An attack posture analysis method and related apparatus
By performing multi-dimensional feature analysis on the alarm data of blocked IPs and external threat intelligence, the problem that traditional network security situation awareness cannot accurately assess advanced long-term threats has been solved, achieving rapid, comprehensive, and accurate attack situation analysis and network security improvement.
Patent Information
- Application Number
- CN202410601269.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-15
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-05-15
AI Technical Summary
Traditional cybersecurity situational awareness is insufficient to accurately assess the external attack posture against enterprises, especially when advanced persistent threats (APTs) are low-frequency, multi-IP, and multi-stage attacks. Monitoring indicators may still show a flat trend, making it impossible to detect threats in a timely manner.
By acquiring alarm data of blocked IPs and external threat intelligence, multiple attack posture characteristics are extracted, divided into multiple indicator groups, the threat level of each indicator group is determined, a target threat level combination is generated, and a pre-set threat level combination scoring quick reference table is queried to obtain the threat score of the blocked IP, thus realizing multi-dimensional threat level quantification.
It enables rapid, comprehensive, and accurate attack posture analysis of blocked IPs, allowing for timely adjustment of network security protection levels and improvement of network security.
Smart Images

Figure CN118337515B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and more specifically, to an attack posture analysis method and related apparatus. Background Technology
[0002] With the rapid development of computer networks, network security has become a focal point of concern for all parties.
[0003] Network security situation awareness involves acquiring, understanding, and displaying security elements that can cause changes in the network situation within a large-scale network environment, and using this information to predict future network security trends. Traditional network security situation awareness primarily relies on the detection of anomalies in monitoring metrics, such as abnormal changes in the number of alerts or blocked IPs within a time window. If a monitoring metric spikes abnormally high on a particular day, it indicates that a network attack is currently underway. However, in the event of low-frequency, multi-IP, multi-stage APT (Advanced Persistent Threat) attacks, monitoring metrics may still show a flat trend, and traditional network security situation awareness may fail to detect the threat. Therefore, traditional network security situation awareness has limitations and struggles to accurately assess the external attack posture against an enterprise. Summary of the Invention
[0004] In view of this, the present invention provides an attack situation analysis method and related apparatus, which can quickly, comprehensively and accurately analyze the attack situation periodically.
[0005] To achieve the above-mentioned objectives, the present invention provides the following specific technical solution:
[0006] In a first aspect, embodiments of the present invention provide an attack posture analysis method, including:
[0007] Acquire alarm data of blocked IPs within a preset period and external threat intelligence of the blocked IPs;
[0008] Multiple attack posture characteristics of the blocked IP are extracted from the alarm data and the external threat intelligence;
[0009] The multiple attack situation features are divided into multiple indicator groups, and each indicator group corresponds to an attack feature dimension.
[0010] Based on the attack posture characteristics in each of the indicator groups, the threat level corresponding to each indicator group is determined.
[0011] Based on the threat level corresponding to each of the aforementioned indicator groups, a target threat level combination is generated;
[0012] The threat score of the blocked IP is obtained by querying a pre-set threat level combination scoring quick reference table based on the target threat level combination.
[0013] In some embodiments, the extraction of multiple attack posture characteristics of the blocked IP from the alarm data and the external threat intelligence includes:
[0014] The first attack posture characteristics of the blocked IP are extracted from the alarm data. The first attack posture characteristics include: attack result, first attack method, first attack intent, attack purpose, and first attacker identity.
[0015] Based on the blocked IP, query the external threat intelligence. If the external threat intelligence includes the blocked IP, extract the second attack posture characteristics of the blocked IP from the external threat intelligence. If the external threat intelligence does not include the blocked IP, set the second attack posture characteristics of the blocked IP to a default value. The second attack posture characteristics include: second attack method, second attack intent, second attack identity, threat level, and confidence level.
[0016] The first attack posture characteristics and the second attack posture characteristics of the blocked IP are encoded respectively.
[0017] In some embodiments, determining the threat level corresponding to each indicator group based on the attack posture characteristics in each indicator group includes:
[0018] Determine the target constraints that the attack posture characteristics satisfy in each of the indicator groups;
[0019] The threat level corresponding to each indicator group is determined based on the target constraints satisfied by the attack posture characteristics in each indicator group and the pre-set correspondence between the constraints and threat levels in each indicator group.
[0020] In some embodiments, the step of querying a pre-set threat level combination scoring quick lookup table based on the target threat level combination to obtain the threat score of the blocked IP includes:
[0021] The threat score corresponding to the target threat level combination is obtained by using the threat score corresponding to each threat level combination in the threat level combination scoring quick lookup table.
[0022] Determine whether the attack posture features of the blocked IP in each of the indicator groups correspond to the maximum satisfied threat vector. For each indicator group, the same threat level corresponds to at least one set of attack posture features, and each set of attack posture features corresponds to a threat vector. The maximum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the largest Boolean value, and the minimum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the smallest Boolean value.
[0023] If the attack posture characteristics of the blocked IP in each of the indicator groups correspond to the maximum satisfied threat vector, the threat score corresponding to the target threat level combination is determined as the threat score of the blocked IP.
[0024] If the attack posture characteristics of the blocked IP in each of the indicator groups do not all correspond to the maximum satisfied threat vector, an interpolation method is used to score the threat of the blocked IP.
[0025] In some embodiments, the method of using interpolation to perform threat scoring on the blocked IP includes:
[0026] Determine the current threat vector and current threat level corresponding to the attack posture characteristics of the blocked IP in each of the indicator groups;
[0027] For each of the indicator groups, the distance between the current threat vector and the minimum satisfied threat vector is divided by the depth of the current threat level to obtain the proportion of the current threat vector. The proportion of the current threat vector is then multiplied by a pre-set difference between adjacent threat levels to obtain the proportion difference of the indicator group. The depth of the current threat level is the distance between the maximum satisfied threat vector and the minimum satisfied threat vector in the current threat level.
[0028] Calculate the average of the proportion differences of each of the aforementioned indicator groups to obtain the average proportion difference;
[0029] The threat score of the blocked IP is obtained by subtracting the average percentage difference from the threat score corresponding to the target threat level combination.
[0030] In some embodiments, a method for setting up a quick reference table for assigning scores to threat level combinations includes:
[0031] The threat score of the combination of threat levels with the highest threat intensity is set to a preset value. The combination of threat levels with the highest threat intensity is the combination of threat levels obtained by arranging the highest threat levels of each of the indicator groups in a preset order.
