APT organization asset extension method and device, electronic equipment and storage medium
By introducing IP nodes, assets, and fingerprint features into the asset relationship graph and utilizing a graph neural network model, the problem of low accuracy in asset mapping of APT organizations in existing technologies is solved, achieving more complete asset characterization and higher mapping accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NSFOCUS INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2024-04-22
- Publication Date
- 2026-05-01
AI Technical Summary
When performing topology analysis on APT group assets, existing technology's rule-based modeling methods struggle to fully characterize the structure of large-scale network asset information, resulting in low topology accuracy.
By utilizing the asset relationship diagram, which contains three types of information—IP nodes, assets, and fingerprint features—a graph neural network model is used to extract multi-dimensional asset information features, thereby achieving a complete characterization of APT organization assets.
It improves the accuracy of asset outlining for APT organizations and makes up for the shortcomings of existing technologies in that they cannot uncover the relationships between asset information.
Smart Images

Figure CN118377960B_ABST
Abstract
Description
Methods, devices, electronic equipment, and storage media for APT organizations to extend their assets. Technical Field
[0001] This invention relates to the field of data security technology, and in particular to a method, apparatus, electronic device, and storage medium for routing APT group assets. Background Technology
[0002] With the rapid development of information technology, Advanced Persistent Threats (APTs) have evolved into a new approach to national cyberspace countermeasures. APT attacks are typically launched by APT groups. Their aim is to conduct long-term surveillance, steal, or disrupt the target organization's confidential information or critical infrastructure. A successful APT attack can result in incalculable losses. Current responses to APT attacks largely rely on existing threat intelligence and network traffic monitoring for detection and defense. However, traditional APT response methods are reactive and focus less on the information of the initiating organizations, making it difficult to address the ever-evolving attack patterns of APT groups. Therefore, a technology is needed to proactively probe APT group assets to enhance network defense capabilities. Cyberspace asset mapping technology can assist users in probing network assets on the public internet using technical probes, making proactive tracking of APT group assets possible. Specifically, cyberspace asset mapping can be achieved through specialized search engines, such as FOFA, which uses File Identifiers (FIDs) to create a profile for each website and generate FID characteristics, forming an asset portrait. FID can be used to associate IPs, domains, and other asset information with similar characteristics to the current APT organization's assets. Then, through asset association analysis, the APT organization tags associated with similar assets can be determined, thus completing the expansion of APT organization assets.
[0003] In recent years, network asset association and topology based on network traffic has gradually attracted attention, especially with the rise of big data and artificial intelligence technologies, leading to the emergence of many new asset association methods. In existing technologies, when modeling and storing asset data, traditional rule-based modeling methods only focus on the semantic description of single asset information, making it difficult to represent the structural information in large-scale network asset information. Then, similar assets are obtained using a cyberspace asset search engine, and semantic relationships between different assets are obtained through similarity calculations to complete the topology of APT organization assets. However, this method can only obtain shallow semantic relationships between similar assets, resulting in low accuracy in topologically identifying APT organization assets. Summary of the Invention
[0004] The exemplary embodiments of this disclosure provide a method, apparatus, electronic device, and storage medium for mapping APT organization assets. By including three types of information in the asset relationship graph—IP nodes, assets, and fingerprint features—it achieves a multi-dimensional portrait of APT organization assets, resulting in a more complete depiction of APT organization assets. This allows the graph neural network model to extract more dimensional asset information features to map APT organization assets, thereby improving the accuracy of mapping APT organization assets.
[0005] The first aspect of this disclosure provides a method for mapping assets of an APT organization, the method comprising:
[0006] Obtain the fingerprint features corresponding to the selected IP node, wherein the fingerprint features include application layer fingerprint features and / or protocol layer fingerprint features;
[0007] The pre-stored asset relationship diagram is compressed using the fingerprint features corresponding to the IP node to obtain a sub-asset relationship diagram corresponding to the IP node. The asset relationship diagram is used to describe the relationship between the IP node, the fingerprint features, and the assets.
[0008] The sub-asset relationship graph corresponding to the IP node is input into a preset graph neural network algorithm to predict the APT organization of the IP node, thereby obtaining the APT organization of the IP node;
[0009] The asset relationship graph is extended by the APT organization of the IP node to obtain the extended asset information.
[0010] In this embodiment, the asset relationship graph includes three types of information: IP nodes, assets, and fingerprint features. This enables a multi-dimensional characterization of APT organization assets, resulting in a more complete characterization of APT organization assets. This allows the graph neural network model to extract more dimensional asset information features to extend the asset profile of APT organizations, thereby improving the accuracy of extending the asset profile of APT organizations.
[0011] In one embodiment, obtaining the fingerprint feature corresponding to the selected IP node includes:
[0012] Obtain at least one field value corresponding to each first specified field in the protocol layer traffic data of the IP node; based on the at least one field value corresponding to each first specified field, obtain the target field value corresponding to each first specified field, and determine the target field value corresponding to each first specified field as the protocol layer fingerprint feature; and / or,
[0013] Obtain the field values corresponding to each of the second specified fields in the application layer traffic data of the IP node, and determine the field values corresponding to each of the second specified fields as the application layer fingerprint features.
[0014] In this embodiment, APT organization assets are characterized by protocol layer fingerprint features and application layer fingerprint features, which ensures a more comprehensive characterization of APT organization assets and further improves the accuracy of APT organization asset mapping.
[0015] In one embodiment, the second specified field includes a field corresponding to at least one of the following types: version information type, certificate type, banner information type, configuration information type, user-named information type, identity field type, and HTTP service information type.
[0016] In one embodiment, obtaining the target field value corresponding to each of the first specified fields based on at least one field value corresponding to each of the first specified fields includes:
[0017] For any first specified field, a preset statistical analysis algorithm corresponding to the first specified field is used to perform noise filtering on the field values corresponding to the first specified field to obtain the target field value corresponding to the first specified field.
[0018] In this embodiment of the application, noise filtering is performed on the values of each field corresponding to each first specified field in the protocol layer traffic data to ensure that the obtained protocol layer fingerprint features are more accurate, thereby further improving the accuracy of APT organization asset outlining.
[0019] In one embodiment, the types of nodes in the asset relationship graph include IP nodes, fingerprint feature nodes, and asset nodes, and the edge between any two nodes represents an association between the two nodes.
[0020] The step of compressing the pre-stored asset relationship graph using the fingerprint features corresponding to the IP node to obtain the sub-asset relationship graph corresponding to the IP node includes:
[0021] Based on the fingerprint features corresponding to the IP node, the target fingerprint feature node corresponding to the IP node in the asset relationship diagram is obtained;
[0022] Based on the target fingerprint feature node, the sub-asset relationship graph corresponding to the IP node is obtained.
