (z old ,max(L z ),L z ).
[0138] If the average number of attacks threshold z is too large, normal attack events are easily identified as instant dialing attack events, resulting in false alarms; if the average number of attacks threshold z is too small, instant dialing attack events are easily identified as normal attack events, resulting in false negatives.
[0139] When technicians review and provide feedback, the judgment results for each time window should be re-examined. If there is a difference between the judgment results of the technicians and the calculation results of the instant dialing attack identification module, adjustments should be made as follows: If the instant dialing attack identification module determines that there is no instant dialing attack behavior in a certain time window, but the technicians determine that there is, then y should be decreased or z should be increased; otherwise, y should be increased or z should be decreased.
[0140] The following example illustrates the above adjustments:
[0141] set up Right now If the number of attacking IPs within the time window exceeds the threshold y, and the average number of attacks per IP is less than z, then a second-dial attack is considered to exist; otherwise, it is considered not to exist.
[0142] If within a certain time window If the technicians determine that an error exists, they should then analyze the data feedback module to determine the cause of the calculation error (whether y is too large or z is too small), and adjust the thresholds for y and z accordingly. When x is relatively stable within the time window, y and z can quickly converge to data that accurately reflects the actual situation of a dial-up attack.
[0143] In summary, the instant dialing attack identification method used in the embodiments of this invention is entirely new:
[0144] ① Use "within a unit x time period, there are greater than or equal y attacking IP addresses that launch attack behaviors (such as scanning) against the same asset, and each attacking IP address generates less than z attack behaviors within this time period" to characterize the dial-up attack behavior within a time window;
[0145] ② A method of using a sliding window to distinguish different start-second dialing attack events;
[0146] ③ Based on the actual situation of the instant dialing attack, dynamically adjust the values of each parameter used to determine the instant dialing attack within the time window, the time window sliding interval, etc.
[0147] In the methods provided in the embodiments of the present invention, some contents are not limited to the forms restricted by the above description, and the following modifications are equivalent to the forms described.
[0148] 1. The time descriptions above use minutes as the default unit. However, this is not limited to minutes; seconds or other time units are equivalent to minutes as described above.
[0149] 2. The above description of the formula only specifies the relevant parameter variables, without detailing the internal design of the formula. As long as the parameter variables are similar and the trend of the results is consistent, different calculation methods are equivalent.
[0150] Here are some examples of simplified forms of the formulas:
[0151]
[0152]
[0153] x new =f x (x old ,P l ,P s )=α x x old +β x P l +γ x P S
[0154] y new =f y (y old ,min(L y ),L y )=α y y old +β y min(L y )+γ y avg(L y )
[0155] z new =f z (z old ,max(L z ),L z )=α z z old +β z min(L z )+γ z avg(L z )
[0156] The calculation parameters for each formula are designed, including but not limited to the forms described above.
[0157] In summary, considering that a dial-up attack is a continuous attack launched by an attacker using dial-up attacks; the characteristic of a continuous attack is that the network attack is continuous in time (usually the interval between two network attacks is less than 1 minute); from the perspective of the attacked party, the characteristic is that the attacker can be detected by security devices to be constantly switching IPs and launching a large number of network attacks on the target system within a continuous period of time; if the attacker launches a continuous attack after an interruption in the middle, it can be considered as two dial-up attack events. Therefore, in the above-mentioned method for identifying dial-up attack events, three parameters are used to characterize the dial-up attack behavior: within a short period of time (within time window x), a large number of IPs (more than y) launch attacks by rapidly changing IPs (each IP attacks less than z times), making it easy to determine whether the assets have been subjected to a dial-up attack within the current time window.
[0158] The aforementioned method for identifying instant dialing attack events can automatically extract an instant dialing attack event from several time window segments, and divide instant dialing attack events of unknown duration into numerous time segments, making it applicable to instant dialing attack events of different durations.
[0159] The above-described method for identifying instant dialing attacks sets several indicators to quantitatively describe such attacks. It can also automatically and dynamically adjust the values of key parameters based on actual conditions, exhibiting strong scalability. Dynamically adjusting these indicators according to actual business needs reduces the error in identifying instant dialing attacks.
[0160] The method provided in this invention mainly attempts to achieve objective judgment. The professional's perception is mainly used in the data feedback stage to adjust x, y, and z, so that the final judgment result of this patent is close to the judgment of the professional, forming a more objective judgment of the dialing event.