[0032] Set the difference between adjacent threat levels in each of the aforementioned indicator groups;
[0033] Based on the combination of threat levels with the highest threat intensity, the threat level of one of the indicator groups is changed in sequence to determine the resulting combination of threat levels, the target indicator group to be changed, and the changed threat level.
[0034] Based on the threat score of the threat level combination before the modification, the modified target indicator group, the modified threat level, and the score difference between adjacent threat levels in each indicator group, the threat score of the modified threat level combination is determined until a quick reference table of threat level combination scoring composed of the threat scores of all threat level combinations is obtained.
[0035] In some embodiments, it also includes:
[0036] An attacker profile of the blocked IP is established based on the alarm data and the external threat intelligence. The attacker profile of the blocked IP includes the attack method, attack intent and attacker identity.
[0037] In some embodiments, it also includes:
[0038] The blocked IPs with a threat score greater than a threshold are identified as target blocked IPs;
[0039] The number of the target blocked IPs and the proportion of the target blocked IPs within a preset period are statistically analyzed.
[0040] Secondly, embodiments of the present invention provide an attack posture analysis device, comprising:
[0041] The data acquisition unit is used to acquire alarm data of blocked IPs within a preset period and external threat intelligence of the blocked IPs;
[0042] The feature extraction unit is used to extract multiple attack posture features of the blocked IP from the alarm data and the external threat intelligence;
[0043] The feature segmentation unit is used to divide the multiple attack situation features into multiple indicator groups, and each indicator group corresponds to an attack feature dimension.
[0044] The threat level determination unit is used to determine the threat level corresponding to each of the indicator groups based on the attack situation characteristics in each indicator group.
[0045] The threat level combination generation unit is used to generate a target threat level combination based on the threat level corresponding to each of the indicator groups.
[0046] The threat scoring determination unit is used to query a pre-set threat level combination scoring quick lookup table based on the target threat level combination to obtain the threat score of the blocked IP.
[0047] Thirdly, embodiments of the present invention provide an electronic device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the attack posture analysis method described in any implementation of the first aspect.
[0048] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0049] This invention discloses an attack posture analysis method and related apparatus. Taking attackers as the analysis target, it periodically acquires alarm data and external threat intelligence of blocked IPs. By extracting multiple attack posture features of the blocked IPs from the alarm data and external threat intelligence, and dividing these features into multiple indicator groups, it achieves multi-dimensional attack characteristic analysis of the blocked IPs. Based on this, it determines the threat level corresponding to each indicator group according to the attack posture features in each group, generates a target threat level combination based on the threat level of each indicator group, and obtains the threat score of the blocked IPs by querying a pre-set threat level combination scoring quick reference table. This achieves multi-dimensional threat level quantification and overall threat quantification of the blocked IPs, enabling rapid, comprehensive, and accurate periodic analysis of attack postures. This helps to adjust network security protection levels in a timely manner based on attack postures, thereby improving network security. Attached Figure Description
[0050] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0051] Figure 1 This is a flowchart illustrating an attack situation analysis method disclosed in an embodiment of the present invention;
[0052] Figure 2 This is a schematic representation of a threat level combination scoring quick lookup method disclosed in an embodiment of the present invention;
[0053] Figure 3 This is a schematic diagram of the structure of an attack situation analysis device disclosed in an embodiment of the present invention;
[0054] Figure 4 This is a schematic diagram of the structure of an electronic device disclosed in an embodiment of the present invention. Detailed Implementation
[0055] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0056] This invention provides an attack situation analysis method and related apparatus. Before introducing the technical solution provided by this invention, an application scenario involved in this invention will be described first.
[0057] For example, to improve network security, security monitoring systems are typically deployed in large-scale network environments. During operation, these systems block IPs based on built-in rules, output alarm data, and periodically conduct network security situational awareness. However, traditional network security situational awareness primarily relies on anomaly detection of monitoring indicators, such as abnormal changes in the number of alarms or blocked IPs within a time window, reflecting the trend of these indicators. Furthermore, network security situational awareness usually considers the enterprise's own vulnerabilities, such as vulnerability remediation and incident handling indicators. In other words, traditional network security situational awareness combines monitoring indicators with internal vulnerability remediation and incident handling indicators for overall situational assessment, making it difficult to perceive complex attack scenarios. For example, even under phased, low-frequency attacks, the network security situation may still show a flat trend, failing to accurately depict the external attack posture against the enterprise. Therefore, this invention focuses on attackers, achieving multi-dimensional attack characteristic analysis of blocked IPs, quantifying the multi-dimensional threat levels of blocked IPs, and quantifying the overall threat. This enables rapid, comprehensive, and accurate periodic analysis of the attack posture. For instance, when the number or proportion of malicious IPs with high threat scores increases significantly, it helps to adjust the network security protection level in a timely manner based on the attack posture, thereby improving network security.
[0058] Figure 1 This is a flowchart illustrating an attack posture analysis method disclosed in an embodiment of the present invention, as shown below. Figure 1 As shown, the attack posture analysis method disclosed in this embodiment specifically includes the following steps:
[0059] S101: Obtain alarm data of blocked IPs within a preset period and external threat intelligence of blocked IPs;
[0060] The preset period is the attack situation analysis period, which can be set according to the actual application scenario, such as one hour, one day, one week, etc. Taking the preset period of one day as an example, the attack situation analysis is carried out based on the alarm data of blocked IPs and the external threat intelligence of blocked IPs within each day.
[0061] The blocked IPs are derived from a list of blocked IPs obtained by security monitoring equipment or systems based on static rules and statistical methods. The blocked IPs are IPs that are prohibited from accessing the system.
[0062] Alarm data is output by security monitoring equipment or security monitoring systems, while external threat intelligence is provided by external vendors.
[0063] Alarm data based on blocked IP addresses includes:
[0064] (1) Traffic monitoring equipment collects attack source address, attack target, triggered alarm, trigger time, and attack payload, and focuses on analyzing the main HTTP fields of web alarm logs.
[0065] (2) Host security protection tools collect data such as logs, application processes, and system commands.
[0066] (3) Honeypots collect data such as attacker command execution and lateral movement paths.
[0067] (4) Extract IOCs (Indicators of Compromise) such as malicious domains, hacker tools, and malicious files that appear in the alerts.