[0023] In one embodiment, obtaining the sub-asset relationship graph corresponding to the IP node based on the target fingerprint feature node includes:
[0024] The asset node connected to the target fingerprint feature node in the asset relationship diagram is identified as the first target asset node corresponding to the IP node;
[0025] Based on the first target asset node corresponding to the IP node, determine the first target IP node corresponding to the IP node in the asset relationship diagram;
[0026] Based on the IP node, other nodes corresponding to the IP node, the first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node, a sub-asset relationship diagram corresponding to the IP node is obtained, wherein the other nodes include target fingerprint feature nodes and first target asset nodes.
[0027] In this embodiment, a sub-asset relationship diagram corresponding to the IP node is obtained based on the other nodes corresponding to the IP node, the first target IP node corresponding to the IP node, and the other nodes corresponding to the first target IP node. This allows for the filtering of unimportant information in the asset relationship diagram, saving computation and improving efficiency.
[0028] In one embodiment, obtaining the target fingerprint feature node corresponding to the IP node in the asset relationship graph based on the fingerprint feature corresponding to the IP node includes:
[0029] The fingerprint feature node in the asset relationship diagram that has the same fingerprint feature as the IP node is identified as the target fingerprint feature node;
[0030] The step of determining the first target IP node corresponding to the IP node in the asset relationship diagram based on the first target asset node corresponding to the IP node includes:
[0031] Other IP nodes that have the same first target asset node as the IP node in the asset relationship diagram are identified as the first target IP node corresponding to the IP node.
[0032] In one embodiment, obtaining the sub-asset relationship diagram corresponding to the IP node based on the IP node, other nodes corresponding to the IP node, a first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node includes:
[0033] Establish a connection between the IP node and its target fingerprint feature node, and establish a connection between the IP node's target fingerprint feature node and its first target asset node; and,
[0034] For any first target IP node corresponding to the IP node, establish a connection relationship between the first target IP node and the target fingerprint feature node of the first target IP node, establish a connection relationship between the target fingerprint feature node of the first target IP node and the first target asset node of the first target IP node, and establish a connection relationship between the first target IP node and the first target asset node of the first target IP node to obtain the sub-asset relationship diagram corresponding to the IP node.
[0035] In one embodiment, the step of inputting the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to predict the APT organization of the IP node and obtain the APT organization of the IP node includes:
[0036] The sub-asset relationship graph corresponding to the IP node is input into a preset graph neural network algorithm to obtain the confidence level of the IP node belonging to each target APT organization;
[0037] The target APT organization with the highest confidence value among all target APT organizations, which is greater than a specified value, is identified as the APT organization of the IP node.
[0038] In this embodiment of the application, the target APT organization with the highest confidence value among the target APT organizations, which is greater than a specified value, is determined as the APT organization of the IP node, so as to ensure the accuracy of the determined IP node APT organization.
[0039] In one embodiment, the step of extending the asset relationship graph through the APT organization of the IP node to obtain the extended asset information includes:
[0040] Locate a second target IP node in the asset relationship graph that is the same APT organization as the IP node;
[0041] Based on the asset relationship diagram, a second target asset node corresponding to the second target IP node is determined, wherein the second target asset node is an asset node connected to the target IP node in the asset relationship diagram;
[0042] In the asset relationship diagram, the IP node is connected to the second target asset node, and the IP node is connected to the target fingerprint feature node in the asset relationship diagram to obtain the asset information after the extension.
[0043] In this embodiment, the second target IP node associated with the IP node is determined by the APT organization based on the IP node, and the assets of the APT organization are extended based on the associated IP node. This makes up for the deficiency in the prior art that it is impossible to mine the relationship between asset information and improves the accuracy of extending the assets of the APT organization.
[0044] A second aspect of this disclosure provides an asset outreach device for APT organizations, the device comprising:
[0045] The fingerprint feature determination module is used to obtain the fingerprint features corresponding to the selected IP node, wherein the fingerprint features include application layer fingerprint features and / or protocol layer fingerprint features;
[0046] The compression module is used to compress the pre-stored asset relationship diagram using the fingerprint features corresponding to the IP node to obtain the sub-asset relationship diagram corresponding to the IP node.
[0047] The APT organization prediction module is used to input the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to predict the APT organization of the IP node, thereby obtaining the APT organization of the IP node.
[0048] The asset extension module is used to extend the asset relationship graph through the APT organization of the IP node to obtain the extended asset information.
[0049] In one embodiment, the fingerprint feature determination module is specifically used for:
[0050] Obtain at least one field value corresponding to each first specified field in the protocol layer traffic data of the IP node; based on the at least one field value corresponding to each first specified field, obtain the target field value corresponding to each first specified field, and determine the target field value corresponding to each first specified field as the protocol layer fingerprint feature; and / or,
[0051] Obtain the field values corresponding to each of the second specified fields in the application layer traffic data of the IP node, and determine the field values corresponding to each of the second specified fields as the application layer fingerprint features.
[0052] In one embodiment, the second specified field includes a field corresponding to at least one of the following types: version information type, certificate type, banner information type, configuration information type, user-named information type, identity field type, and HTTP service information type.
[0053] In one embodiment, the fingerprint feature determination module performs the step of obtaining target field values corresponding to each of the first specified fields based on at least one field value corresponding to each of the first specified fields, specifically for:
[0054] For any first specified field, a preset statistical analysis algorithm corresponding to the first specified field is used to perform noise filtering on the field values corresponding to the first specified field to obtain the target field value corresponding to the first specified field.
[0055] In one embodiment, the types of nodes in the asset relationship graph include IP nodes, fingerprint feature nodes, and asset nodes, and the edge between any two nodes represents an association between the two nodes.
[0056] The compression module is specifically used for:
[0057] Based on the fingerprint features corresponding to the IP node, the target fingerprint feature node corresponding to the IP node in the asset relationship diagram is obtained;
[0058] Based on the target fingerprint feature node, the sub-asset relationship graph corresponding to the IP node is obtained.
[0059] In one embodiment, the compression module performs the step of obtaining the sub-asset relationship graph corresponding to the IP node based on the target fingerprint feature node, specifically for:
[0060] The asset node connected to the target fingerprint feature node in the asset relationship diagram is identified as the first target asset node corresponding to the IP node;
[0061] Based on the first target asset node corresponding to the IP node, determine the first target IP node corresponding to the IP node in the asset relationship diagram;
[0062] Based on the IP node, other nodes corresponding to the IP node, the first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node, a sub-asset relationship diagram corresponding to the IP node is obtained, wherein the other nodes include target fingerprint feature nodes and first target asset nodes.