[0161] This invention addresses the practical need for identifying dial-up attacks by establishing a complete method for identifying dial-up attack events in a formalized manner. It can automatically identify whether an organization has been subjected to a dial-up attack by inputting security alarm data from network security devices (IDS / IPS, etc.), avoiding subjective human identification, reducing the company's labor costs, and improving the degree of automated evidence collection.
[0162] It should be understood that, although Figure 1 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 1At least some of the steps in the process may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these steps or stages is not necessarily sequential, but may be executed in turn or alternately with other steps or at least some of the steps or stages in other steps.
[0163] In one embodiment, a device for identifying instant dialing attack events is provided, comprising a real-time data reading module, an instant dialing attack identification module, an instant dialing event determination module, and a data feedback module, the relationships of which are as follows: Figure 4 As shown. Specifically:
[0164] Real-time data reading module: Obtains real-time security alarm data on asset access from security protection equipment and security detection equipment, and extracts information such as the IP address of the attacked asset and the IP address of the attack source from it. This data is the basic source data for this product to analyze dial-up attack events.
[0165] The instant dialing attack detection module receives information from the real-time data reading module, statistically analyzes information such as the access frequency (z) and the number of accessing IP addresses (y) of assets within a time window, calculates the instant dialing index of each accessed asset during that period, and determines whether an instant dialing attack exists during that period. The instant dialing attack detection module primarily addresses the determination of instant dialing attack events within a single time window.
[0166] The instant dialing event determination module, based on the analysis results of the instant dialing attack identification module for several time windows, uses a sliding window to analyze the instant dialing attack events within a time period, determine the duration of each attack, and distinguish between different attacks. Determining a single instant dialing attack event requires differentiation based on different access assets (note that assets do not necessarily correspond one-to-one with IP addresses; one asset can correspond to multiple IP addresses). The instant dialing event determination module employs a sliding window-based timed detection mechanism, primarily addressing the differentiation of single instant dialing attack events within any given time period.
[0167] Data feedback module: Based on the actual situation of the instant dialing attack event and the results of the instant dialing event judgment module, dynamically adjust the parameters of the instant dialing attack identification module and the instant dialing event judgment module.
[0168] In summary, the data flow diagram in this instant dialing attack event identification device is as follows: Figure 5As shown, the instant dialing attack event identification device receives two types of inputs: one is real-time alarm data from security protection equipment, security monitoring equipment, or other security software and hardware (i.e., anything that can generate security alarms, whether software or hardware, can be used as input for this patent); the other is dynamic feedback on manual adjustments made according to the actual situation and the instant dialing attack event discrimination results (feedback events do not directly adjust the x, y, z parameters). The output information of the instant dialing attack event identification device is the discrimination result of the instant dialing attack event.
[0169] The data feedback module is an auxiliary step; initially, all parameters need to be set manually. In the early stages, due to a lack of data, adjustments can be made manually in conjunction with the results from the data feedback module. Once the parameter values stabilize, the role of the data feedback module diminishes, and adjustments via the data feedback module are no longer necessary for each iteration.
[0170] In other words, such as Figure 6 As shown, the overall design process of this instant dialing attack event identification device is as follows:
[0171] First, obtain real-time security alert data of assets from various security hardware and software (such as IDS and IPS) to determine whether there are any instant dialing attack events within the time window;
[0172] Based on the instant dialing attack situation in each time window, a sliding window method is used to determine whether the instant dialing attack situations in these time windows belong to the same instant dialing attack event.
[0173] Finally, the results of the instant dialing attack event are obtained. Based on the actual situation of the instant dialing attack, the above-mentioned adjustment variables (x, y, z) and sliding intervals are adjusted accordingly.
[0174] In this instant dialing attack event identification device, the optimal process adds a data feedback module compared to the basic process, which can automatically and dynamically adjust various parameters, making the product more applicable.
[0175] In one embodiment, such as Figure 7 As shown, a system for identifying instant dialing attack events is provided, including the following program modules:
[0176] The security alarm data acquisition module 701 is used to acquire security alarm data about asset access collected by network security devices in real time, and extract the real-time attack source IP address of each asset from the security alarm data.
[0177] The sliding time window creation module 702 is used to create a sliding time window, the window length of which is x; initialize the current time window (t1, t'1], and initialize the time set of the second dialing attack event. Initialize the dial-up event time list L S = [];
[0178] Module 703 is used to, for each asset, calculate the statistics within the current time window (t) based on the extracted real-time attack source IP addresses. i ,t' i The total number of attacked IP addresses for this asset and the average number of attacks per attacking IP address;
[0179] The 704 second-dial attack detection module is used to identify attacks based on the current time window (t) for each asset. i ,t' i The total number of attacked IP addresses and the average number of attacks per attacking IP address within the current time window (t) are used to determine the impact of attacks on the asset. i ,t' i Check if the asset is subject to a dial-up attack; if so, proceed to the first judgment module 705; if not, proceed to the second judgment module 706.
