Security Situation Awareness Attack Tracing Method, Device, Equipment, Medium and Product
By combining the adaptive hidden Markov model and the multi-level correlation learning model, the Markov hypothesis limitation and computational complexity problems in the security situation-aware attack tracing in the existing technology are solved, and a more accurate and scalable attack path tracing is achieved.
Patent Information
- Application Number
- CN202211089792.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-07
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-09-07
AI Technical Summary
The existing technology has problems such as Markov hypothesis limitations, long observation sequences required for model training and computational complexity in the tracing of security situation awareness attacks, making it difficult to effectively deal with complex cyber attacks.
Adaptive Hidden Markov Model (SAHMM) and multi-level association learning model (TXSA5) are used to input attack parameters to obtain multiple attack paths, and the final attack path collection is formed by fusion model output, solving the limitations and computational complexity of a single model.
It realizes more accurate hacker attack path traceability, improves the scalability and accuracy of network security, and avoids the singleness and computational complexity of a single model.
Smart Images

Figure CN117675260B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security, and in particular, to a method, apparatus, device, medium, and product for security situation awareness attack traceability. Background Art
[0002] Currently, in the actual implementation of security situation awareness attack traceability, there are few algorithms such as machine learning used to solve problems. Generally, it mainly relies on experience and feature matching association. In the current theoretical research on security situation awareness attack traceability prediction, there are the following methods: grey theory, neural network, Bayesian network, support vector machine model, and hidden Markov model, but each has its own disadvantages. For example, the model based on the hidden Markov method has the following three limitations: (1) This method requires that the security satisfies the Markov property, that is, it requires that each stage of the multi-step attack is continuous and there is no loss of attack steps. (2) This method requires a long observation sequence to train the parameters of the HMM model, otherwise the correctness of the model training result cannot be guaranteed. (3) Finally, with the continuous expansion of the network scale and the complexity of attacks, it is difficult to calculate the state transition probability between attack behaviors, and the scalability is not ideal. Summary of the Invention
[0003] To overcome the problems existing in the related art, the present disclosure provides a method, apparatus, device, medium, and product for security situation awareness attack traceability.
[0004] According to the first aspect of the embodiments of the present disclosure, a method for security situation awareness attack traceability is provided, including:
[0005] Inputting attack parameters into the SAHMM model to obtain a first attack path, where the attack parameters at least include an attack pattern, elements existing in or possible attack paths in the attack sequence, a transition probability matrix of all attack stages, an observation probability matrix of each attack element in the stage where it is located, an initial state probability vector of each attack element, and a reinforcement factor;
[0006] Inputting the attack parameters into the adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths;
[0007] If the second set of attack paths includes the first attack path, outputting the second set of attack paths as the final set of paths;
[0008] If the second set of attack paths does not include the first attack path, outputting a third set of paths as the final set of paths, where the third set of attack paths includes the second set of attack paths and the first attack path.
[0009] In some embodiments, inputting attack parameters into the SAHMM model to obtain a first attack path includes:
[0010] Determine an observation set based on the attack pattern, where the observation set includes at least one observation value;
[0011] Determine the probability of the corresponding path appearing based on the observation value;
[0012] Obtain the path with the maximum probability in the observation set and output it as the first attack path.
[0013] In some embodiments, input the attack parameters into an adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths, including:
[0014] Determine an observation set based on the attack pattern, where the observation set includes at least one observation value;
[0015] Determine the probability of the corresponding path appearing based on the observation value and the corresponding reinforcement factor;
[0016] Obtain the set of paths with the maximum probability in the observation set and output it as the second set of attack paths.
[0017] In some embodiments, include:
[0018] The transition probability matrix of all attack stages, the observation probability matrix of each attack element in the stage where it is located, and the initial state probability vector of each attack element are obtained through HMM training.