[0063] In one embodiment, the compression module performs the step of obtaining the target fingerprint feature node corresponding to the IP node in the asset relationship graph based on the fingerprint feature corresponding to the IP node, specifically for:
[0064] The fingerprint feature node in the asset relationship diagram that has the same fingerprint feature as the IP node is identified as the target fingerprint feature node;
[0065] The compression module performs the step of determining the first target IP node corresponding to the IP node in the asset relationship diagram based on the first target asset node corresponding to the IP node, specifically for:
[0066] Other IP nodes that have the same first target asset node as the IP node in the asset relationship diagram are identified as the first target IP node corresponding to the IP node.
[0067] In one embodiment, the compression module performs the step of obtaining a sub-asset relationship diagram corresponding to the IP node based on the IP node, other nodes corresponding to the IP node, a first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node, specifically for:
[0068] Establish a connection between the IP node and its target fingerprint feature node, and establish a connection between the IP node's target fingerprint feature node and its first target asset node; and,
[0069] For any first target IP node corresponding to the IP node, establish a connection relationship between the first target IP node and the target fingerprint feature node of the first target IP node, establish a connection relationship between the target fingerprint feature node of the first target IP node and the first target asset node of the first target IP node, and establish a connection relationship between the first target IP node and the first target asset node of the first target IP node to obtain the sub-asset relationship diagram corresponding to the IP node.
[0070] In one embodiment, the APT organization prediction module is specifically used for:
[0071] The sub-asset relationship graph corresponding to the IP node is input into a preset graph neural network algorithm to obtain the confidence level of the IP node belonging to each target APT organization;
[0072] The target APT organization with the highest confidence value among all target APT organizations, which is greater than a specified value, is identified as the APT organization of the IP node.
[0073] In one embodiment, the asset extension module is specifically used for:
[0074] Locate a second target IP node in the asset relationship graph that is the same APT organization as the IP node;
[0075] Based on the asset relationship diagram, a second target asset node corresponding to the second target IP node is determined, wherein the second target asset node is an asset node connected to the target IP node in the asset relationship diagram;
[0076] In the asset relationship diagram, the IP node is connected to the second target asset node, and the IP node is connected to the target fingerprint feature node in the asset relationship diagram to obtain the asset information after the extension.
[0077] According to a third aspect of the present disclosure, an electronic device is provided, comprising:
[0078] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor; the instructions being executed by the at least one processor to enable the at least one processor to perform the method as described in the first aspect.
[0079] According to a fourth aspect provided in the embodiments of this disclosure, a computer storage medium is provided, the computer storage medium storing a computer program for performing the method as described in the first aspect. Attached Figure Description
[0080] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0081] Figure 1A is a schematic diagram of one applicable scenario according to an embodiment of the present disclosure;
[0082] Figure 1B is a second schematic diagram of an applicable scenario according to one embodiment of the present disclosure;
[0083] Figure 2 is a flowchart illustrating one of the methods for mapping APT organization assets according to an embodiment of the present disclosure;
[0084] Figure 3 is a schematic diagram of asset relationships according to an embodiment of the present disclosure;
[0085] Figure 4 is one of the flowcharts illustrating the relationship between sub-assets corresponding to IP nodes according to an embodiment of this disclosure;
[0086] Figure 5 is one of the flowcharts illustrating the relationship between sub-assets corresponding to IP nodes according to an embodiment of this disclosure;
[0087] Figure 6 is a second schematic flowchart of an APT organization asset extension method according to an embodiment of the present disclosure;
[0088] Figure 7 is a schematic diagram of a wiring device for APT organization assets according to an embodiment of the present disclosure;
[0089] Figure 8 is a schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure. Detailed Implementation
[0090] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0091] In this disclosure, the term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0092] The application scenarios described in this disclosure are for the purpose of more clearly illustrating the technical solutions of this disclosure and do not constitute a limitation on the technical solutions provided in this disclosure. Those skilled in the art will understand that with the emergence of new application scenarios, the technical solutions provided in this disclosure are also applicable to similar technical problems. In the description of this disclosure, unless otherwise stated, "multiple" means two or more.
[0093] In existing technologies, when modeling and storing asset data, traditional rule-based modeling methods only focus on the semantic description of single asset information, making it difficult to represent the structural information in large-scale network asset information. Then, similar assets are obtained using a cyberspace asset search engine, and semantic relationships between different assets are obtained through similarity calculations to complete the topology mapping of APT organization assets. However, this method can only obtain shallow semantic relationships between similar assets, resulting in low accuracy in mapping the topology of APT organization assets.
[0094] Therefore, this disclosure provides a method for mapping APT organization assets. By including three types of information—IP nodes, assets, and fingerprint features—in the asset relationship graph, it achieves a multi-dimensional characterization of APT organization assets, resulting in a more complete asset profile. This allows the graph neural network model to extract more dimensional asset information features for mapping APT organization assets, improving the accuracy of the mapping process. The solution of this disclosure will be described in detail below with reference to the accompanying drawings.
[0095] Figure 1A shows an application scenario of an APT organization asset extension method, which includes a server 110 and an electronic device 120.
[0096] In one possible application scenario, a user sends an APT organization asset extension instruction to a server 110 via an electronic device 120. The server 110 responds to the instruction by identifying the IP node requiring APT organization asset extension. Then, the server 110 acquires the fingerprint features corresponding to the IP node, including application-layer and / or protocol-layer fingerprint features. Using the fingerprint features and a pre-stored asset relationship graph, the server 110 obtains a sub-asset relationship graph corresponding to the IP node, which describes the association between the IP node, fingerprint features, and assets. The server 110 then inputs the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to predict the APT organization of the IP node, thus obtaining the APT organization of the IP node. Finally, the server 110 extends the asset relationship graph using the APT organization of the IP node to obtain the extended asset information.
[0097] Figure 1B illustrates another application scenario, which includes a server 110, an electronic device 120, and a storage device 130. Wherein:
[0098] The user sends an APT organization asset extension command to the server 110 via electronic device 120. In response to the user's command, the server 110 determines the IP nodes for which APT organization asset extension needs to be performed. Then, the server 110 acquires the fingerprint features corresponding to the IP nodes, including application layer fingerprint features and / or protocol layer fingerprint features. Using the fingerprint features corresponding to the IP nodes and the asset relationship graph pre-stored in memory 130, the server 110 obtains a sub-asset relationship graph corresponding to the IP nodes, which describes the association between the IP nodes, fingerprint features, and assets. The server 110 then inputs the sub-asset relationship graph corresponding to the IP nodes into a preset graph neural network algorithm to predict the APT organization of the IP nodes, thus obtaining the APT organization of the IP nodes. Finally, the server 110 performs asset extension on the asset relationship graph based on the APT organization of the IP nodes, obtaining the extended asset information.
[0099] In Figures 1A and 1B, the server 110 and the electronic device 120 can interact through a communication network. The communication network can be either wireless or wired.
[0100] For example, server 110 can access the network via cellular mobile communication technology and communicate with electronic device 120, wherein the cellular mobile communication technology includes, for example, 5th Generation Mobile Networks (5G) technology.
