Automatic update method, system and device for attack script library based on machine learning

Through the automatic update method of the attack script library based on machine learning, the problem of traditional vulnerability scanning reports lacking complete attack paths and real-time updates is solved, and the attack script library is efficient, accurate and real-time updates are achieved, and network security defense is improved.

CN118199952BActive Publication Date: 2025-05-23STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410285380.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-13
Publication Date
2025-05-23
Estimated Expiration
2044-03-13

Smart Images

  • Figure CN118199952B_ABST
    Figure CN118199952B_ABST
Patent Text Reader

Abstract

A machine learning-based attack script library automatic update method, system and device, the method first identifies the attack sequence of attack data based on the ATT&CK model framework, determines the attack process, and then identifies whether it is a new attack method of unknown vulnerabilities in the attack knowledge base based on the attack process. If so, the new attack method is added to the attack knowledge base to update the attack knowledge base, and the defense strategy corresponding to the new attack method is added to the defense knowledge base to update the defense knowledge base, and the attack link is planned, and then the intrusion and attack simulation technology is used to simulate the automatic attack, and finally the TTPs of the network threat intelligence are used to analyze and restore the entire process of the attack event, and the attack knowledge base and the defense knowledge base are updated again according to the entire process of the attack event. The present invention helps to improve the prevention, detection and response capabilities of network security, and reduces potential security threats and risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of computer network security, and in particular relates to a method, system and device for automatically updating an attack script library based on machine learning. Background Art

[0002] With the rapid development and popularization of computer networks, security vulnerabilities emerge in an endless stream, and there are many ways to attack and exploit. The scanning reports of traditional vulnerability scanning products only analyze the problem from the perspective of vulnerabilities and assets, and list the vulnerability verification process in detail. Traditional vulnerability scanning reports only describe a single vulnerability, but lack a complete attack path. The description of a single vulnerability lacks a handle for managers. Advanced attack techniques are often very hidden and bypass security protection measures. Therefore, it is urgent to use active hunting methods to promote defense through attack, simulate hackers to verify the security defense of existing security defense systems, verify the defense effect of security devices based on attack results, and accumulate attack behaviors and response strategies into an attack script library, thereby improving the diversity and real-time update of simulated attack forms.

[0003] Through the above analysis, the problems and defects of the prior art are as follows:

[0004] (1) Traditional vulnerability scanning reports only describe a single vulnerability but lack a complete attack path. A single vulnerability description is not a good starting point for managers.

[0005] (2) Advanced attack techniques are often very covert and difficult to detect. It is urgent to actively simulate attacks and automatically update the attack script library to improve the system's security defense capabilities. Summary of the invention

[0006] The purpose of the present invention is to provide a method, system and device for automatically updating an attack script library based on machine learning in order to solve the above problems in the prior art.

[0007] To achieve the above objectives, the technical solution of the present invention is as follows:

[0008] In a first aspect, the present invention proposes a method for automatically updating an attack script library based on machine learning, comprising:

[0009] S1. Capture attack data, identify the attack sequence of attack data based on the ATT&CK model framework, and determine the attack process;

[0010] S2. Based on the attack process, identify whether it is a new attack method for unknown vulnerabilities in the attack knowledge base. If so, add the new attack method to the attack knowledge base to update the attack knowledge base, add the defense strategy corresponding to the new attack method to the defense knowledge base to update the defense knowledge base, and plan the attack link;

[0011] S3, using intrusion and attack simulation technology to simulate automatic attacks;

[0012] S4. Use the TTPs of network threat intelligence to analyze and restore the entire process of the attack event, and update the attack knowledge base and defense knowledge base again based on the entire process of the attack event.

[0013] The S3 includes:

[0014] S31. Collect information about the target system, including network structure, system configuration, application programs, and security vulnerability information;

[0015] S32, integrating the information of the target system into the knowledge graph to update the knowledge graph;

[0016] S33, using the updated knowledge graph to simulate the path taken by the attacker, and using a recursive algorithm to simulate the attacker's behavior, looking for a new path on the graph until the target is found or the set termination condition is reached, and finally outputting the simulated attack path;

[0017] S34, generating attack code or script according to the attack path obtained by simulation;

[0018] S35. Perform simulated attacks in a secure test environment, monitor the response results of the target system, and audit whether the system successfully monitors and responds to these attacks based on the response results.