[0068] External threat intelligence includes data such as confidence level, threat level, historical attack methods, attack target preferences, active time, domain name resolution records, malicious file IOCs, hacking tools, geographic information, ISP, and network type.
[0069] Furthermore, to facilitate subsequent analysis and processing, the acquired data will undergo unified data format preprocessing. This includes attempting to extract malicious domains, hacking tools, and malicious files from encrypted messages; removing encryption protocol alarm data irrelevant to business operations; and eliminating interfering data (such as data introduced from internal security assessments and crawler mapping without intrusion intent). The unified data format can be a web-based alarm data format.
[0070] S102: Extract multiple attack posture characteristics of blocked IPs from alarm data and external threat intelligence;
[0071] The alarm data can reveal multiple attack characteristics representing the blocking IP behavior within a preset period, such as attack results, attack methods, attack intent, attack purpose, and attacker identity.
[0072] External threat intelligence can provide multiple attack posture characteristics that indicate the blocking of IP historical behavior, such as attack methods, attack intent, attacker identity, threat level, and confidence level.
[0073] Although the attack posture characteristics of blocked IPs extracted from alarm data and external threat intelligence contain similar features, such as attack methods, attack intent, and attacker identity, it should be noted that the values of attack posture characteristics may differ due to the different acquisition channels. For example, attack methods extracted from alarm data may cover the three attack stages: attack preparation, attack execution, and privilege escalation, while attack methods extracted from external threat intelligence may only involve the attack preparation stage.
[0074] For ease of distinction, for example, the attack posture features extracted from the alarm data are defined as the first attack posture features, which include: attack result, first attack method, first attack intent, attack purpose, and first attacker identity; the attack posture features extracted from external threat intelligence are defined as the second attack posture features, which include: second attack method, second attack intent, second attacker identity, threat level, and confidence level.
[0075] S103: Divide multiple attack posture features into multiple indicator groups, with each indicator group corresponding to an attack feature dimension;
[0076] The number of indicator groups is set according to the actual application scenario. The more indicator groups there are, the higher the accuracy of the analysis of blocked IPs.
[0077] For example, multiple attack posture characteristics are divided into a first indicator group, a second indicator group, a third indicator group, a fourth indicator group, and a fifth indicator group.
[0078] The first indicator group includes the attack results in the first attack posture characteristics, representing the dimension of the attack results;
[0079] The second indicator group includes the first attack method in the first attack posture characteristics and the second attack method in the second attack posture characteristics, representing the attack method dimension;
[0080] The third indicator group includes the first attack intent and attack purpose in the first attack posture characteristics and the second attack intent in the second attack posture characteristics, representing the attack intent dimension;
[0081] The fourth indicator group includes the first attack identity in the first attack posture characteristics and the second attack identity in the second attack posture characteristics, representing the attack identity dimension;
[0082] The fifth indicator group includes the threat level and confidence level from the second attack posture characteristics, representing the threat level dimension.
[0083] S104: Determine the threat level corresponding to each indicator group based on the attack posture characteristics in each indicator group;
[0084] The threat level here is a relative concept. For the same set of indicators, since each attack posture characteristic has two or more possible values, the threat caused by different values is different, and the corresponding threat level is also different. Therefore, the threat level here is relatively accurate and objective.
[0085] Taking the first indicator group as an example, the attack result includes two values: attack success and attack failure. The threat level corresponding to a successful attack is necessarily higher than the threat level corresponding to an attack failure.
[0086] Apart from the first indicator group, the other indicator groups include multiple attack posture characteristics. Each attack posture characteristic has two or more possible values. Multiple attack posture characteristics correspond to multiple combinations of values. Different combinations of values may correspond to the same threat level or different threat levels.
[0087] For example, the correspondence between the value combinations in each indicator group and the threat level is pre-defined.
[0088] For example, the correspondence between the constraints satisfied by the value combinations in each indicator group and the threat level is predefined.
[0089] Taking the third indicator group as an example, both the first and second attack identities include two values: suspected fixed hacker and controlled or dynamic address. The threat levels corresponding to the first attack identity being suspected fixed hacker and the second attack identity being suspected fixed hacker, the first attack identity being suspected fixed hacker and the second attack identity being controlled or dynamic address, and the first attack identity being controlled or dynamic address and the second attack identity being suspected fixed hacker are the same and are represented by 0. The threat level corresponding to the first attack identity being controlled or dynamic address and the second attack identity being controlled or dynamic address is another threat level and is represented by 1. Threat level 0 is higher than threat level 1.
[0090] For ease of subsequent processing, threat levels are represented by numbers.
[0091] S105: Generate a target threat level combination based on the threat level corresponding to each indicator group;
[0092] The threat levels corresponding to each indicator group are arranged in a preset order to obtain a set of numbers, namely the target threat level combination. For example, the preset order is: first indicator group → second indicator group → third indicator group → fourth indicator group → fifth indicator group. The target threat level combination 12010 means that the threat level of the first indicator group is 1, the threat level of the second indicator group is 2, the threat level of the third indicator group is 0, the threat level of the fourth indicator group is 1, and the threat level of the fifth indicator group is 0.
[0093] S106: Query the pre-set threat level combination scoring quick reference table based on the target threat level combination to obtain the threat score of the blocked IP.
[0094] Threat ratings can be based on a 10-point scale, a 100-point scale, or other scales.
[0095] The Threat Level Combination Scoring Quick Reference Table includes threat scores corresponding to different threat level combinations. Different threat level combinations correspond to different levels of threat intensity; the higher the threat intensity represented by a threat level combination, the higher the corresponding threat score. The threat score is a relative score, that is, the score of a threat level combination relative to other threat level combinations. For example, threat level combination 00000 indicates that all indicator groups have the highest threat level, and its threat intensity is necessarily greater than other threat level combinations. Therefore, threat level combination 00000 has the highest threat score. It is evident that obtaining the threat score for a blocked IP by consulting the pre-set threat level combination scoring quick reference table based on the target threat level combination is relatively accurate and objective.