[0019] According to the second aspect of the embodiments of the present disclosure, there is provided a security situation awareness attack traceability device, including:
[0020] A first acquisition module, configured to input attack parameters into a SAHMM model to obtain a first attack path, where the attack parameters include at least an attack pattern, elements existing in the attack sequence or possible attack paths, the transition probability matrix of all attack stages, the observation probability matrix of each attack element in the stage where it is located, the initial state probability vector of each attack element, and a reinforcement factor;
[0021] A second acquisition module, configured to input the attack parameters into an adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths;
[0022] An output module, if the second set of attack paths includes the first attack path, output the second set of attack paths as the final path set;
[0023] If the second set of attack paths does not include the first attack path, output a third set of paths as the final path set, and the third set of attack paths includes the second set of attack paths and the first attack path.
[0024] In some embodiments, the first acquisition module is configured to:
[0025] Determine an observation set based on the attack pattern, where the observation set includes at least one observation value;
[0026] Determine the probability of the corresponding path occurring based on the observation value;
[0027] Obtain the path with the maximum probability in the observation set and output it as the first attack path.
[0028] In some embodiments, the second acquisition module is configured to:
[0029] Determine an observation set based on the attack pattern, where the observation set includes at least one observation value;
[0030] Determine the probability of the corresponding path occurring based on the observation value and the corresponding reinforcement factor;
[0031] Obtain the set of paths with the maximum probability in the observation set and output it as the second attack path set.
[0032] An embodiment of the third aspect of the present application provides an electronic device, including a processor and a memory. At least one instruction, at least one segment of program, code set or instruction set is stored in the memory, and the instruction, the program, the code set or the instruction set is loaded and executed by the processor to implement the steps of the security situation awareness attack traceability method provided by the embodiment of the first aspect of the present application.
[0033] An embodiment of the fourth aspect of the present application provides a non-transitory computer-readable storage medium. When the instructions in the storage medium are executed by the processor of the mobile terminal, the mobile terminal can execute to implement the steps of the security situation awareness attack traceability method provided by the embodiment of the first aspect of the present application.
[0034] An embodiment of the fifth aspect of the present application provides a computer program product. When the instructions in the computer program product are executed by the processor of the mobile terminal, the mobile terminal can execute to implement the steps of the security situation awareness attack traceability method provided by the embodiment of the first aspect of the present application.
[0035] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects: In this application, an adaptive Hidden Markov SAHMM and a multi-level reinforcement association learning algorithm TXSA5 model are used to trace the origin of hacker attacks. Among them, the adaptive Hidden Markov model can solve the inherent defects of the Hidden Markov model. At the same time, an adaptive multi-level reinforcement association learning TXSA5 model is introduced, and by fusing the output results of the two models, the singularity of the adaptive Hidden Markov model is avoided, and at the same time, the origin of hacker attacks can be effectively traced, so that the attack path of hackers can be obtained more accurately, improving network security.
[0036] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present invention and, together with the specification, are used to explain the principles of the present invention.
[0038] Figure 1 is a flowchart of a security situation awareness attack tracing method shown according to an exemplary embodiment.
[0039] Figure 2 is a block diagram of a security situation awareness attack tracing device shown according to an exemplary embodiment.
[0040] Figure 3 is an internal structure diagram of an electronic device shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.
[0042] Figure 1 is a flowchart of a security situation awareness attack tracing method shown according to an exemplary embodiment, as Figure 1 shown, including the following steps:
[0043] In step S101, the attack parameters are input into the SAHMM model to obtain the first attack path, where the attack parameters at least include the attack mode, the elements existing in the attack sequence or possible attack paths, the transition probability matrix of all attack stages, the observation probability matrix of each attack element in the stage, the initial state probability vector of each attack element, and the reinforcement factor.
[0044] Specifically, by inputting the attack parameters into the SAHMM model, an optimal attack path can be output. Combining with the specific scenario, when inputting the attack parameters into the SAHMM model, the specific input is as shown in the following formula:
[0045] λ=(I,M,A,B,π)
[0046] where M represents the attack mode, I represents the elements existing in the attack sequence or possible attack paths (paths of the Nth power of hundreds of millions), A represents the transition probability matrix of all attack stages, B represents the observation probability matrix of each attack element in the stage, and π represents the initial state probability vector of each attack element.
[0047] By inputting the attack parameters into the SAHMM model, an optimal path is output: P=(p 1 ,p 2 ,…,p T ).