[0019] The S4 includes:

[0020] S41. Extract key IOC evidence or manual analysis personnel expressions from network threat intelligence to locate the behavioral characteristics of the attack;

[0021] S42. Associate homology conditions from behavioral characteristics, merge similar items from technical and tactical perspectives, and form a behavioral template that is understandable, valuable, and common to humans;

[0022] S43. Based on the context, goals and conditions of the behavior, establish the causal order of the behavior and restore the entire process of the attack.

[0023] The S2 is executed by an AI engine configured with an attack algorithm.

[0024] In a second aspect, the present invention proposes an automatic update system for attack script libraries based on machine learning, including a process refinement module, a knowledge base update and link planning module, an attack simulation module, and an analysis and restoration module;

[0025] The process extraction module is used to capture attack data, identify the attack sequence of the attack data based on the ATT&CK model framework, and determine the attack process;

[0026] The knowledge base update and link planning module is used to identify whether it is a new attack method for attacking unknown vulnerabilities in the attack knowledge base based on the attack process. If so, the new attack method is added to the attack knowledge base to update the attack knowledge base, the defense strategy corresponding to the new attack method is added to the defense knowledge base to update the defense knowledge base, and the attack link is planned;

[0027] The attack simulation module is used to simulate automatic attacks using intrusion and attack simulation technology;

[0028] The analysis and restoration module is used to analyze and restore the entire process of the attack event using the TTPs of the network threat intelligence, and to update the attack knowledge base and the defense knowledge base again according to the entire process of the attack event.

[0029] The attack simulation module includes an information collection unit, a knowledge graph update unit, an attack path simulation unit, an attack code or script generation unit, and a simulated attack audit unit;

[0030] The information collection unit is used to collect information of the target system, including network structure, system configuration, application program and security vulnerability information;

[0031] The knowledge graph updating unit is used to integrate the information of the target system into the knowledge graph to update the knowledge graph;

[0032] The attack path simulation unit is used to simulate the path taken by the attacker using the updated knowledge graph, and use a recursive algorithm to simulate the attacker's behavior, looking for a new path on the graph until the target is found or the set termination condition is reached, and finally outputs the simulated attack path;

[0033] The attack code or script generating unit is used to generate an attack code or script according to the attack path obtained by simulation;

[0034] The simulated attack audit unit is used to perform simulated attacks in a safe test environment, monitor the response results of the target system, and audit whether the system successfully monitors and responds to these attacks based on the response results.

[0035] The analysis and restoration module includes a feature positioning unit, a behavior recognition unit, and an association unit;

[0036] The feature location unit is used to extract key IOC evidence or expressions of manual analysts from network threat intelligence to locate the behavioral features of the attack;

[0037] The behavior recognition unit is used to associate homology conditions from behavior characteristics, merge similar items from technical and tactical perspectives, and form a behavior template that is human-understandable, reference-worthy and common;

[0038] The association unit is used to formulate the causal order of the behavior according to the context, target and conditions of the behavior, and restore the entire process of the attack event.

[0039] The knowledge base update and link planning module is an AI engine configured with an attack algorithm, and an adaptive learning unit is provided inside the module, which is used to adaptively optimize the attack algorithm according to the result data obtained by the attack simulation module;

[0040] A real-time network environment monitoring unit is added to the attack knowledge base, and the unit is used to collect the status and changes of the current network environment in real time, and to provide feedback to the knowledge base update and link planning module in real time when the network environment changes.

[0041] The system also includes an automatic labeling and feedback module, a data fusion module, and a threat intelligence integration module;

[0042] The automatic marking and feedback module is used to automatically mark the result of whether the simulated attack is successful, and feed it back to the attack knowledge base for corresponding update;

[0043] The data fusion module is used to fuse multi-source data in the entire process of restoring the attack event, and the multi-source data includes network traffic and system logs;

[0044] The threat intelligence integration module is used to obtain the latest attack techniques and vulnerability information in real time based on an external threat intelligence platform and integrate it into the attack knowledge base.