[0096] This embodiment discloses an attack posture analysis method that takes attackers as the analysis object, periodically acquires alarm data and external threat intelligence of blocked IPs, extracts multiple attack posture features of blocked IPs from the alarm data and external threat intelligence, and divides these features into multiple indicator groups to achieve multi-dimensional attack characteristic analysis of blocked IPs. Based on this, the threat level corresponding to each indicator group is determined according to the attack posture features in each indicator group. A target threat level combination is generated based on the threat level corresponding to each indicator group. The threat score of the blocked IP is obtained by querying a pre-set threat level combination scoring quick reference table based on the target threat level combination. This achieves multi-dimensional threat level quantification and overall threat quantification of blocked IPs, enabling rapid, comprehensive, and accurate periodic analysis of attack postures. This helps to adjust network security protection levels in a timely manner based on attack postures, thereby improving network security.
[0097] Furthermore, since external threat intelligence is intelligence information provided by the vendor regarding historical attack behavior, i.e., historical threat intelligence information, it may or may not include blocked IPs within a preset period. To avoid null values for attack posture characteristics due to the exclusion of blocked IPs within a preset period in external threat intelligence, this embodiment provides an optional implementation method for S102 in the above embodiment: extracting multiple attack posture characteristics of blocked IPs from alarm data and external threat intelligence, including the following steps:
[0098] A1: Extract the first attack posture characteristics of the blocked IP from the alarm data. The first attack posture characteristics include: attack result, first attack method, first attack intent, attack purpose, and first attacker identity.
[0099] A2: Query external threat intelligence based on the blocked IP. If the external threat intelligence includes the blocked IP, extract the second attack posture characteristics of the blocked IP from the external threat intelligence. If the external threat intelligence does not include the blocked IP, set the second attack posture characteristics of the blocked IP as the default value. The second attack posture characteristics include: second attack method, second attack intent, second attack identity, threat level, and confidence level.
[0100] Since external threat intelligence does not include blocked IPs, the threat level of blocked IPs can be considered relatively low. The default value for each secondary attack posture characteristic can be set to the lowest threat level, such as setting the default value for secondary attack intent to non-malicious and the default value for threat level to low threat.
[0101] A3: Encode the first and second attack posture characteristics of the blocked IP respectively.
[0102] For example, attack results: number 0 represents a successful attack, that is, a successful intrusion, obtaining server privileges or sensitive information; number 1 represents a failed attack, that is, an attack attempt that was not successfully exploited.
[0103] The first attack method divides the attack into three stages: 1. Attack preparation: information gathering, routine vulnerability scanning, phishing emails, fake websites, etc.; 2. Attack execution: targeted vulnerability exploitation, malicious files, denial of service, etc.; 3. Privilege maintenance: backdoor persistence, command execution, etc. Number 0 represents coverage of all three attack stages; number 1 represents the presence of either the attack execution or privilege maintenance stage, but not all three stages; number 2 represents only the attack preparation stage.
[0104] The first attack intent is: number 0 represents malicious, that is, the attack methods include destructive behaviors such as remote code execution, command execution, and credential stuffing; number 1 represents non-malicious, that is, probing behaviors such as mapping, web crawling, and port scanning, which may be followed by search engines and security companies.
[0105] Attack objective: Number 0 represents a targeted attack, that is, various attack attempts are carried out against a specific application or product with the goal of breaking into the system. It is usually assumed that sufficient reconnaissance and detection have been completed in the early stage before the attack is carried out. Number 1 represents a non-targeted attack, that is, there is no specific attack target at the moment, which is mainly reflected in the information collection and detection stage.
[0106] The first attack identity is categorized as follows: 0 represents a suspected fixed hacker, meaning an attacker directly identifiable through IOC (Indicator of Compatibility), such as those exhibiting domain name resolution or malicious files in alert messages, showing sustained attack behavior, and whose historical alerts reveal suspected APT attacks, thus identifying the attacker's fixed springboard. 1 represents a controlled or dynamic address, typically considered a dynamic address, including botnets of carrier base stations, controlled terminals, or servers. These IPs are briefly occupied by attackers but subsequently used primarily by normal users, making direct attack identification difficult. If the attack identity cannot be determined, this category is the default.
[0107] Second attack method (TI): Similarly, number 0 represents covering all three attack phases; number 1 represents the presence of an attack execution or privilege maintenance phase, but not covering all three phases; number 2 represents only the attack preparation phase.
[0108] Secondary Intent of Attack (TI): Again, number 0 represents malicious intent and number 1 represents non-malicious intent.
[0109] Secondary Attacker Identity (TI): Similarly, number 0 represents a suspected fixed hacker, and number 1 represents a controlled or dynamic address.
[0110] Threat Level (TI): 0 represents high, meaning a high threat level according to multi-source intelligence assessment; 1 represents medium, meaning a medium threat level according to multi-source intelligence assessment; and 2 represents low, meaning a low threat level according to multi-source intelligence assessment.
[0111] Confidence Level (TI): 0 represents high confidence, i.e., high confidence level of multi-source intelligence assessment; 1 represents medium confidence, i.e., medium confidence level of multi-source intelligence assessment; and 2 represents low confidence, i.e., low confidence level of multi-source intelligence assessment.
[0112] In the above embodiment, S104: Determining the threat level corresponding to each indicator group based on the attack situation characteristics in each indicator group can be implemented in multiple ways. The following is one optional implementation method:
[0113] B1: Determine the target constraints that the attack posture characteristics satisfy in each indicator group;
[0114] B2: Determine the threat level corresponding to each indicator group based on the target constraints satisfied by the attack posture characteristics in each indicator group and the pre-defined correspondence between the constraints and threat levels in each indicator group.
[0115] For example, the correspondence between constraints and threat levels in the first indicator group is shown in Table 1.
[0116] Table 1
[0117]
[0118] The correspondence between constraints and threat levels in the second indicator group is shown in Table 2.
[0119] Table 2
[0120]
[0121]
[0122] The correspondence between constraints and threat levels in the third indicator group is shown in Table 3.
[0123] Table 3
[0124]
[0125] The correspondence between constraints and threat levels in the fourth indicator group is shown in Table 4.
[0126] Table 4
[0127]
[0128]
[0129] The correspondence between constraints and threat levels in the fifth indicator group is shown in Table 5.
[0130] Table 5
[0131]
[0132] Each indicator group includes at least one attack posture feature. For example, the first indicator group only includes <attack results>, and the second indicator group includes: <attack method> (i.e., the first attack method mentioned above) and <attack method (TI)> (i.e., the second attack method mentioned above).