[0048] In some embodiments, the transition probability matrix of all attack stages, the observation probability matrix of each attack element in the stage, and the initial state probability vector of each attack element are obtained through HMM training.
[0049] Specifically, the above-mentioned A, the transition probability matrix of all attack stages, B, the observation probability matrix of each attack element in the stage, and π, the initial state probability vector of each attack element, are obtained by training with the classical HMM.
[0050] In some embodiments, inputting the attack parameters into the SAHMM model to obtain the first attack path includes:
[0051] Determining an observation set based on the attack mode, where the observation set at least includes one observation value;
[0052] Determining the probability of the corresponding path appearing based on the observation value;
[0053] Obtaining the path with the maximum probability in the observation set and outputting it as the first attack path.
[0054] Specifically, combining with the specific embodiment, the specific process of inputting the attack parameters into the SAHMM model to obtain the first attack path is as follows:
[0055] First, through the M value, the observation value O = (O 1 , O 2 …, O T ) can be determined. O is a variable quantity. In fact, according to different attack scenarios, different attack patterns can be recognized, thus forming different pattern M values. From the M value, the element categories participating in the attack process can be determined, and then the observation value O can be determined. Among them, the observation value actually refers to a combination of hacker attack sequences (phases). The hacker's attack is divided into several phases, and each O represents a phase of the hacker's attack. For example, O1 represents the O1 phase of the hacker's attack. Example: O = (1, 2, 3, 4, 5, 6), then O1 is the first phase; O = (2, 4, 5, 6), then O1 is the 2nd phase. This O value is determined by the M value.
[0056] Secondly, initialization is performed. The purpose of initialization is to set the initial value, as follows:
[0057] δ 1 (i) = π i b i (o 1 ), i ∈ I 1
[0058] ψ 1 (i) = 0, i ∈ I 1
[0059] Among them, i represents the elements existing in the attack sequence or possible attack paths.
[0060] I 1 represents the set of values of the first element in each attack path.
[0061] π i represents the probability that the element value i appears in the first position.
[0062] b i (o 1 ) represents the probability that the element value i appears in the observation value o 1 or the o 1 phase.
[0063] π i b i (o 1 ) The multiplication of these two formulas constitutes the probability δ 1 (i) of the element value i in the first element and the o 1 phase.
[0064] Then, the points passed by the most likely path are obtained through the principle of dynamic programming. Considering the specific scenario, t = 2, 3, …, T, as follows:
[0065]
[0066]
[0067] From the t - 1 state (or stage) to the t state, the value of j in the t - 1 state is an element in I t-1 The probability of successive multiplication of element j from the initial state to the t - 1 state is δ t-1 (j), and a ji represents the probability (possibility) from element j to element i, and b i (o t ) represents the probability that element value i appears in the o t stage. For a fixed observed value o t , for each i, b i (o t ) is actually the same. Therefore, for each element j, as long as the probability δ t-1 (j) of the appearance of element j in the previous stage is judged and multiplied by the possibility (probability) from element j to i, according to the principle of dynamic programming, it can be determined which element j to i has the greatest probability, and this is the meaning of ψ t (i), and at the same time, the value of δ t (i) can also be determined. Among them, according to the principle of dynamic programming, if the optimal path passes through node b at time t, then the partial path of this path from node b to the end point e must be optimal for all possible partial paths from b to e. Because if not, there would be another better partial path from b to e. If it is connected to the partial path from b to e, a path better than the original path will be formed, which is contradictory. So max is used here in this solution.
[0068] According to each observed value, continue to calculate using the method described above, and the value of δ t (i) of each current stage can be obtained, and at the same time, the point passed by the most likely path in the previous stage ψ t (i) can be obtained.
[0069] As can be seen from the above, the point passed by the optimal path in the previous stage and the probability value δ T (i) of the end point. For the maximum path in the end point stage, it is to compare the values of δ T (i) to determine that the most likely element i is the optimal path point, that is, P T . Therefore, the optimal path point is obtained through the following formula:
[0070]
[0071]
[0072] Since the points passed by the optimal path in the previous stage were obtained from the previous calculation, the optimal path is traced back from the end point forward, with t corresponding to t + 1. The optimal path combination is obtained, and the specific formula is as follows:
[0073] For t = T - 1, T - 2, …, 1
[0074] P t = ψ t+1 (i t+1 )
[0075] The optimal path is obtained: P = (P 1 , P 2 , … P T ).