[0101] Optionally, server 110 can access the network and communicate with electronic device 120 via short-range wireless communication, wherein the short-range wireless communication method includes, for example, Wireless Fidelity (Wi-Fi) technology.
[0102] The description in this application focuses only on a single server 110, a single electronic device 120, and a single memory 130. However, those skilled in the art should understand that the illustrated server 110, electronic device 120, and single memory 130 are intended to illustrate the operation of the server 110, electronic device 120, and single memory 130 involved in the technical solutions of this application, and are not intended to imply any limitation on the number, type, or location of the server 110, electronic device 120, and single memory 130. It should be noted that adding additional modules to or removing individual modules from the illustrated environment will not change the underlying concept of the exemplary embodiments of this application.
[0103] It should be noted that the method for routing APT organization assets proposed in this application is not only applicable to the application scenarios shown in Figures 1A and 1B, but also applicable to any routing device with APT organization assets.
[0104] For example, electronic device 120 includes, but is not limited to: large visual screen, tablet computer, laptop computer, handheld computer, mobile internet device (MID), wearable device, virtual reality (VR) device, augmented reality (AR) device, wireless terminal device in industrial control, wireless terminal device in autonomous driving, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, or wireless terminal device in smart home, etc.; the terminal device may have a related client installed, which may be software (e.g., browser, short video software, etc.), or web page, mini program, etc.
[0105] The following describes an exemplary implementation of the APT organization asset topology method of this application, in conjunction with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the methods and principles of this application, and the implementation of this application is not limited in any way in this respect.
[0106] Figure 2 shows a flowchart of the APT organization asset extension method disclosed herein, which may include the following steps:
[0107] Step 201: Obtain the fingerprint features corresponding to the selected IP node, wherein the fingerprint features include application layer fingerprint features and / or protocol layer fingerprint features;
[0108] In this embodiment, the IP node is selected by the user.
[0109] In one embodiment, application layer fingerprint features and protocol layer fingerprint features are determined in the following manner:
[0110] Protocol layer fingerprint feature: Obtain at least one field value corresponding to each first specified field in the protocol layer traffic data of the IP node; based on the at least one field value corresponding to each first specified field, obtain the target field value corresponding to each first specified field, and determine the target field value corresponding to each first specified field as the protocol layer fingerprint feature.
[0111] In this application embodiment, each of the first designated fields can be multiple data fields under IP (Internet Protocol), TCP (Transmission Control Protocol), ICMP (Internet Control Message Protocol), and TLS (Transport Layer Security). Assets used by the same APT organization typically share similarities and fixed characteristics. Therefore, by analyzing the transmission information in the protocol fields, it is possible to infer some asset information of the communicating parties. Although this information cannot directly prove whether the current IP belongs to the same APT organization, it has high corroborating value for ATP organization asset mapping. Specifically, for the IP protocol, since different service types can provide different services to upper-layer applications, the service type is set as the first designated field. Additionally, the corresponding first designated fields for the IP protocol also include a time-to-live (TTL) field and a flag field. For the TCP protocol, the window size field may differ across operating systems, so the window size can be used as the corresponding first designated field for the TCP protocol. Furthermore, the determined first designated fields for the TCP protocol also include a maximum segment length field and a source port field, etc. For the ICMP protocol, its query or error messages can reflect the network connection status of a host to some extent. The first specified fields for the ICMP protocol include the Type field, ID field, sequence number field, and data field. For the TLS protocol, key exchange, server parameter setting, and authentication are the three phases of the handshake. Therefore, the first specified fields selected by the TLS protocol include information such as the handshake data length field, key suite length field, and TLS version field.
[0112] It should be noted that the first specified fields mentioned above are only for illustrative purposes and do not limit the first specified fields in the embodiments of this application. The first specified fields in the embodiments of this application can be set according to the actual situation.
[0113] In one embodiment, obtaining the target field value corresponding to each of the first specified fields based on at least one field value corresponding to each of the first specified fields can be specifically implemented as follows:
[0114] For any first specified field, a preset statistical analysis algorithm corresponding to the first specified field is used to perform noise filtering on the field values corresponding to the first specified field to obtain the target field value corresponding to the first specified field.
[0115] The preset statistical analysis algorithm in this embodiment can be to count the frequency of occurrence of each field value corresponding to any first specified field, and then use the feature value with the highest frequency as the target field value corresponding to any first specified field. Alternatively, it can be to count the maximum field value among all field values corresponding to any first specified field, and then determine the maximum field value as the target field value corresponding to any first specified field. The preset statistical analysis algorithm described above is only for illustrative purposes and does not limit the preset statistical analysis algorithm corresponding to each first specified field. The preset statistical analysis algorithm corresponding to each first specified field in this embodiment can be set according to the actual situation.
[0116] Furthermore, the format of each first specified field in this application embodiment is pre-set. In this application embodiment, the most representative features are extracted based on the characteristics of each first specified field value, thereby characterizing the fingerprint features of the first specified field. For example, Options represents the option values in the TCP protocol, and its length is variable. The TCP header can have up to 40 bytes of optional information, used to pass additional information to the endpoint or to align other options. In this application embodiment, the format of the first specified field is a string composed of each TCP option ordered in the order of its appearance.
[0117] It should be noted that the format of each first specified field in this application embodiment can be set according to the actual situation, and this application embodiment does not limit the format of the first specified field.
[0118] Application layer fingerprint feature: Obtain the field values corresponding to each second specified field in the application layer traffic data of the IP node, and determine the field values corresponding to each second specified field as the application layer fingerprint feature.
[0119] In this application embodiment, each of the second specified fields can be fields such as http, banner, etc., which mainly reflect the differences between the hardware characteristics and software information used by APT organizations. In this application embodiment, each of the second specified fields in the application layer traffic data is divided into 5 categories. Among them:
[0120] (1) Version information and certificate:
[0121] Since version information and certificates can identify basic information about hosts and services, the version and certificate fields can be used as corresponding secondary specified fields for different protocols or services.
[0122] (2) Banner information:
[0123] Since banner information may include information such as software developer, software name, service type, and version number, it serves as an identifier for different service servers. Therefore, banner information can be used as a secondary specified field.
[0124] (3) Configuration information and user-named information:
[0125] In application layer services, configuration information and user-named information often have certain similarities. Therefore, the configuration information of each service in the application layer and user-named fields are used as the second specified fields, such as mssql.result.instance name, redis.result.arch_bits, etc.
[0126] (4) Fields that identify the user's identity:
[0127] Application-layer services contain fields that identify their identity. For example, `ssh.result.key_exchange.server_host_key.fingerprint_sha256` can directly identify the service host fingerprint. And...
[0128] The `postgres.result.handshake_log.server_certificates.certificate.parsed..subject.org` anization identifies the organization name that issued the Postgres service certificate.