[0180] The first determination module 705 is used to determine if the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 for Set the current time window (t) i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) i ,t' i ]; Go to loop module 707;
[0181] If the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t' k ], set the current time window (t) i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) j ,t' i ]; Go to loop module 707;
[0182] The second determination module 706 is used to determine if the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 for Current time window (t) i ,t' i The corresponding time set of second-dial attack events Si for Switch to loop module 707;
[0183] If the previous time window (t) i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t' k ], determine the current time window (t) i ,t' i ] and the previous time window (t i-1 ,t' i-1 The corresponding time set of second-dial attack events S i-1 =(t j ,t' k Does the intersection exist?
[0184] When there is an intersection, the current time window (t) will be used. i ,t' i The corresponding time set of second-dial attack events S i Updated to (t) j ,t' k ]; Go to loop module 707;
[0185] When there is no intersection, S i-1 =(t j ,t' k Add to the second dialing event time list L S =[…,S i-1 ],(t j ,t' k This refers to the duration of a single, rapid attack on a specific asset; the current time window (t) represents this duration. i ,t' i The corresponding time set of second-dial attack events S i Updated to Switch to loop module 707;
[0186] The loop module 707 is used to slide the sliding window to the right at sliding intervals, and to set the current time window (t) as the current time window. i ,t' i Updated to (t) i+1 ,t' i+1 This causes the statistics module 703 to the loop module 707 to work repeatedly.
[0187] For specific limitations regarding the instant dialing attack event identification system, please refer to the limitations of the instant dialing attack event identification method described above, which will not be repeated here. Each module in the aforementioned instant dialing attack event identification system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0188] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements the aforementioned method for identifying dithering attacks.
[0189] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0190] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program relating to all or part of the processes in the methods of the above embodiments.
[0191] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon relating to all or part of the processes in the methods of the above embodiments.
[0192] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0193] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0194] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A method for identifying instant dialing attack events, characterized in that, include: S1, real-time acquisition of security alarm data on asset access collected by network security devices, and extraction of the real-time attack source IP address of each asset from the security alarm data; S2, establish a sliding time window with a window length of x; initialize the current time window (t1, t′1], and initialize the time set of the second-dial attack event. Initialize the dial-up event time list L S = []; S3, for each asset, based on the extracted real-time attack source IP addresses, statistics are compiled within the current time window (t). i ,t′ i The total number of attacked IP addresses for this asset and the average number of attacks per attacking IP address; S4, for each asset, based on the current time window (t) i ,t′ i The total number of attacked IP addresses and the average number of attacks per attacking IP address within the current time window (t) are used to determine the impact of attacks on the asset. i ,t′ i Does this asset contain information about a potential instant-dial attack? If it exists, proceed to step S5; if it does not exist, proceed to step S6. S5, if the previous time window (t) i-1 ,t′ i-1 The corresponding time set of second-dial attack events S i-1 for Set the current time window (t) i ,t′ i The corresponding time set of second-dial attack events S i Updated to (t) i ,t′ i ]; Execute step S7; If the previous time window (t) i-1 ,t′ i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t′ k ], set the current time window (t) i ,t′ i The corresponding time set of second-dial attack events S i Updated to (t) j ,t′ i ]; Execute step S7; S6, if the previous time window (t) i-1 ,t′ i-1 The corresponding time set of second-dial attack events S i-1 for Current time window (t) i ,t′ i The corresponding time set of second-dial attack events S i for Execute step S7; If the previous time window (t) i-1 ,t′ i-1 The corresponding time set of second-dial attack events S i-1 Not for That is, S i-1 =(t j ,t′ k ], determine the current time window (t) i ,t′ i ] and the previous time window (t i-1 ,t′ i-1 The corresponding time set of second-dial attack events S i-1 =(t j ,t′ k Does the intersection exist? When there is an intersection, the current time window (t) will be used. i ,t′ i The corresponding time set of second-dial attack events S i Updated to (t) j ,t′ k ]; Execute step S7; When there is no intersection, S i-1 =(t j ,t′ k Add to the second dialing event time list L S =[...,S i-1 ],(t j ,t′ k This refers to the duration of a single, rapid attack on a specific asset; the current time window (t) represents this duration. i ,t′ i The corresponding time set of second-dial attack events S i Updated to Execute step S7; S7, the sliding window slides to the right at sliding intervals, moving the current time window (t) i ,t′ i Updated to (t) i+1 ,t′ i+1 Repeat steps S3-S7.