[0076] In step S102, the attack parameters are input into the adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths.
[0077] Specifically, by inputting the attack parameters into the adaptive multi-level association learning TXSA5 model, 10 optimal attack paths can be output. Combining with the specific scenario, the attack parameters are input into the adaptive multi-level association learning TXSA5 model, and the specific input is as follows:
[0078] λ = (I, M, A, B, π, ρ)
[0079] Among them, M represents the attack mode, I represents the elements existing in the attack sequence or possible attack paths (paths of the Nth power of hundreds of millions), A represents the transition probability matrix of all attack stages, B represents the observation probability matrix of each attack element in the stage, π represents the initial state probability vector of each attack element. ρ represents the reinforcement factor, and ρ is actually determined by a certain algorithm from various factors such as the front-back relationship, IP address relationship, IP address threat index, mixed combat mode, experience index, etc. to obtain a reinforcement factor value.
[0080] By inputting the attack parameters into the adaptive multi-level association learning TXSA5 model, 10 optimal paths are output: P i = (p i1 , p i2 , …, p iT ) i ∈ [1, 10].[[]END]]
[0081] In some embodiments, inputting the attack parameters into the adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths includes:
[0082] Determine an observation set based on the attack pattern, where the observation set includes at least one observation value;
[0083] Determine the probability of the occurrence of the corresponding path based on the observation value and the corresponding reinforcement factor;
[0084] Obtain the path set with the maximum probability in the observation set and output it as the second attack path set.
[0085] Specifically, in combination with a specific embodiment, the specific process of inputting the attack parameters into the adaptive multi-level association learning TXSA5 model to obtain the second attack path set is as follows:
[0086] First, still through the M value, we can determine the observation value O = (O 1 , O 2 …, O T ).
[0087] Secondly, calculate the δ value of each level, specifically as follows:
[0088] δ 1 (i) = π i b i (o 1 ), i ∈ I 1
[0089] δ t (i) = a ji * b i (o t ), i ∈ I t , t = 2, 3, … T
[0090] Where i represents an element existing in the attack sequence or a possible attack path.
[0091] I 1 represents the set of values of the first element in each attack path.
[0092] π i represents the probability that the element value i appears in the first position.
[0093] b i (o 1 ) represents the probability that the element value i appears in the observation value o 1 or at the o 1 stage.
[0094] δ t (i) represents the product of the possibility of the transition (occurrence) from element j to element i and the possibility of the occurrence of element i at the o t stage.
[0095] Then, the probability value of each attack path is calculated through the enhancement factors, specifically as follows:
[0096] ρ i =W 1 *a i1 +W 2 *a i2 +…+W j *a ij
[0097] Pb i =δ 1 *δ 2 *…δ T *ρ i
[0098] a i1 ,a i2 ,…,a ij represents the specific small enhancement factor value of each path.
[0099] W 1 ,W 2 ,…,W j represents the weight of the enhancement factor of each category.
[0100] δ 1 *δ 2 *…δ T actually represents a joint probability of the possibility of occurrence between elements at each stage and the probability of an element appearing at a certain stage.
[0101] ρ i value is the sum of the products of various small enhancement factor values and weights (the weights they occupy).
[0102] Pb i =δ 1 *δ 2 *…δ T *ρ i represents the multiplication of probabilities of two different dimensions, thus making the certainty (possibility of occurrence) higher.
[0103] Finally, by sorting the probabilities of occurrence of each attack path, the second attack path set is obtained, specifically as follows:
[0104] SPb = sort(Pb)
[0105] MSPb[0:9] = SPb[0:9]
[0106] sort is a sorting function that sorts a large number of path PB probability values from largest to smallest. It is a representation method in the Python language. The 10 probability values with the largest probabilities are taken out to obtain the corresponding 10 optimal paths, that is, the second attack path set.
[0107] In step S103, if the second attack path set includes the first attack path, output the second attack path set as the final path set.