[0129] (5) HTTP (Hypertext Transfer Protocol) service information:
[0130] In HTTP services, traffic data, whether actively scanned or passively acquired, contains a wealth of information in its access status and header structure. For example, the `http.result.headers.server` field contains server information, and `http.result.headers.user_agent` contains request proxy header information.
[0131] It should be noted that the second specified fields in the embodiments of this application can be set according to the actual situation, and the embodiments of this application do not limit the second specified fields.
[0132] In this embodiment, the field values corresponding to each of the second specified fields in the application layer traffic data of the IP node are obtained through active probing. For example, a scanner such as zgrab2 can be used. In this embodiment, the type, frequency, and time of the zgrab2 probe request can be flexibly defined. Response data is obtained by actively sending constructed data packets to the IP node, and the field values corresponding to each of the second specified fields are extracted from the response data. The active probing method in this embodiment can be set according to actual conditions, and this embodiment does not limit the active probing method.
[0133] Step 202: Compress the pre-stored asset relationship diagram using the fingerprint features corresponding to the IP node to obtain the sub-asset relationship diagram corresponding to the IP node, wherein the asset relationship diagram is used to describe the relationship between the IP node, fingerprint features and assets;
[0134] Figure 3 shows a schematic diagram of the asset relationship graph. As can be seen, the node types in the asset relationship graph include IP nodes, fingerprint feature nodes, and asset nodes, and an edge between any two nodes represents a relationship between them. Each node has corresponding attribute information. The attribute information corresponding to IP nodes includes the APT organization. The attribute information corresponding to fingerprint feature nodes is the fingerprint feature. The attribute information corresponding to asset nodes includes the asset name.
[0135] In this embodiment, the edge between an IP node and a fingerprint feature node represents an "extraction" relationship, meaning the IP node can extract the fingerprint feature corresponding to that fingerprint feature node. The edge between a fingerprint feature node and an asset node represents an "inclusion" relationship, meaning the asset node reports the fingerprint feature corresponding to the fingerprint feature node it is connected to. The edge between an IP node and an asset node represents an "ownership" relationship, meaning the IP node owns the asset corresponding to that asset node. Furthermore, in this embodiment, the same IP node can own multiple assets, and the same asset node can be associated with multiple IP nodes.
[0136] The assets in this application embodiment include software assets and hardware assets. Software assets may be services, and hardware assets may be operating systems, etc. This application embodiment does not limit the assets; the assets in this application embodiment can be set according to actual conditions.
[0137] The following describes the specific method for determining the sub-asset relationship diagram corresponding to the IP node in step 202. Figure 4 shows a flowchart illustrating the process of determining the sub-asset relationship diagram corresponding to the IP node, which may include the following steps:
[0138] Step 401: Based on the fingerprint features corresponding to the IP node, obtain the target fingerprint feature node corresponding to the IP node in the asset relationship diagram;
[0139] In one embodiment, step 401 may be specifically implemented as: identifying the fingerprint feature node in the asset relationship diagram that has the same fingerprint feature as the IP node as the target fingerprint feature node.
[0140] In this embodiment, the IP node and fingerprint feature can be represented by an entity dictionary. The format of the IP entity dictionary can be: IP entity dictionary: {<"fingerprint field 1":"field value 1">, <"fingerprint field 2":"field value 2">, ...<"fingerprint field n":"field value n">}.
[0141] As can be seen from Figure 3, based on the attribute information of each fingerprint feature node in the asset relationship diagram, it can be determined whether the fingerprint feature of the fingerprint feature node is the same as the fingerprint feature of the IP node.
[0142] Step 402: Based on the target fingerprint feature node, obtain the sub-asset relationship graph corresponding to the IP node.
[0143] Figure 5 shows a flowchart illustrating the process of determining the sub-asset relationship diagram corresponding to an IP node, which may include the following steps:
[0144] Step 501: The asset node connected to the target fingerprint feature node in the asset relationship diagram is identified as the first target asset node corresponding to the IP node;
[0145] In this embodiment, the relationship between fingerprint features and assets can also be represented by an entity dictionary. The format of this entity dictionary is the same as that of the entity dictionary described above, and will not be repeated here.
[0146] For example, as shown in Figure 3, if the target fingerprint feature node is fingerprint feature node 1, then the corresponding first target asset node is asset 1.
[0147] Step 502: Based on the first target asset node corresponding to the IP node, determine the first target IP node corresponding to the IP node in the asset relationship diagram;
[0148] In one embodiment, step 502 may be specifically implemented as: identifying other IP nodes in the asset relationship diagram that have the same first target asset node as the IP node as the first target IP node corresponding to the IP node.
[0149] Step 503: Based on the IP node, other nodes corresponding to the IP node, the first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node, obtain the sub-asset relationship diagram corresponding to the IP node, wherein the other nodes include the target fingerprint feature node and the first target asset node.
[0150] In one embodiment, step 503 may be specifically implemented as follows: establishing a connection relationship between the IP node and the target fingerprint feature node of the IP node, and establishing a connection relationship between the target fingerprint feature node of the IP node and the first target asset node of the IP node; and, for any first target IP node corresponding to the IP node, establishing a connection relationship between the first target IP node and the target fingerprint feature node of the first target IP node, establishing a connection relationship between the target fingerprint feature node of the first target IP node and the first target asset node of the first target IP node, and establishing a connection relationship between the first target IP node and the first target asset node of the first target IP node, to obtain the sub-asset relationship diagram corresponding to the IP node.
[0151] In this embodiment of the application, the first target IP node corresponding to the IP node can be one or more, and this embodiment of the application does not limit the number of the first target IP nodes.
[0152] Step 203: Input the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to predict the APT organization of the IP node, and obtain the APT organization of the IP node;
[0153] The graph neural network algorithm in this application embodiment can be a graph convolutional neural network algorithm or a graph attention neural network algorithm, etc. The graph neural network algorithm in this application embodiment can be set according to actual conditions, and this application embodiment does not limit the graph neural network algorithm. Below, graph convolutional neural network algorithms and graph attention neural network algorithms are used as examples to introduce graph neural network algorithms.