[0133] Each indicator group defines threat levels within the group based on the constraints satisfied by the attack posture characteristics. For example, the second indicator group defines three threat levels, with level 0 being the highest threat level, decreasing in numerical order. After the attack posture characteristics are encoded, they can be represented by threat vectors. Taking the second indicator group as an example, the threat vector (0,0,0) represents attack intent: 0 and attack intent (T1): 0 and attack purpose: 0.
[0134] Within each indicator group, the same constraints are used for the same threat level, and there may be more than one threat vector satisfying the same constraint. We define the maximum satisfied threat vector based on the Boolean maximum satisfaction condition, and conversely, the minimum satisfied threat vector based on the Boolean minimum satisfaction condition. That is, the maximum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the largest Boolean value, and the minimum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the smallest Boolean value. For example, within threat level 0 of the second indicator group, the maximum satisfied threat vector is "Attack Method: 0 / Attack Method (TI): 0", and the minimum satisfied threat vector is "Attack Method: 0 / Attack Method (TI): 2" or "Attack Method: 2 / Attack Method (TI): 0".
[0135] This embodiment provides a method for setting a quick lookup table for threat level combination scoring, specifically including the following steps:
[0136] C1: Set the threat score of the highest threat level combination to a preset value. The highest threat level combination is the threat level combination obtained by arranging the highest threat levels of each indicator group in a preset order.
[0137] Taking the five indicator groups mentioned above as an example, the highest threat level combination is 00000, and its threat score can be set to a preset value of 10 points.
[0138] C2: Set the difference between adjacent threat levels in each indicator group;
[0139] The difference between adjacent threat levels in each indicator group can be set according to the actual application scenario.
[0140] For example: the difference between adjacent threat levels in the first indicator group is 0.6, the difference between adjacent threat levels in the second indicator group is 1.1, the difference between adjacent threat levels in the third indicator group is 1.1, the difference between adjacent threat levels in the fourth indicator group is 1.1, and the difference between adjacent threat levels in the fifth indicator group is 0.5.
[0141] C3: Based on the combination of threat levels with the highest threat intensity, modify the threat level of one indicator group in sequence, and determine the resulting threat level combination, the target indicator group to be modified, and the modified threat level;
[0142] C4: Based on the threat score of the threat level combination before the change, the target indicator group to be changed, the threat level after the change, and the score difference between adjacent threat levels in each indicator group, determine the threat score of the threat level combination after the change, until a quick reference table of threat level combination scoring composed of the threat scores of all threat level combinations is obtained.
[0143] For example, if the threat level combination before the change is the highest threat level combination 00000 with a threat score of 10, the target indicator group to be changed is the first indicator group, the threat level after the change is 1, and the difference between adjacent threat levels in the first indicator group is 0.6, then the threat score of the threat level combination 10000 after the change is 10 - 0.6 = 9.4.
[0144] For example: if the threat level combination before the change is 10000 and the threat score is 9.4, the target indicator group to be changed is the second indicator group, the threat level after the change is 2 (that is, it is 2 threat levels higher than the original threat level), and the difference between adjacent threat levels in the first indicator group is 1.1, then the threat score of the threat level combination 12000 after the change is 9.4 - 2 × 1.1 = 7.2.
[0145] Until a quick reference table of threat level combination scores, comprising all threat level combinations, is obtained, such as... Figure 2 As shown.
[0146] In the above embodiment, S106: The threat score of the blocked IP can be obtained by querying a pre-set threat level combination scoring quick lookup table based on the target threat level combination. There are several ways to achieve this; the following examples illustrate two possible implementation methods:
[0147] Method 1 includes the following steps:
[0148] D1: Based on the threat score corresponding to each threat level combination in the threat level combination scoring quick reference table, obtain the threat score corresponding to the target threat level combination;
[0149] D2: The threat score corresponding to the target threat level combination is determined as the threat score for blocking the IP.
[0150] For example, if the target threat level combination is 12010, then the query... Figure 2 The threat level combination scoring quick reference table shown indicates that the threat score corresponding to the target threat level combination 12010 is 6.1.
[0151] In Method 1, as long as the IPs have the same combination of threat levels, the blocked IPs will have the same threat score. The threat score of the blocked IPs can be quickly obtained from the threat level combination scoring quick reference table.
[0152] Method 2 includes the following steps:
[0153] E1: Based on the threat score corresponding to each threat level combination in the threat level combination scoring quick reference table, obtain the threat score corresponding to the target threat level combination;
[0154] E2: Determine whether the attack posture characteristics of the blocked IP in each indicator group correspond to the maximum satisfied threat vector;
[0155] For each indicator group, the same threat level corresponds to at least one set of attack posture features. Each set of attack posture features corresponds to a threat vector. The threat vector that satisfies the maximum constraint is the threat vector that satisfies the corresponding constraint and has the largest Boolean value. The threat vector that satisfies the minimum constraint is the threat vector that satisfies the corresponding constraint and has the smallest Boolean value.
[0156] For example: Since the constraint for threat level 0 in the second indicator group is: Attack method: 0 or Attack method (TI): 0, threat level 0 in the second indicator group corresponds to the following 5 threat vectors:
[0157] "Attack Method: 0 / Attack Method (TI): 0";
[0158] "Attack Method: 0 / Attack Method (TI): 1";
[0159] "Attack Method: 0 / Attack Method (TI): 2";
[0160] "Attack Method: 1 / Attack Method (TI): 0";
[0161] "Attack methods: 2 / Attack methods (TI): 0".
[0162] The maximum satisfied threat vector is the Boolean maximum "Attack method: 0 / Attack method (TI): 0", and the minimum satisfied threat vector is the Boolean minimum "Attack method: 0 / Attack method (TI): 2" or "Attack method: 2 / Attack method (TI): 0".
[0163] If the threat vectors of other indicator groups are the same, but the threat vectors of the second indicator group are different, and they all correspond to the same threat score, then the threat score result is relatively coarse and not precise enough. In order to obtain a more accurate threat score, the following operations are performed.
[0164] E3: If the attack posture characteristics of the blocked IP in each indicator group correspond to the maximum satisfied threat vector, the threat score corresponding to the target threat level combination is determined as the threat score of the blocked IP.
[0165] E4: If the attack posture characteristics of the blocked IP in each indicator group do not all correspond to the maximum satisfied threat vector, an interpolation method is used to score the threat of the blocked IP.