[0108] Specifically, if the second attack path set includes the first attack path, it indicates that the output result of the SAHMM model is ideal. However, to avoid the singularity of the output result of the SAHMM model, the second attack path set is output as the final path set.
[0109] In step S104, if the second attack path set does not include the first attack path, output the third path set as the final path set. The third attack path set includes the second attack path set and the first attack path.
[0110] Specifically, if the second attack path set does not include the first attack path, it indicates that there is a deviation between the output results of the two models. Therefore, to avoid the deviation of the output result caused by the correct output of a certain model not being output, the two output results are integrated into a path set, that is, the third attack path set is output to ensure the accuracy of the attack path.
[0111] Figure 2 It is a block diagram of a security situation awareness attack traceability device shown according to an exemplary embodiment. Refer to Figure 2 This device includes a first acquisition module 201, a second acquisition module 202, and an output module 203.
[0112] The detection module 201 is used to input the attack parameters into the SAHMM model to obtain the first attack path. Among them, the attack parameters at least include the attack mode, the elements existing in the attack sequence or the possible attack paths, the transition probability matrix of all attack stages, the observation probability matrix of each attack element in the stage, the initial state probability vector of each attack element, and the reinforcement factor.
[0113] The determination module 202 is used to input the attack parameters into the adaptive multi-level association learning TXSA5 model to obtain the second attack path set.
[0114] The conversion module 203, if the second attack path set includes the first attack path, outputs the second attack path set as the final path set.
[0115] If the second attack path set does not include the first attack path, output the third path set as the final path set, where the third attack path set includes the second attack path set and the first attack path.
[0116] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0117] In one embodiment, an electronic device is provided. The electronic device may be a terminal, and its internal structure diagram may be as Figure 3 shown. The electronic device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, near field communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a method for security situation awareness attack traceability. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0118] Those skilled in the art can understand that Figure 3 the structure shown in
[0119] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements. Figure 3 In one embodiment, the security situation awareness attack traceability device provided by the present application can be implemented in the form of a computer program, and the computer program can run on an electronic device as
[0120] At least one instruction, at least one program, a code set or an instruction set is stored in the memory of the electronic device, and the instruction, the program, the code set or the instruction set is loaded and executed by the processor to implement the security situation awareness attack traceability method according to any one of the above embodiments. For example, to implement the security situation awareness attack traceability method, it includes: inputting attack parameters into the SAHMM model to obtain a first attack path, where the attack parameters at least include an attack mode, elements existing in the attack sequence or possible attack paths, a transition probability matrix of all attack stages, an observation probability matrix of each attack element at its stage, an initial state probability vector of each attack element, and a reinforcement factor; inputting the attack parameters into the adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths; if the second set of attack paths includes the first attack path, outputting the second set of attack paths as the final path set; if the second set of attack paths does not include the first attack path, outputting a third path set as the final path set, where the third set of attack paths includes the second set of attack paths and the first attack path.
[0121] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: inputting attack parameters into the SAHMM model to obtain a first attack path, where the attack parameters at least include an attack mode, elements existing in the attack sequence or possible attack paths, a transition probability matrix of all attack stages, an observation probability matrix of each attack element at its stage, an initial state probability vector of each attack element, and a reinforcement factor; inputting the attack parameters into the adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths; if the second set of attack paths includes the first attack path, outputting the second set of attack paths as the final path set; if the second set of attack paths does not include the first attack path, outputting a third path set as the final path set, where the third set of attack paths includes the second set of attack paths and the first attack path.
[0122] In one embodiment, a computer program product is provided. When the instructions in the computer program product are executed by a processor of a mobile terminal, the mobile terminal is enabled to perform the following steps: input attack parameters into a SAHMM model to obtain a first attack path, where the attack parameters at least include an attack mode, elements existing in an attack sequence or possible attack paths, a transition probability matrix for all attack stages, an observation probability matrix for each attack element in the stage where it is located, an initial state probability vector for each attack element, and a reinforcement factor; input the attack parameters into an adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths; if the second set of attack paths includes the first attack path, output the second set of attack paths as the final path set; if the second set of attack paths does not include the first attack path, output a third path set as the final path set, where the third set of attack paths includes the second set of attack paths and the first attack path.