[0154] (1) Graph Convolutional Neural Network Algorithm:
[0155] Graph Convolutional Neural Network (GCN) algorithms aggregate features of nearby IP nodes and weighted aggregate features of the IP node itself to achieve information aggregation of current asset information and its relationships. In this embodiment, the hidden layer of the GCN algorithm aggregates the features of each node and its connected nodes in the asset relationship graph, performs calculations, then recursively processes the data layer by layer, adding activation functions for further processing. The final model outputs the distribution corresponding to different nodes. Specifically:
[0156] For a graph convolutional neural network, all entity nodes of its input are represented as Where N is the number of nodes, and F is the dimension of each node feature, which is represented as a vectorized representation of the attribute information corresponding to the fingerprint feature node in the asset relationship graph. This vector can be obtained through pre-trained BERT models and word2vec language models. This method inputs the attribute and structural information of IP entity nodes into a multi-layer graph convolutional neural network. Each layer embeds the attribute information of the nodes learned from the previous layer and generates new attribute information based on the activation function. The new node attribute information in the hidden layer can be determined by formula (1):
[0157]
[0158] in This represents a vector containing the attribute information of the i-th IP node in the l-th layer of the neural network. This represents the second weight preset in the l-th layer of the neural network. N represents the first weight preset in the l-th layer of the neural network. i Then c is the set of the first target IP nodes corresponding to IP node i. i It is a normalization constant. Let j be a vector of attribute information of the j-th first target IP node in the l-th layer of the neural network. This represents a vector containing the attribute information of the i-th IP node in the (l+1)-th layer of the neural network. σ is a non-linear activation function, which can be the Sigmoid function, ReLU function, etc., but this embodiment does not limit σ.
[0159] After learning the asset relationship graph through a multi-layer convolutional neural network, a vector of attribute information output by each IP node in the last layer is obtained. Then, the confidence level of the IP node belonging to each APT organization is obtained based on the obtained vector using the softmax activation function. This can be obtained through formula (2):
[0160]
[0161] Among them, h i ′ Let be the confidence level that the i-th IP node belongs to each APT organization. This is a vector of attribute information output by the i-th IP node in the last layer.
[0162] In this embodiment, each APT organization is pre-set. The confidence level of the IP node belonging to each APT organization can be obtained by formula (2). The vector contains the confidence level value, and each value corresponds to an APT organization. The value of each APT organization corresponding to which position in the vector is pre-set. This embodiment will not limit this further.
[0163] Furthermore, in this embodiment, the graph convolutional neural network model is optimized by minimizing the cross-entropy loss value on all labeled IP nodes. The cross-entropy loss value of the graph convolutional neural network model can be determined by formula (3):
[0164]
[0165] in, Let G be the cross-entropy loss value of the graph convolutional neural network model, G be the total number of APT organizations in the asset relationship graph, y be the set of APT organizations corresponding to each IP node in the asset relationship graph that contains APT organizations, and h′ be the cross-entropy loss value of the graph convolutional neural network model. ig Let t be the confidence score of the i-th IP node identified in the graph convolutional neural network as belonging to the APT organization g. ig Let be the true similarity value of the i-th IP node belonging to the APT organization g.
[0166] In this embodiment, the cross-entropy loss value is determined and compared with a preset threshold. If it is greater than the preset threshold, the parameters in the graph convolutional neural network are adjusted to optimize the graph convolutional neural network.
[0167] (2) Graph Attention Neural Network Algorithm:
[0168] The graph attention neural network algorithm also requires all entity nodes in the input to be represented as... Where N is the number of nodes, F is the dimension of each node's feature, and the vector is determined in the same way as in the graph convolutional neural network algorithm. Then, it is input into the graph attention neural network algorithm to determine the importance of asset node s to IP node i. This importance can be determined by formula (4):
[0169]
[0170] Where, α is Let s represent the importance of asset s to IP node i, and W be a pre-set sharing matrix. For the pre-set weight vector, Let i be the attribute information vector corresponding to IP node i. Let be the vector corresponding to asset node s. N is the attribute information vector corresponding to the first target IP node d corresponding to IP node i. i Let i be the set of the first target IP nodes corresponding to IP node i.
[0171] After obtaining the importance of each asset to IP node i, it is necessary to perform weighted aggregation of all asset information of each IP node according to the importance of the assets. In order to stabilize the learning process of the self-attention mechanism, it is also necessary to extend it using a multi-head attention mechanism. Specifically, it is necessary to concatenate the results of K independent attention mechanisms to obtain the predicted attribute information vector of IP node i. Then, for the last layer of the attention mechanism, i.e. the prediction layer, the average value of all attention mechanism results is taken, and the confidence of IP node i belonging to each APT organization is output by using the softmax activation function for each node. The confidence of IP node i belonging to each APT organization can be obtained by formula (5):
[0172]
[0173] Among them, h i ′ Let be the confidence level that the i-th IP node belongs to each APT organization. The importance of asset s to IP node i is expressed by the attention coefficient W obtained through the k-th attention mechanism in the graph attention neural network algorithm. k Let M be the weight matrix of the input linear transformation process corresponding to the k-th attention mechanism. i K is the set of the first target asset nodes corresponding to IP node i, and K is the total number of attention mechanisms in the graph attention neural network algorithm.
[0174] The optimization of the graph attention neural network in this embodiment is the same as that of the graph convolutional neural network, and will not be described again here.
[0175] Step 204: The asset relationship diagram is extended using the APT organization of the IP node to obtain the extended asset information.
[0176] In one embodiment, step 205 may be specifically implemented as follows: finding a second target IP node in the asset relationship graph that is the same as the APT organization of the IP node; determining a second target asset node corresponding to the second target IP node based on the asset relationship graph, wherein the second target asset node is an asset node connected to the target IP node in the asset relationship graph; connecting the IP node to the second target asset node in the asset relationship graph, and connecting the IP node to the target fingerprint feature node in the asset relationship graph, to obtain the extended asset information.
[0177] To further understand the asset extension method for APT organizations in this disclosure, the asset extension method for APT organizations in this disclosure is further described as follows: Figure 6 shows a flowchart of the asset extension method for APT organizations in this disclosure, which may include the following steps:
[0178] Step 601: Obtain the fingerprint feature corresponding to the selected IP node, wherein the fingerprint feature includes application layer fingerprint feature and / or protocol layer fingerprint feature;
[0179] Step 602: Based on the fingerprint features corresponding to the IP node, obtain the target fingerprint feature node corresponding to the IP node in the asset relationship diagram;
[0180] The types of nodes in the asset relationship graph include IP nodes, fingerprint feature nodes, and asset nodes, and the edge between any two nodes represents an association between the two nodes.
[0181] Step 603: The asset node connected to the target fingerprint feature node in the asset relationship diagram is identified as the first target asset node corresponding to the IP node;
[0182] Step 604: Based on the first target asset node corresponding to the IP node, determine the first target IP node corresponding to the IP node in the asset relationship diagram;
[0183] Step 605: Based on the IP node, other nodes corresponding to the IP node, the first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node, obtain the sub-asset relationship diagram corresponding to the IP node, wherein the other nodes include the target fingerprint feature node and the first target asset node;
[0184] Step 606: Input the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to obtain the confidence level of the IP node belonging to each target APT organization;
[0185] Step 607: The target APT organization with the highest confidence value among all the target APT organizations, which is greater than a specified value, is determined as the APT organization of the IP node;
[0186] Step 608: Locate a second target IP node in the asset relationship graph that is the same APT organization as the IP node;
[0187] Step 609: Based on the asset relationship diagram, determine the second target asset node corresponding to the second target IP node, wherein the second target asset node is an asset node connected to the target IP node in the asset relationship diagram;
[0188] Step 610: In the asset relationship diagram, connect the IP node to the second target asset node, and connect the IP node to the target fingerprint feature node in the asset relationship diagram to obtain the asset information after the extension.