[0045] In a third aspect, the present invention provides an automatic update device for an attack script library based on machine learning, comprising a processor and a memory;

[0046] The memory is used to store computer program code and transmit the computer program code to the processor;

[0047] The processor is used to execute the aforementioned automatic update method of the attack script library based on machine learning according to the instructions in the computer program code.

[0048] Compared with the prior art, the present invention has the following beneficial effects:

[0049] 1. The method of the present invention realizes efficient and accurate attack simulation through machine learning, which not only greatly improves the real-time performance of the attack script library, helps to improve the efficiency and accuracy of network security and threat detection, but also can achieve the purpose of multi-point intrusion.

[0050] 2. The method described in the present invention combines intrusion and attack simulation technology with recursive algorithms to perform attack simulation. Intrusion and attack simulation technology can strengthen the monitoring of audit system response characteristics and penetration behavior. The application of recursive algorithms can not only adapt to the ever-changing attack strategies and system environments, provide more flexible and continuous security assessments, but also continuously learn and improve the attack simulation process. With the accumulation of more data, its accuracy and efficiency will be effectively improved, thereby shortening the time from intrusion to discovery, which helps to quickly respond to and patch security vulnerabilities and reduce potential security risks.

[0051] 3. The system of the present invention optimizes the attack algorithm adaptively for the result data obtained by the attack simulation module by setting an adaptive learning unit inside the AI ​​engine, so that the subsequent simulated attack is closer to the actual attack environment; by adding a real-time network environment monitoring unit to the attack knowledge base, the status and changes of the current network environment are collected in real time. When the network environment changes, such as new equipment access, system update, etc., the module will feedback these changes to the AI ​​engine in real time, so that the attack simulation can be carried out for the current network environment; the result of whether the simulated attack is successful is automatically marked by the automatic marking and feedback module, and the result is fed back to the attack knowledge base for corresponding update; the data fusion module integrates multi-source data including network traffic and system logs in the entire process of restoring the attack event, and uses data fusion technology to provide a more comprehensive and accurate attack simulation effect, which can help the system more accurately restore the process of being attacked and provide more accurate analysis and suggestions for the security team; the threat intelligence integration module obtains the latest attack techniques and vulnerability information in real time and integrates it into the attack knowledge base, making the simulated attack more cutting-edge and real-time; the above scheme can further improve the efficiency, accuracy and real-time performance of automated attack simulation, and provide enterprises with more powerful and accurate security assessments and suggestions.

[0052] 4. The present invention has strong versatility and is applicable to a variety of different industries and systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 This is an overall flow chart of the method described in Example 1.

[0054] Figure 2 This is a structural diagram of the system described in Example 3.

[0055] Figure 3 for Figure 2 Structure diagram of the attack simulation module.

[0056] Figure 4 This is a structural diagram of the equipment described in Example 4. DETAILED DESCRIPTION

[0057] The present invention is further described in detail below in conjunction with specific implementations and drawings.

[0058] The present invention proposes a method for automatically updating an attack script library based on machine learning, which has the following positive effects:

[0059] First, the present invention learns from a large amount of penetration testing experience and works in a way similar to human thinking. It can not only attack and exploit single-point vulnerabilities, but also carry out lateral vulnerability attacks by elevating privileges to achieve the purpose of multi-point intrusion.

[0060] The present invention can iterate the knowledge of historical output and current output during the attack process. When knowledge items that can be jointly utilized are found in the system knowledge experience library, the system will conduct in-depth joint utilization of the current vulnerability to achieve the purpose of business risks that could not be discovered by single-point vulnerability exploitation before. It can provide powerful vulnerability discovery capabilities according to user detection needs.

[0061] Second, the automatic update method of the attack script library based on machine learning has brought significant technological progress to the field of network security, which is specifically reflected in the following aspects:

[0062] 1. Real-time and accuracy: Traditional attack script library updates rely on manual continuous tracking and integration of new vulnerabilities and attack methods, which is time-consuming and misses the latest threats. Machine learning methods can automatically and quickly learn and extract new attack patterns from large amounts of data, greatly improving the real-time and accuracy of attack script libraries.