[0123] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or an external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static random access memory (SRAM) and dynamic random access memory (DRAM), etc.
[0124] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0125] The above embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A method for security situation awareness attack traceability, characterized in that, it includes: Input the attack parameters into an adaptive Hidden Markov SAHMM model to obtain the first attack path. Among them, the attack parameters at least include the attack mode, the elements existing in the attack sequence or possible attack paths, the transition probability matrix of all attack stages, the observation probability matrix of each attack element in the corresponding stage, the initial state probability vector of each attack element, and the reinforcement factor; the reinforcement factor is determined by at least one of the factors of context, IP address relationship, IP address threat index, combined operation mode, and experience index; Input the attack parameters into an adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths; If the second set of attack paths includes the first attack path, output the second set of attack paths as the final path set; If the second set of attack paths does not include the first attack path, output a third set of attack paths as the final path set, and the third set of attack paths includes the second set of attack paths and the first attack path; The step of inputting the attack parameters into the adaptive Hidden Markov SAHMM model to obtain the first attack path includes: determining an observation set based on the attack mode, where the observation set at least includes one observation value; determining the probability of the corresponding path appearing based on the observation value; obtaining the path with the maximum probability in the observation set and outputting it as the first attack path; The step of inputting the attack parameters into the adaptive multi-level association learning TXSA5 model to obtain the second set of attack paths includes: determining an observation set based on the attack mode, where the observation set at least includes one observation value; determining the probability of the corresponding path appearing based on the observation value and the corresponding reinforcement factor; obtaining the set of paths with the maximum probability in the observation set and outputting it as the second set of attack paths.
2. The security situation awareness attack traceability method according to claim 1, characterized in that, it includes: The transition probability matrix of all attack stages, the observation probability matrix of each attack element in the corresponding stage, and the initial state probability vector of each attack element are obtained through HMM training.
3. A security situation awareness attack traceability device, characterized in that, it includes: A first acquisition module for inputting attack parameters into an adaptive Hidden Markov SAHMM model to obtain the first attack path. Among them, the attack parameters at least include the attack mode, the elements existing in the attack sequence or possible attack paths, the transition probability matrix of all attack stages, the observation probability matrix of each attack element in the corresponding stage, the initial state probability vector of each attack element, and the reinforcement factor; the reinforcement factor is determined by at least one of the factors of context, IP address relationship, IP address threat index, combined operation mode, and experience index; A second acquisition module for inputting the attack parameters into an adaptive multi-level association learning TXSA5 model to obtain a second set of attack paths; An output module, if the second attack path set includes the first attack path, outputs the second attack path set as the final path set; if the second attack path set does not include the first attack path, outputs the third path set as the final path set, where the third attack path set includes the second attack path set and the first attack path; The first acquisition module is configured to: determine an observation set based on the attack pattern, where the observation set includes at least one observation value; determine the probability of a corresponding path appearing based on the observation value; and acquire the path with the maximum probability in the observation set and output it as the first attack path; The second acquisition module is configured to: determine an observation set based on the attack pattern, where the observation set includes at least one observation value; determine the probability of a corresponding path appearing based on the observation value and the corresponding reinforcement factor; and acquire the path set with the maximum probability in the observation set and output it as the second attack path set.
4. An electronic device Characterized in that it includes a processor and a memory, and at least one instruction, at least one program, a code set or an instruction set is stored in the memory, and the instruction, the program, the code set or the instruction set is loaded and executed by the processor to implement the security situation awareness attack traceability method according to any one of claims 1-2.
5. A non-transitory computer-readable storage medium Characterized in that when the instructions in the storage medium are executed by a processor of a mobile terminal, the mobile terminal is enabled to execute the security situation awareness attack traceability method according to any one of claims 1-2.
6. A computer program product Characterized in that when the instructions in the computer program product are executed by a processor of a mobile terminal, the mobile terminal is enabled to execute the security situation awareness attack traceability method according to any one of claims 1-2.
Citation Information
Patent Citations
Power monitoring system-based network threat quantification method and system
CN112819336A
Multi-target network security dynamic evaluation method based on Bayesian network attack graph
CN114519190A