2. The method for identifying instant dialing attack events according to claim 1, characterized in that, The sliding interval is less than or equal to x / 2.
3. The method for identifying instant dialing attack events according to claim 1, characterized in that, In step S4, for each asset, if in the current time window (t) i ,t′ i If the total number of attacked IP addresses of the asset within the specified time window is greater than or equal to a preset threshold y for the total number of attacked IP addresses, and the average number of attacks per attacked IP address is less than a preset threshold z for the average number of attacks per attacked IP address, then it is determined that within the current time window (t... i ,t′ i This asset was found to be vulnerable to a dial-up attack.
4. The method for identifying instant dialing attack events according to claim 1, characterized in that, In step S4, for each asset, based on the current time window (t) i ,t′ i The total number of attacked IP addresses for this asset. and the average number of attacks per attacking IP address Calculate the instant attack index of this asset. If the asset's instant attack index Reaching the preset dialing threshold V ref Then it is determined that within the current time window (t) i ,t′ i This asset is susceptible to instant-call attacks; if the instant-call attack index of this asset... The preset dialing threshold V was not reached. ref Then it is determined that within the current time window (t) i ,t′ i There are no instances of instant dialing attacks on this asset.
5. The method for identifying instant dialing attack events according to claim 4, characterized in that, Instant Attack Index The specific calculation formula is as follows: Where, α i β i and γ i These are preset coefficients.
6. The method for identifying instant dialing attack events according to claim 1, characterized in that, The method further includes: After manually reviewing all the instant dialing attack events, if the review results show that there are multiple records of the instant dialing attack events, the window length x of the time window will be increased; if the review results show that there are few records of the instant dialing attack events, the window length x of the time window will be decreased.
7. The method for identifying instant dialing attack events according to claim 1, characterized in that, The method further includes: After manually reviewing all the reported second-dial attack events, if the review results show that multiple instances account for P% of all second-dial attack events. l The percentage of cases where data is underreported in all instant dialing attacks is P. s According to the first preset formula x new =f x (x old P l P s Adjust the window length x of the time window; The first preset formula x new =f x (x old P l P s Specifically:
8. The method for identifying instant dialing attack events according to claim 3, characterized in that, After manually reviewing all the instant dialing attack events, if the review results show that an instant dialing attack event exists in a certain time window, but step S4 determines that there is no instant dialing attack event in that time window, the preset threshold y for the total number of attacked IP addresses is reduced and / or the preset threshold z for the average number of attacks per attacking IP address is increased. If the review results show that no dial-up attack events were manually determined to exist in a certain time window, but step S4 determines that a dial-up attack event exists in that time window, the preset threshold y for the total number of attacked IP addresses is increased and / or the preset threshold z for the average number of attacks per attacking IP address is decreased.
9. The method for identifying instant dialing attack events according to claim 3, characterized in that, The method further includes: Count the total number of attacking IP addresses for each dipping attack event to obtain the total set L of attacking IP addresses for all dipping attacks. y =[y i y i+1 ..., y i+n ]; According to the second preset formula y new =f y (y old ,min(L y ), L y The preset threshold value y for the total number of attacked IP addresses is adjusted. The average number of attacks per attacking IP address for each dipping attack event is calculated to obtain the set L of average attack counts per attacking IP address for all dipping attack events. z =[z i , z i+1 ..., z i+n ]; According to the third preset formula z new =f z (z old ,max(L z ), L z The threshold value z for the average number of attacks per preset attack IP address is adjusted.
10. The method for identifying instant dialing attack events according to claim 9, characterized in that, The second preset formula y new =f y (y old ,min(L y ), L y Specifically: y new =f y (y old ,min(L y ),L y )=a y y old +b y min(L y )+c y avg(L y ) Where, α y β y γ y These are preset coefficients; The third preset formula z new =f z (z old ,max(L z ), L z Specifically: With new =f z (With old ,max(L z ),L z )=α z With old +β z min(L z )+γ z avg(L z ) Where, α z β z γ z These are preset coefficients.
Citation Information
Patent Citations
Identification method, device and system for second dialing IP
CN114172677A
Network security evaluation method, device and equipment and storage medium
CN111193728A
Cache structure of sliding window
KR1020040057177A