[0063] 2. Adaptability: Machine learning-based methods can adaptively adjust and optimize attack algorithms to make them more relevant to the current network environment and threat patterns. This adaptive capability enables the system to more effectively respond to changing network threats.

[0064] 3. Automation and intelligence: Combining AI engines and attack algorithms, the system can automatically update the knowledge base and plan attack links. This automated and intelligent approach greatly reduces the need for manual intervention and improves the system's work efficiency.

[0065] 4. Comprehensive simulated attack effects: Through enhanced data fusion technology and automated threat intelligence integration mechanism, the system can combine multi-source data for data fusion to provide more comprehensive and accurate simulated attack effects.

[0066] 5. Improve security protection capabilities: By simulating attacks and feedback, the system can promptly detect and repair potential security vulnerabilities and threats, thereby improving the security protection capabilities of the entire network.

[0067] Embodiment 1:

[0068] like Figure 1 As shown, a method for automatically updating an attack script library based on machine learning is implemented in the following steps in a high-risk network environment:

[0069] 1. Deploy high-interaction honeypots to attract attackers to actively attack, thereby capturing real attack traffic, attack methods and other attack data.

[0070] 2. Identify the attack sequence of attack data based on the ATT&CK model framework and determine the attack process.

[0071] As a comprehensive knowledge base, the ATT&CK model framework understands and classifies attacker behaviors through actual observation of each stage of the attack life cycle, covering malicious behaviors implemented by various APT organizations. The MITRE ATT&CK matrix arranges all known tactics and techniques in an easy-to-understand format. Attack tactics are displayed at the top of the matrix, and individual techniques are listed under each column. An attack sequence contains at least one technique according to the tactics, and a complete attack sequence is constructed by moving from the left (initial access) to the right (impact). A tactic uses multiple techniques. For example, an attacker tries both phishing attachments and phishing links in a spear phishing attack.

[0072] Generally, attackers will not use all 12 strategies in the same attack, because this increases the probability of the attack being discovered: initial access, execution, persistence, privilege escalation, defense bypass, credential access, discovery, lateral movement, collection, command and control, data exfiltration, and impact. These 12 strategies can cover most of the current hacker attack methods.

[0073] The application of this model framework provides a way to understand and classify attacker behavior, including the malicious behavior of various APT organizations. Using the MITRE ATT&CK matrix, known attack tactics and techniques are presented in an easy-to-understand format to help security teams better understand and identify attack sequences. It also supports the construction of a complete attack sequence, from initial access to impact, which helps predict and respond to attack behaviors at all stages.

[0074] Security defense based on the ATT&CK model framework can be improved and enhanced in the following ways:

[0075] (1) Data richness

[0076] Integrate multiple sources of intelligence: Use APIs or custom data collection tools to integrate open source intelligence (OSINT), industry-specific intelligence, honeypot operation data, and other relevant threat intelligence sources.

[0077] Data correlation analysis: Link data from different sources through correlation analysis and aggregation techniques to form a comprehensive view of attack activities.

[0078] (2) Automated analysis

[0079] Machine Learning Models: Deploy machine learning algorithms to automatically detect abnormal patterns and attack behaviors, reducing reliance on manual analysis.

[0080] Automated response: Integrate SOAR (Security Orchestration, Automation, and Response) tools to automatically execute response measures to mitigate identified threats.

[0081] (3) Context Awareness

[0082] Context-sensitive analysis: Incorporates information such as network configuration, asset classification, and business processes into the analysis to enhance the accuracy of attack impact assessment.

[0083] Customized alerts: Customize security alerts based on asset criticality and business impact, ensuring security teams are aware of the most critical events.

[0084] (4) Dynamic confrontation simulation

[0085] Red Team and Blue Team Drills: Conduct regular red team and blue team drills to evaluate and improve security defense measures.

[0086] Automated penetration testing: Use automated tools to conduct continuous security testing to discover new vulnerabilities and weaknesses.

[0087] (5) Deceptive Defense

[0088] Deploy honeypots and honeynets: Deploy honeypot and honeynet strategies in the network to trap attackers and collect intelligence about the attackers' behavior.