[0166] For example, one alternative implementation of E4 includes the following steps:
[0167] E41: Determine the current threat vector and current threat level corresponding to the attack posture characteristics of the blocked IP in each indicator group;
[0168] Taking the attack posture characteristics of the blocked IP in the second indicator group as follows: attack method: 0 and attack method (TI): 1, the current threat vector is "attack method: 0 / attack method (TI): 1", and the current threat level is 0.
[0169] E42: For each indicator group, divide the distance between the current threat vector and the minimum satisfying threat vector by the depth of the current threat level to obtain the proportion of the current threat vector, and multiply the proportion of the current threat vector by the pre-set difference between adjacent threat levels to obtain the proportion difference of the indicator group;
[0170] To facilitate understanding of the above distances, the following example illustrates the situation: For instance, in the second indicator group, the threat level is 0, and the maximum satisfying threat vector is "Attack Method: 0 / Attack Method (TI): 0". The distance between this vector and the threat vectors "Attack Method: 1 / Attack Method (TI): 0" or "Attack Method: 0 / Attack Method (TI): 1" is 1, and the distance between this vector and the threat vectors "Attack Method: 0 / Attack Method (TI): 2" or "Attack Method: 2 / Attack Method (TI): 0" is 2.
[0171] The depth of the current threat level is the distance between the maximum and minimum satisfied threat vectors in the current threat level. Taking threat level 0 in the second indicator group as an example, its depth is 2.
[0172] Taking the attack posture characteristics of the blocked IP in the second indicator group as follows: attack method: 0 and attack method (TI): 1, the current threat vector is "attack method: 0 / attack method (TI): 1", the current threat level is 0, and the distance between the current threat vector and the minimum satisfying threat vector is 1. Dividing the distance between the current threat vector and the minimum satisfying threat vector by the depth of the current threat level, we get the proportion of the current threat vector as 1 / 2. Multiplying the proportion of the current threat vector as 1 / 2 by the pre-set difference between adjacent threat levels of 1.1, we get the proportion difference of the second indicator group as 0.55.
[0173] Following the same principle, the proportional differences of other indicator groups can be calculated.
[0174] E43: Calculate the average of the proportion differences of each indicator group to obtain the average proportion difference;
[0175] E44: Subtract the average percentage difference from the threat score corresponding to the target threat level combination to obtain the blocked IP for threat scoring.
[0176] As can be seen, using interpolation to score the threat of blocked IPs can effectively distinguish the threat scores of blocked IPs corresponding to different threat vector combinations with the same threat level combination, making the threat scoring of blocked IPs more accurate.
[0177] Furthermore, after obtaining the threat scores of blocked IPs within a preset period, blocked IPs with threat scores greater than a threshold can be identified as target blocked IPs. The threshold can be set according to the actual application scenario. Taking a threshold of 7 as an example, blocked IPs with threat scores greater than 7 are target blocked IPs. These blocked IPs have a higher threat level and require special attention.
[0178] In addition, it can also count the number and proportion of target blocked IPs within a preset period and generate an attack situation analysis report. If the number or proportion of target blocked IPs suddenly increases within the preset period, it is necessary to pay close attention and notify relevant personnel to conduct an in-depth investigation.
[0179] One specific scenario is as follows: On a certain day, the on-duty personnel, while reviewing the attack situation analysis report, discover an abnormally sharp increase in both the number and proportion of blocked target IPs. They promptly report this and dispatch additional personnel for further analysis. They find that the vast majority of the blocked IPs are classified as high-risk and highly confident in the threat intelligence, and local alerts also detect multi-stage attack behaviors including information probing, remote command execution, and webshell uploads. Further investigation of the logs reveals attempts to exploit a suspected zero-day vulnerability. In this situation, it is necessary to promptly add monitoring rules, assign relevant personnel to strengthen monitoring, and report the suspected vulnerability to the vendor for confirmation.
[0180] Furthermore, attacker profiles of blocked IPs can be created based on alarm data and external threat intelligence. By using attackers as a mirror, attacker profiles can be accurately depicted. The attacker profile of blocked IPs includes attack methods, attack intentions, and attacker identity.
[0181] Perform the following actions when creating an attacker profile for a blocked IP:
[0182] Attack methods can be summarized into three stages: attack preparation (information gathering, routine vulnerability scanning, phishing emails, etc.), attack execution (targeted vulnerability exploitation, malicious files, denial-of-service attacks, etc.), and privilege escalation (backdoor persistence, system command execution, etc.). Vulnerabilities for targeted attacks are extracted and compared with historical attack methods from threat intelligence.
[0183] Understanding attack intent requires combining it with attack methods. Alarms involving numerous attack execution stages, or attacking IPs covering all three complete attack stages, indicate malicious intrusion. Secondly, analyze the attack target's objective. Frequency analysis of attack targets reveals target preferences. The number of applications is a threshold indicator. Attacks targeting applications by domain and then expanding to probe the same network segment, or attempting various exploits on specific applications, clearly indicate intrusion intent. If there are no targeted mass scans or crawlers, it's likely a probing intent.
[0184] To identify attackers, attackers can be broadly categorized as non-malicious applications (internet asset mapping), security personnel (scanning and testing security tools without destructive intent), botnets (with obvious automated characteristics), and malicious attackers (with a more complete attack phase or strong targeting). A brief assessment of the attacker's identity is made by analyzing their intent and methods. Extracting domain name resolutions, malicious files, and other Indices of Computation (IOCs) facilitates the identification of the attacker.
[0185] By analyzing the attacker profiles of specific blocked IPs, a refined analysis of those IPs can be achieved. Most current attacks are launched through proxies or botnets. Considering that ISP broadband and mobile base stations typically use dynamic IPs, IP users can change rapidly; only recently active IPs in threat intelligence are considered valuable. Emphasis should be placed on high-risk, high-confidence attack sources identified in threat intelligence, paying attention to discrepancies between alert data and threat intelligence attack methods, reviewing past serious attack incidents, and considering the potential influence of geographical factors. This allows for the investigation and countermeasures against suspected APT attackers.
[0186] Based on the attack situation analysis method disclosed in the above embodiments, this embodiment correspondingly discloses an attack situation analysis device. Please refer to... Figure 3 The device includes:
[0187] The data acquisition unit 301 is used to acquire alarm data of blocked IPs within a preset period and external threat intelligence of the blocked IPs;
[0188] The feature extraction unit 302 is used to extract multiple attack posture features of the blocked IP from the alarm data and the external threat intelligence;
[0189] The feature segmentation unit 303 is used to divide the multiple attack situation features into multiple indicator groups, and each indicator group corresponds to an attack feature dimension.
