Threat detection method and system based on trace graph behavior semantics extraction

By constructing an interest subgraph based on the source graph and assigning text descriptions to event edges and entity nodes, and by utilizing NLP technology and detection models, the shortcomings of existing threat detection systems in identifying hidden attack behaviors are addressed, achieving higher detection accuracy and more interpretable alerts.

CN116938587BActive Publication Date: 2026-05-29BEIHANG UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIHANG UNIV
Filing Date
2023-08-25
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing threat detection systems struggle to effectively identify attacks hidden within normal behavior, lack a holistic consideration and semantic representation of attack behavior, resulting in high false alarm rates, poor detection performance, and a lack of interpretability in alert results.

Method used

Interest subgraphs are constructed based on the source graph, text descriptions are assigned to event edges and entity nodes using NLP technology, the nature of behavior is determined by the detection model, and the detection accuracy is improved by combining semantic rules and training data.

Benefits of technology

It improves the accuracy of threat detection and the analytical capabilities of security analysts, effectively identifying attack behaviors and providing interpretable alert results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116938587B_ABST
    Figure CN116938587B_ABST
Patent Text Reader

Abstract

This invention relates to a threat detection method and system based on source graph behavior semantic extraction. The method includes: S1: collecting system audit logs from the host, extracting events from them, and constructing a source graph G; S2: finding all defined interest events in G, and dividing a set of interest subgraphs G from G based on labels and a set number of hops. i S3: for G i The event edges and entity nodes are assigned corresponding text descriptions to obtain interest subgraphs with text descriptions. The text description information of entity nodes and event edges is sorted and connected to form an interest subgraph for each G. i S4: Generate text descriptions for known attack and non-attack subgraphs to train the detection model; G i Input the detection model, output a threat score, and determine G. i Is it an attack subgraph? The method provided in this invention performs behavior segmentation on the source graph, assigns text descriptions to entity nodes and event edges, and extracts their correlation with attacks to determine the nature of the behavior.
Need to check novelty before this filing date? Find Prior Art