[0089] Deception strategy customization: Design specific deception defenses based on known attack patterns.

[0090] (6) User and Entity Behavior Analytics (UEBA)

[0091] Behavioral analytics engine: Implement a UEBA solution to monitor user and entity behavior to identify potential insider threats or compromised credentials.

[0092] (7) Cross-platform compatibility

[0093] Broad platform support: Ensure security tools and controls can be applied to multiple operating systems and platforms, including cloud services and mobile environments.

[0094] (8) Real-time update and sharing

[0095] Community collaboration: Participate in and contribute to the open source community to share and update threat intelligence and defense strategies in real time.

[0096] Automated Intelligence Updates: Automatically update tactics and technical information in the ATT&CK framework.

[0097] (9) Education and training

[0098] Customized training: Provide security training and practical exercises based on the ATT&CK framework to enhance the team's practical capabilities.

[0099] Continuous Learning: Encourage security teams to participate in regular professional development and continuing education activities.

[0100] (10) Attack Path Analysis

[0101] Attack path mapping: Perform attack path analysis using specialized tools to identify and eliminate potential intrusion paths.

[0102] Disruption Strategy: Implement controls to disrupt identified attack paths, reduce opportunities for lateral movement, and protect critical assets.

[0103] Implementation steps:

[0104] Phase 1: Planning and Integration

[0105] Needs Analysis: Evaluate the current security architecture and identify requirements and goals.

[0106] Tool selection: Choose appropriate security tools and technologies based on your needs.

[0107] Data Integration: Establish data integration processes to ensure that all data sources can work together.

[0108] Phase 2: Deployment and Configuration

[0109] System configuration: Configure security systems and tools to integrate new data sources and analytical techniques.

[0110] Policy definition: Develop targeted security policies, including deception defense and UEBA policies.

[0111] Automated processes: Set up automated threat detection and response processes.

[0112] Phase 3: Testing and Optimization

[0113] Simulated attack: Test the effectiveness of the system through dynamic adversarial simulation.

[0114] Drills and training: Organize red and blue team drills to train the security team's practical capabilities.

[0115] Performance Assessment: Evaluate the performance of automation and analysis tools and make necessary adjustments.

[0116] Phase 4: Maintenance and Updates

[0117] Continuous monitoring: Monitor system operation to ensure that all components are functioning properly.

[0118] Intelligence Updates: Regularly update threat intelligence and ATT&CK framework content.

[0119] Technology iteration: Update and upgrade security technologies and strategies based on changes in the threat environment.

[0120] Phase 5: Sharing and Collaboration

[0121] Information Sharing: Share threat intelligence and defense experiences with other organizations.

[0122] Community Engagement: Participate in the security community and contribute solutions and best practices.

[0123] Key considerations:

[0124] Privacy and Compliance: Ensure that data collection and processing comply with legal and regulatory requirements.

[0125] Resource allocation: Allocate resources based on priority to ensure that critical assets are adequately protected.

[0126] Culture and Awareness: Build a safety culture and improve the safety awareness of organizational members.

[0127] The above improvements can establish a powerful, flexible and adaptive security defense system to effectively combat increasingly complex network threats.

[0128] 3. Based on the AI ​​engine configured with an attack algorithm (which can be a hacker attack algorithm), identify whether it is a new attack method that attacks unknown vulnerabilities in the knowledge base. If so, analyze the new attack method and add it to the attack knowledge base to update the attack knowledge base so that the attack knowledge base contains as many attack methods as possible. Add the defense strategy corresponding to the new attack method to the defense knowledge base to update the defense knowledge base. When the new attack method attacks the vulnerability knowledge base, the defense strategy in the defense knowledge base can be used to defend against the new attack method and plan the attack link.