[0190] Threat level determination unit 304 is used to determine the threat level corresponding to each of the indicator groups based on the attack situation characteristics in each indicator group;
[0191] Threat level combination generation unit 305 is used to generate target threat level combinations based on the threat level corresponding to each of the indicator groups;
[0192] Threat scoring determination unit 306 is used to query a pre-set threat level combination scoring quick lookup table based on the target threat level combination to obtain the threat score of the blocked IP.
[0193] In some embodiments, the feature extraction unit 302 is specifically used to extract a first attack posture feature of the blocked IP from the alarm data. The first attack posture feature includes: attack result, first attack method, first attack intent, attack purpose, and first attacker identity. The unit queries the external threat intelligence based on the blocked IP. If the external threat intelligence includes the blocked IP, it extracts a second attack posture feature of the blocked IP from the external threat intelligence. If the external threat intelligence does not include the blocked IP, it sets the second attack posture feature of the blocked IP as a default value. The second attack posture feature includes: second attack method, second attack intent, second attacker identity, threat level, and confidence level. The unit encodes the first attack posture feature and the second attack posture feature of the blocked IP respectively.
[0194] In some embodiments, the threat level determination unit 304 is specifically used to determine the target constraints satisfied by the attack posture characteristics in each of the indicator groups; and to determine the threat level corresponding to each indicator group based on the target constraints satisfied by the attack posture characteristics in each of the indicator groups and the pre-set correspondence between the constraints and the threat level in each of the indicator groups.
[0195] In some embodiments, the threat scoring and determination unit 306 includes:
[0196] The query subunit is used to obtain the threat score corresponding to the target threat level combination based on the threat score corresponding to each threat level combination in the threat level combination scoring quick lookup table.
[0197] The judgment subunit is used to determine whether the attack situation features of the blocked IP in each of the indicator groups correspond to the maximum satisfied threat vector. For each indicator group, the same threat level corresponds to at least one set of attack situation features, and each set of attack situation features corresponds to a threat vector. The maximum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the largest Boolean value, and the minimum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the smallest Boolean value.
[0198] The first scoring subunit is used to determine the threat score corresponding to the target threat level combination as the threat score of the blocked IP if the attack posture characteristics of the blocked IP in each of the indicator groups correspond to the maximum satisfied threat vector.
[0199] The second scoring subunit is used to score the threat of the blocked IP by interpolation if the attack posture characteristics of the blocked IP in each of the indicator groups do not all correspond to the maximum satisfied threat vector.
[0200] In some embodiments, the second scoring subunit is specifically used to determine the current threat vector and current threat level corresponding to the attack posture characteristics of the blocked IP in each of the indicator groups; for each indicator group, the distance between the current threat vector and the minimum satisfying threat vector is divided by the depth of the current threat level to obtain the proportion of the current threat vector, and the proportion of the current threat vector is multiplied by a pre-set difference between adjacent threat levels to obtain the proportion difference of the indicator group, wherein the depth of the current threat level is the distance between the maximum satisfying threat vector and the minimum satisfying threat vector in the current threat level; the average proportion difference of each indicator group is calculated to obtain the average proportion difference; the threat score corresponding to the target threat level combination is subtracted from the average proportion difference to obtain the threat score of the blocked IP.
[0201] In some embodiments, the attack situation analysis device further includes a threat level combination scoring quick lookup table setting unit, specifically used for:
[0202] The threat score of the combination of threat levels with the highest threat intensity is set to a preset value. The combination of threat levels with the highest threat intensity is the combination of threat levels obtained by arranging the highest threat levels of each of the indicator groups in a preset order.
[0203] Set the difference between adjacent threat levels in each of the aforementioned indicator groups;
[0204] Based on the combination of threat levels with the highest threat intensity, the threat level of one of the indicator groups is changed in sequence to determine the resulting combination of threat levels, the target indicator group to be changed, and the changed threat level.
[0205] Based on the threat score of the threat level combination before the modification, the modified target indicator group, the modified threat level, and the score difference between adjacent threat levels in each indicator group, the threat score of the modified threat level combination is determined until a quick reference table of threat level combination scoring composed of the threat scores of all threat level combinations is obtained.
[0206] In some embodiments, the attack situation analysis device further includes:
[0207] The attacker profiling unit is used to establish an attacker profile of the blocked IP based on the alarm data and the external threat intelligence. The attacker profile of the blocked IP includes the attack method, attack intent and attacker identity.
[0208] In some embodiments, the attack situation analysis device further includes:
[0209] The IP blocking statistics unit is used to identify IPs with a threat score greater than a threshold as target blocking IPs; and to count the number of target blocking IPs and the proportion of target blocking IPs within a preset period.
[0210] This embodiment discloses an attack posture analysis device that takes attackers as the analysis target, periodically acquires alarm data and external threat intelligence of blocked IPs, extracts multiple attack posture features of the blocked IPs from the alarm data and external threat intelligence, and divides these features into multiple indicator groups to achieve multi-dimensional attack characteristic analysis of the blocked IPs. Based on this, the threat level corresponding to each indicator group is determined according to the attack posture features in each indicator group, and a target threat level combination is generated based on the threat level corresponding to each indicator group. A pre-set threat level combination scoring quick reference table is then consulted to obtain the threat score of the blocked IPs, achieving multi-dimensional threat level quantification and overall threat quantification of the blocked IPs. This enables rapid, comprehensive, and accurate periodic analysis of the attack posture, facilitating timely adjustment of network security protection levels based on the attack posture and improving network security.
[0211] This embodiment also discloses an electronic device; for example, please refer to [link to example]. Figure 4 The electronic device includes a memory 401, a processor 402, and a computer program stored in the memory. The processor 402 executes the computer program to implement the steps of the attack situation analysis method described in any of the above embodiments.
[0212] This embodiment also discloses a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the attack situation analysis method described in any of the above embodiments.
[0213] This embodiment also discloses a computer program product, including a computer program that, when executed by a processor, implements the steps of the attack posture analysis method described in any of the above embodiments.
[0214] It should be noted that the attack posture analysis method and related apparatus provided by this invention can be applied to the fields of network security or finance. The above are merely examples and do not limit the application areas of the attack posture analysis method and related apparatus provided by this invention.