[0189] Based on the same disclosed concept, the method for mapping APT organization assets as described above can also be implemented by a mapping device for APT organization assets. The effect of this mapping device is similar to that of the aforementioned method, and will not be repeated here.
[0190] Figure 7 is a schematic diagram of a wiring device for APT organization assets according to an embodiment of the present disclosure.
[0191] As shown in Figure 7, the APT organization asset mapping device 700 disclosed herein may include a fingerprint feature determination module 710, a compression module 720, an APT organization prediction module 730, and an asset mapping module 740.
[0192] The fingerprint feature determination module 710 is used to obtain fingerprint features corresponding to the IP node, wherein the fingerprint features include application layer fingerprint features and / or protocol layer fingerprint features;
[0193] Compression module 720 is used to obtain a sub-asset relationship diagram corresponding to the IP node by using the fingerprint features corresponding to the IP node and a pre-stored asset relationship diagram, wherein the asset relationship diagram is used to describe the relationship between the IP node, fingerprint features and assets;
[0194] The APT organization prediction module 730 is used to input the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to predict the APT organization of the IP node, thereby obtaining the APT organization of the IP node.
[0195] The asset extension module 740 is used to extend the asset relationship diagram through the APT organization of the IP node to obtain the extended asset information.
[0196] In one embodiment, the fingerprint feature determination module 710 is specifically used for:
[0197] Obtain at least one field value corresponding to each first specified field in the protocol layer traffic data of the IP node; based on the at least one field value corresponding to each first specified field, obtain the target field value corresponding to each first specified field, and determine the target field value corresponding to each first specified field as the protocol layer fingerprint feature; and / or,
[0198] Obtain the field values corresponding to each of the second specified fields in the application layer traffic data of the IP node, and determine the field values corresponding to each of the second specified fields as the application layer fingerprint features.
[0199] In one embodiment, the second specified field includes a field corresponding to at least one of the following types: version information type, certificate type, banner information type, configuration information type, user-named information type, identity field type, and HTTP service information type.
[0200] In one embodiment, the fingerprint feature determination module 710 performs the step of obtaining target field values corresponding to each of the first specified fields based on at least one field value corresponding to each of the first specified fields, specifically for:
[0201] For any first specified field, a preset statistical analysis algorithm corresponding to the first specified field is used to perform noise filtering on the field values corresponding to the first specified field to obtain the target field value corresponding to the first specified field.
[0202] In one embodiment, the types of nodes in the asset relationship graph include IP nodes, fingerprint feature nodes, and asset nodes, and the edge between any two nodes represents an association between the two nodes.
[0203] The compression module 720 is specifically used for:
[0204] Based on the fingerprint features corresponding to the IP node, the target fingerprint feature node corresponding to the IP node in the asset relationship diagram is obtained;
[0205] Based on the target fingerprint feature node, the sub-asset relationship graph corresponding to the IP node is obtained.
[0206] In one embodiment, the compression module 720 performs the step of obtaining the sub-asset relationship graph corresponding to the IP node based on the target fingerprint feature node, specifically for:
[0207] The asset node connected to the target fingerprint feature node in the asset relationship diagram is identified as the first target asset node corresponding to the IP node;
[0208] Based on the first target asset node corresponding to the IP node, determine the first target IP node corresponding to the IP node in the asset relationship diagram;
[0209] Based on the IP node, other nodes corresponding to the IP node, the first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node, a sub-asset relationship diagram corresponding to the IP node is obtained, wherein the other nodes include target fingerprint feature nodes and first target asset nodes.
[0210] In one embodiment, the compression module 720 performs the step of obtaining the target fingerprint feature node corresponding to the IP node in the asset relationship graph based on the fingerprint feature corresponding to the IP node, specifically for:
[0211] The fingerprint feature node in the asset relationship diagram that has the same fingerprint feature as the IP node is identified as the target fingerprint feature node;
[0212] The compression module 720 executes the step of determining the first target IP node corresponding to the IP node in the asset relationship diagram based on the first target asset node corresponding to the IP node, specifically for:
[0213] Other IP nodes that have the same first target asset node as the IP node in the asset relationship diagram are identified as the first target IP node corresponding to the IP node.
[0214] In one embodiment, the compression module 720 performs the step of obtaining a sub-asset relationship diagram corresponding to the IP node based on the IP node, other nodes corresponding to the IP node, a first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node, specifically for:
[0215] Establish a connection between the IP node and its target fingerprint feature node, and establish a connection between the IP node's target fingerprint feature node and its first target asset node; and,
[0216] By establishing a connection between the first target IP node and the target fingerprint feature node of the first target IP node, and by establishing a connection between the target fingerprint feature node of the first target IP node and the first target asset node of the first target IP node, and by establishing a connection between the first target IP node and the first target asset node of the first target IP node, the sub-asset relationship diagram corresponding to the IP node is obtained.
[0217] In one embodiment, the APT organization prediction module 730 is specifically used for:
[0218] The sub-asset relationship graph corresponding to the IP node is input into a preset graph neural network algorithm to obtain the confidence level of the IP node belonging to each target APT organization;
[0219] The target APT organization with the highest confidence value among all target APT organizations, which is greater than a specified value, is identified as the APT organization of the IP node.
[0220] In one embodiment, the asset extension module 740 is specifically used for:
[0221] Locate a second target IP node in the asset relationship graph that is the same APT organization as the IP node;
[0222] Based on the asset relationship diagram, a second target asset node corresponding to the second target IP node is determined, wherein the second target asset node is an asset node connected to the target IP node in the asset relationship diagram;
[0223] In the asset relationship diagram, the IP node is connected to the second target asset node, and the IP node is connected to the target fingerprint feature node in the asset relationship diagram to obtain the asset information after the extension.
[0224] Having introduced a method and apparatus for routing APT organization assets according to an exemplary embodiment of the present disclosure, an electronic device according to another exemplary embodiment of the present disclosure will now be described.
[0225] Those skilled in the art will understand that various aspects of this disclosure can be implemented as a system, method, or program product. Therefore, various aspects of this disclosure can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, collectively referred to herein as a "circuit," "module," or "system."
[0226] In some possible implementations, the electronic device according to this disclosure may include at least one processor and at least one computer storage medium. The computer storage medium stores program code that, when executed by the processor, causes the processor to perform the steps in the outlining method for APT organization assets according to various exemplary embodiments of this disclosure described above. For example, the processor may perform steps 201-204 as shown in FIG2.