[0129] 4. Use intrusion and attack simulation technology to simulate automatic attacks, including:

[0130] 4.1. Collect information about the target system based on attack simulation tools, including network structure, system configuration, application programs, and security vulnerability information;

[0131] 4.2. Integrate the information of the target system into the knowledge graph to update the knowledge graph, which contains entities about the target system (such as servers, applications, databases) and the relationships between entities;

[0132] 4.3. Use the updated knowledge graph to simulate the path taken by the attacker, and use the recursive algorithm to simulate the attacker's behavior, find a new path on the graph until the target is found or the set termination condition is reached, and finally output the simulated attack path. The simulated path taken by the attacker is completed through a series of hypothetical attack steps. Each step is based on the analysis of the entities and their relationships in the graph. In each step of the attack simulation, the recursive algorithm will evaluate the current state and select the next action;

[0133] 4.4. Generate attack code or script based on the simulated attack path to simulate the attack under control;

[0134] 4.5. Perform simulated attacks in a secure test environment, monitor the response results of the target system, and based on the response results, determine the system's weaknesses and audit whether the system successfully monitors and responds to these attacks.

[0135] This step introduces intrusion and attack simulation technology (Breach Attack Simulation, BAS), runs simulated automatic attacks, and imitates international advanced hacker attack technology. Simulated attacks can help detect and verify the security protection capabilities of the network environment.

[0136] BAS is similar to penetration testing, but the assessment objectives of BAS and penetration testing are different. Real penetration is often to attack and penetrate real business targets. The main goal is to evaluate the security of real business targets, but it does not conduct a comprehensive security assessment of the network environment. It can continuously provide automated verification services, support 7*24 hours online duty, respond to security detection tasks at any time, and relieve security experts from daily complex and high-intensity detection. It supports instant tasks, scheduled tasks and cyclic tasks, and provides multi-task mode to meet users' daily detection needs. The system can meet the continuous concurrent execution of multiple tasks.

[0137] 5. Use the TTPs of cyber threat intelligence to analyze and restore the entire process of the attack, including:

[0138] 5.1. Extract key IOC evidence from cyber threat intelligence or analyze the expressions of human personnel to locate the behavioral characteristics of the attack;

[0139] 5.2. Associate homology conditions from behavioral characteristics, merge similar items from technical and tactical perspectives, and form behavioral templates that are understandable, valuable, and common to humans;

[0140] 5.3. Based on the context, goals and conditions of the behavior, establish the causal order of the behavior and restore the entire process of the attack.

[0141] This step focuses on the interpretation and correlation of attack behaviors. The TTPs analysis of network threat intelligence will no longer stop at extracting IOC features, but will determine the conditions, technical methods, and sequence of attack behaviors based on IOC features or other behavior descriptions, so that the attack can be presented "completely", which will help the security team better understand the attack process and take corresponding defensive measures.

[0142] 6. Update the attack knowledge base and defense knowledge base again based on the entire process of the attack event.

[0143] Embodiment 2:

[0144] The overall process is the same as in Example 1, except that:

[0145] This embodiment is aimed at IoT devices. Step 1 is aimed at specific IoT devices, such as smart homes, industrial control systems, etc., to collect communication data, firmware update information and other related data of these devices.

[0146] Step 2 extracts key features from the collected data before identifying the attack sequence of the attack data based on the ATT&CK model framework.

[0147] Embodiment 3:

[0148] like Figure 2 , Figure 3 As shown, an automatic update system for attack script library based on machine learning includes a process refinement module, a knowledge base update and link planning module, an attack simulation module, an analysis and restoration module, an automatic labeling and feedback module, a data fusion module, and a threat intelligence integration module.

[0149] The process extraction module is used to capture attack data, identify the attack sequence of the attack data based on the ATT&CK model framework, and determine the attack process.

[0150] The knowledge base update and link planning module is an AI engine configured with an attack algorithm, which is used to identify whether it is a new attack method that attacks unknown vulnerabilities in the attack knowledge base based on the attack process. If so, the new attack method is added to the attack knowledge base to update the attack knowledge base, and the defense strategy corresponding to the new attack method is added to the defense knowledge base to update the defense knowledge base, and the attack link is planned.

[0151] The knowledge base update and link planning module is internally provided with an adaptive learning unit, which is used to adaptively optimize the attack algorithm according to the result data obtained by the attack simulation module. The attack knowledge base is added with a real-time network environment monitoring unit, which is used to collect the status and changes of the current network environment in real time, and provide feedback to the knowledge base update and link planning module in real time when the network environment changes.