[0215] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.
[0216] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0217] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0218] The above embodiments can be combined arbitrarily. The descriptions of the disclosed embodiments and the features recorded in the embodiments of this specification can be substituted or combined with each other, so that those skilled in the art can implement or use this application.
[0219] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An attack posture analysis method, characterized in that, include: Acquire alarm data of blocked IPs within a preset period and external threat intelligence of the blocked IPs; Multiple attack posture characteristics of the blocked IP are extracted from the alarm data and the external threat intelligence; The multiple attack situation features are divided into multiple indicator groups, and each indicator group corresponds to an attack feature dimension. Based on the attack posture characteristics in each of the indicator groups, the threat level corresponding to each indicator group is determined. Based on the threat level corresponding to each of the aforementioned indicator groups, a target threat level combination is generated; The threat score of the blocked IP is obtained by querying a pre-set threat level combination scoring quick reference table based on the target threat level combination.
2. The attack posture analysis method according to claim 1, characterized in that, The extraction of multiple attack posture characteristics of the blocked IP from the alarm data and the external threat intelligence includes: The first attack posture characteristics of the blocked IP are extracted from the alarm data. The first attack posture characteristics include: attack result, first attack method, first attack intent, attack purpose, and first attacker identity. Based on the blocked IP, query the external threat intelligence. If the external threat intelligence includes the blocked IP, extract the second attack posture characteristics of the blocked IP from the external threat intelligence. If the external threat intelligence does not include the blocked IP, set the second attack posture characteristics of the blocked IP to a default value. The second attack posture characteristics include: second attack method, second attack intent, second attack identity, threat level, and confidence level. The first attack posture characteristics and the second attack posture characteristics of the blocked IP are encoded respectively.
3. The attack posture analysis method according to claim 1, characterized in that, The step of determining the threat level corresponding to each indicator group based on the attack posture characteristics in each indicator group includes: Determine the target constraints that the attack posture characteristics satisfy in each of the indicator groups; The threat level corresponding to each indicator group is determined based on the target constraints satisfied by the attack posture characteristics in each indicator group and the pre-set correspondence between the constraints and threat levels in each indicator group.
4. The attack situation analysis method according to claim 3, characterized in that, The step of querying a pre-set threat level combination scoring quick lookup table based on the target threat level combination to obtain the threat score of the blocked IP includes: The threat score corresponding to the target threat level combination is obtained by using the threat score corresponding to each threat level combination in the threat level combination scoring quick lookup table. Determine whether the attack posture features of the blocked IP in each of the indicator groups correspond to the maximum satisfied threat vector. For each indicator group, the same threat level corresponds to at least one set of attack posture features, and each set of attack posture features corresponds to a threat vector. The maximum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the largest Boolean value, and the minimum satisfied threat vector is the threat vector that satisfies the corresponding constraint and has the smallest Boolean value. If the attack posture characteristics of the blocked IP in each of the indicator groups correspond to the maximum satisfied threat vector, the threat score corresponding to the target threat level combination is determined as the threat score of the blocked IP. If the attack posture characteristics of the blocked IP in each of the indicator groups do not all correspond to the maximum satisfied threat vector, an interpolation method is used to score the threat of the blocked IP.
5. The attack situation analysis method according to claim 4, characterized in that, The method of using interpolation to perform threat scoring on the blocked IP includes: Determine the current threat vector and current threat level corresponding to the attack posture characteristics of the blocked IP in each of the indicator groups; For each of the indicator groups, the distance between the current threat vector and the minimum satisfied threat vector is divided by the depth of the current threat level to obtain the proportion of the current threat vector. The proportion of the current threat vector is then multiplied by a pre-set difference between adjacent threat levels to obtain the proportion difference of the indicator group. The depth of the current threat level is the distance between the maximum satisfied threat vector and the minimum satisfied threat vector in the current threat level. Calculate the average of the proportion differences of each of the aforementioned indicator groups to obtain the average proportion difference; The threat score of the blocked IP is obtained by subtracting the average percentage difference from the threat score corresponding to the target threat level combination.
6. The attack posture analysis method according to claim 1, characterized in that, The method for setting up the threat level combination scoring quick reference table includes: The threat score of the combination of threat levels with the highest threat intensity is set to a preset value. The combination of threat levels with the highest threat intensity is the combination of threat levels obtained by arranging the highest threat levels of each of the indicator groups in a preset order. Set the difference between adjacent threat levels in each of the aforementioned indicator groups; Based on the combination of threat levels with the highest threat intensity, the threat level of one of the indicator groups is changed in sequence to determine the resulting combination of threat levels, the target indicator group to be changed, and the changed threat level. Based on the threat score of the threat level combination before the modification, the modified target indicator group, the modified threat level, and the score difference between adjacent threat levels in each indicator group, the threat score of the modified threat level combination is determined until a quick reference table of threat level combination scoring composed of the threat scores of all threat level combinations is obtained.
7. The attack posture analysis method according to claim 1, characterized in that, Also includes: An attacker profile of the blocked IP is established based on the alarm data and the external threat intelligence. The attacker profile of the blocked IP includes the attack method, attack intent and attacker identity.
8. The attack posture analysis method according to claim 1, characterized in that, Also includes: The blocked IPs with a threat score greater than a threshold are identified as target blocked IPs; The number of the target blocked IPs and the proportion of the target blocked IPs within a preset period are statistically analyzed.
9. An attack posture analysis device, characterized in that, include: The data acquisition unit is used to acquire alarm data of blocked IPs within a preset period and external threat intelligence of the blocked IPs; The feature extraction unit is used to extract multiple attack posture features of the blocked IP from the alarm data and the external threat intelligence; The feature segmentation unit is used to divide the multiple attack situation features into multiple indicator groups, and each indicator group corresponds to an attack feature dimension. The threat level determination unit is used to determine the threat level corresponding to each of the indicator groups based on the attack situation characteristics in each indicator group. The threat level combination generation unit is used to generate a target threat level combination based on the threat level corresponding to each of the indicator groups. The threat scoring determination unit is used to query a pre-set threat level combination scoring quick lookup table based on the target threat level combination to obtain the threat score of the blocked IP.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the attack posture analysis method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Network security situation analysis model and network security assessment method
CN109246153A
Enterprise network security assessment method and device, mobile terminal and storage medium
CN114615016A