[0152] The attack simulation module is used to simulate automatic attacks using intrusion and attack simulation technology, including an information collection unit, a knowledge graph update unit, an attack path simulation unit, an attack code or script generation unit, and a simulated attack audit unit;

[0153] The information collection unit is used to collect information of the target system, including network structure, system configuration, application program and security vulnerability information;

[0154] The knowledge graph updating unit is used to integrate the information of the target system into the knowledge graph to update the knowledge graph;

[0155] The attack path simulation unit is used to simulate the path taken by the attacker using the updated knowledge graph, and use a recursive algorithm to simulate the attacker's behavior, looking for a new path on the graph until the target is found or the set termination condition is reached, and finally outputs the simulated attack path;

[0156] The attack code or script generating unit is used to generate an attack code or script according to the attack path obtained by simulation;

[0157] The simulated attack audit unit is used to perform simulated attacks in a safe test environment, monitor the response results of the target system, and audit whether the system successfully monitors and responds to these attacks based on the response results.

[0158] The analysis and restoration module is used to analyze and restore the entire process of the attack event using the TTPs of the network threat intelligence, and to update the attack knowledge base and the defense knowledge base again according to the entire process of the attack event, including a feature positioning unit, a behavior recognition unit, and an association unit;

[0159] The feature location unit is used to extract key IOC evidence or expressions of manual analysts from network threat intelligence to locate the behavioral features of the attack;

[0160] The behavior recognition unit is used to associate homology conditions from behavior characteristics, merge similar items from technical and tactical perspectives, and form a behavior template that is human-understandable, reference-worthy and common;

[0161] The association unit is used to formulate the causal order of the behavior according to the context, target and conditions of the behavior, and restore the entire process of the attack event.

[0162] The automatic marking and feedback module is used to automatically mark the result of whether the simulated attack is successful, and feed it back to the attack knowledge base for corresponding update;

[0163] The data fusion module is used to fuse multi-source data in the entire process of restoring the attack event, and the multi-source data includes network traffic and system logs;

[0164] The threat intelligence integration module is used to obtain the latest attack techniques and vulnerability information in real time based on an external threat intelligence platform and integrate it into the attack knowledge base.

[0165] The specific implementation of the above modules is shown in Example 1.

[0166] Embodiment 4:

[0167] like Figure 4 As shown, a power grid asset security effectiveness assessment device based on an improved cloud model includes a processor and a memory;

[0168] The memory is used to store computer program code and transmit the computer program code to the processor;

[0169] The processor is used to execute the automatic update method of the attack script library based on machine learning as described in Example 1 or 2 according to the instructions in the computer program code.

Claims

1. A method for automatically updating an attack script library based on machine learning, characterized in that: include: S1. Capture attack data, identify the attack sequence of attack data based on the ATT&CK model framework, and determine the attack process; S2. Based on the attack process, identify whether it is a new attack method for unknown vulnerabilities in the attack knowledge base. If so, add the new attack method to the attack knowledge base to update the attack knowledge base, add the defense strategy corresponding to the new attack method to the defense knowledge base to update the defense knowledge base, and plan the attack link; S3. Use intrusion and attack simulation technology to simulate automatic attacks, including: S31. Collect information about the target system, including network structure, system configuration, application programs, and security vulnerability information; S32, integrating the information of the target system into the knowledge graph to update the knowledge graph; S33, using the updated knowledge graph to simulate the path taken by the attacker, and using a recursive algorithm to simulate the attacker's behavior, looking for a new path on the graph until the target is found or the set termination condition is reached, and finally outputting the simulated attack path; S34, generating attack code or script according to the attack path obtained by simulation; S35. Perform simulated attacks in a secure test environment, monitor the response results of the target system, and audit whether the system successfully monitors and responds to these attacks based on the response results; S4. Analyze and restore the entire process of the attack event using the TTPs of the network threat intelligence, and re-update the attack knowledge base and the defense knowledge base based on the entire process of the attack event. Analyze and restore the entire process of the attack event using the TTPs of the network threat intelligence includes: S41. Extract key IOC evidence or manual analysis personnel expressions from network threat intelligence to locate the behavioral characteristics of the attack; S42. Associate homology conditions from behavioral characteristics, merge similar items from technical and tactical perspectives, and form a behavioral template that is understandable, valuable, and common to humans; S43. Based on the context, goals and conditions of the behavior, establish the causal order of the behavior and restore the entire process of the attack.

2. The method for automatically updating an attack script library based on machine learning according to claim 1, characterized in that: The S2 is executed by an AI engine configured with an attack algorithm.

3. A machine learning-based attack script library automatic update system, characterized by: It includes process extraction module, knowledge base update and link planning module, attack simulation module, and analysis and restoration module; The process extraction module is used to capture attack data, identify the attack sequence of the attack data based on the ATT&CK model framework, and determine the attack process; The knowledge base update and link planning module is used to identify whether it is a new attack method for attacking unknown vulnerabilities in the attack knowledge base based on the attack process. If so, the new attack method is added to the attack knowledge base to update the attack knowledge base, the defense strategy corresponding to the new attack method is added to the defense knowledge base to update the defense knowledge base, and the attack link is planned; The attack simulation module is used to simulate automatic attacks using intrusion and attack simulation technology, including an information collection unit, a knowledge graph update unit, an attack path simulation unit, an attack code or script generation unit, and a simulated attack audit unit; The information collection unit is used to collect information of the target system, including network structure, system configuration, application program and security vulnerability information; The knowledge graph updating unit is used to integrate the information of the target system into the knowledge graph to update the knowledge graph; The attack path simulation unit is used to simulate the path taken by the attacker using the updated knowledge graph, and use a recursive algorithm to simulate the attacker's behavior, looking for a new path on the graph until the target is found or the set termination condition is reached, and finally outputs the simulated attack path; The attack code or script generating unit is used to generate an attack code or script according to the attack path obtained by simulation; The simulated attack audit unit is used to perform simulated attacks in a safe test environment, monitor the response results of the target system, and audit whether the system successfully monitors and responds to these attacks based on the response results; The analysis and restoration module is used to analyze and restore the entire process of the attack event using the TTPs of the network threat intelligence, and to update the attack knowledge base and the defense knowledge base again according to the entire process of the attack event, including a feature positioning unit, a behavior recognition unit, and an association unit; The feature location unit is used to extract key IOC evidence or expressions of manual analysts from network threat intelligence to locate the behavioral features of the attack; The behavior recognition unit is used to associate homology conditions from behavior characteristics, merge similar items from technical and tactical perspectives, and form a behavior template that is human-understandable, reference-worthy and common; The association unit is used to formulate the causal order of the behavior according to the context, target and conditions of the behavior, and restore the entire process of the attack event.

4. The automatic update system of attack script library based on machine learning according to claim 3 is characterized in that: The knowledge base update and link planning module is an AI engine configured with an attack algorithm, and an adaptive learning unit is provided inside the module, which is used to adaptively optimize the attack algorithm according to the result data obtained by the attack simulation module; A real-time network environment monitoring unit is added to the attack knowledge base, and the unit is used to collect the status and changes of the current network environment in real time, and to provide feedback to the knowledge base update and link planning module in real time when the network environment changes.

5. The automatic update system of attack script library based on machine learning according to claim 3 is characterized in that: The system also includes an automatic labeling and feedback module, a data fusion module, and a threat intelligence integration module; The automatic marking and feedback module is used to automatically mark the result of whether the simulated attack is successful, and feed it back to the attack knowledge base for corresponding update; The data fusion module is used to fuse multi-source data in the entire process of restoring the attack event, and the multi-source data includes network traffic and system logs; The threat intelligence integration module is used to obtain the latest attack techniques and vulnerability information in real time based on an external threat intelligence platform and integrate it into the attack knowledge base.

6. A machine learning-based attack script library automatic update device, characterized by: including a processor and a memory; The memory is used to store computer program code and transmit the computer program code to the processor; The processor is used to execute the automatic update method of the attack script library based on machine learning as described in claims 1-2 according to the instructions in the computer program code.

Citation Information

Patent Citations

  • Threat response method and device based on threat intelligence and ATT&CK

    CN112769821A

  • Threat hunting method, device and equipment based on attack and defense confrontation and storage medium

    CN114205123A