[0227] The electronic device 800 according to this embodiment of the present disclosure will now be described with reference to FIG8. The electronic device 800 shown in FIG8 is merely an example and should not be construed as limiting the functionality and scope of the embodiments of the present disclosure.
[0228] As shown in Figure 8, the electronic device 800 is presented in the form of a general-purpose electronic device. The components of the electronic device 800 may include, but are not limited to: at least one processor 801, at least one computer storage medium 802, and a bus 803 connecting different system components (including the computer storage medium 802 and the processor 801).
[0229] Bus 803 represents one or more of several bus architectures, including computer storage media bus or computer storage media controller, peripheral bus, processor, or local bus using any of the various bus architectures.
[0230] Computer storage medium 802 may include readable media in the form of volatile computer storage media, such as random access computer storage medium (RAM) 821 and / or cache storage medium 822, and may further include read-only computer storage medium (ROM) 823.
[0231] The computer storage medium 802 may also include a program / utility 825 having a set (at least one) of program modules 824, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.
[0232] Electronic device 800 can also communicate with one or more external devices 804 (e.g., keyboard, pointing device, etc.), and with one or more devices that enable a user to interact with electronic device 800, and / or with any device that enables electronic device 800 to communicate with one or more other electronic devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 805. Furthermore, electronic device 800 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 806. As shown, network adapter 806 communicates with other modules used in electronic device 800 via bus 803. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 800, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0233] In some possible implementations, various aspects of the method for mapping APT organization assets provided in this disclosure can also be implemented in the form of a program product, which includes program code that, when the program product is run on a computer device, causes the computer device to perform the steps in the method for mapping APT organization assets according to various exemplary embodiments of this disclosure described above.
[0234] The program product may take the form of any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access computer storage media (RAM), read-only computer storage media (ROM), erasable programmable read-only computer storage media (EPROM or flash memory), optical fibers, portable compact disk read-only computer storage media (CD-ROM), optical computer storage media, magnetic computer storage media, or any suitable combination thereof.
[0235] The program product for outlining APT organization assets according to embodiments of this disclosure can be a portable compact disc read-only computer storage medium (CD-ROM) and include program code, and can run on an electronic device. However, the program product of this disclosure is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0236] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0237] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0238] Program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's electronic device, partially on the user's device, as a standalone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving remote electronic devices, the remote electronic device can be connected to the user's electronic device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external electronic device (e.g., via the Internet using an Internet service provider).
[0239] It should be noted that although several modules of the apparatus have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.
[0240] Furthermore, although the operations of the methods disclosed herein are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0241] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, systems, or computer program products. Therefore, this disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this disclosure can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk computer storage media, CD-ROMs, optical computer storage media, etc.) containing computer-usable program code.
[0242] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.
[0243] These computer program instructions may also be stored in a computer-readable computer storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable computer storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0244] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0245] Obviously, those skilled in the art can make various modifications and variations to this disclosure without departing from its spirit and scope. Therefore, if such modifications and variations fall within the scope of the claims of this disclosure and their equivalents, this disclosure is also intended to include such modifications and variations.
Claims
1. A method for expanding the assets of an APT organization, characterized in that, The method includes: acquiring fingerprint features corresponding to a selected IP node, wherein the fingerprint features include application layer fingerprint features and / or protocol layer fingerprint features; identifying fingerprint feature nodes in the asset relationship diagram that have the same fingerprint features as the IP node as target fingerprint feature nodes; identifying asset nodes in the asset relationship diagram that are connected to the target fingerprint feature nodes as first target asset nodes corresponding to the IP node; identifying other IP nodes in the asset relationship diagram that have the same first target asset node as the IP node as first target IP nodes corresponding to the IP node; and determining the first target IP node based on the IP node and its corresponding other asset nodes. Other nodes, the first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node are used to obtain a sub-asset relationship graph corresponding to the IP node. The asset relationship graph is used to describe the relationship between the IP node, fingerprint features, and assets. The other nodes include target fingerprint feature nodes and first target asset nodes. The sub-asset relationship graph corresponding to the IP node is input into a preset graph neural network algorithm to predict the APT organization of the IP node, thereby obtaining the APT organization of the IP node. The asset relationship graph is then extended with asset lines based on the APT organization of the IP node to obtain the extended asset information.
2. The method according to claim 1, characterized in that, The step of obtaining the fingerprint feature corresponding to the selected IP node includes: obtaining at least one field value corresponding to each first specified field in the protocol layer traffic data of the IP node; obtaining target field values corresponding to each first specified field based on the at least one field value corresponding to each first specified field, and determining the target field values corresponding to each first specified field as the protocol layer fingerprint feature; and / or, obtaining field values corresponding to each second specified field in the application layer traffic data of the IP node, and determining the field values corresponding to each second specified field as the application layer fingerprint feature.
3. The method according to claim 2, characterized in that, The second specified field includes a field corresponding to at least one of the following types: version information type, certificate type, banner information type, configuration information type, user-named information type, identity field type, and HTTP service information type.
4. The method according to claim 2, characterized in that, The step of obtaining the target field value corresponding to each of the first specified fields based on at least one field value corresponding to each of the first specified fields includes: for any one of the first specified fields, using a preset statistical analysis algorithm corresponding to the first specified field to perform noise filtering on each field value corresponding to the first specified field to obtain the target field value corresponding to the first specified field.
5. The method according to claim 1, characterized in that, The types of nodes in the asset relationship graph include IP nodes, fingerprint feature nodes, and asset nodes, and the edge between any two nodes represents that the two nodes have an association relationship.
6. The method according to claim 1, characterized in that, The step of obtaining the sub-asset relationship diagram corresponding to the IP node based on the IP node, other nodes corresponding to the IP node, a first target IP node corresponding to the IP node, and other nodes corresponding to the first target IP node includes: establishing a connection relationship between the IP node and the target fingerprint feature node of the IP node, and establishing a connection relationship between the target fingerprint feature node of the IP node and the first target asset node of the IP node; and, for any first target IP node corresponding to the IP node, establishing a connection relationship between the first target IP node and the target fingerprint feature node of the first target IP node, establishing a connection relationship between the target fingerprint feature node of the first target IP node and the first target asset node of the first target IP node, and establishing a connection relationship between the first target IP node and the first target asset node of the first target IP node, thereby obtaining the sub-asset relationship diagram corresponding to the IP node.
7. The method according to claim 1, characterized in that, The step of inputting the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to predict the APT organization of the IP node and obtain the APT organization of the IP node includes: inputting the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to obtain the confidence level of the IP node belonging to each target APT organization; and determining the target APT organization with the largest confidence level among the target APT organizations, which is greater than a specified value, as the APT organization of the IP node.
8. The method according to claim 1, characterized in that, The step of extending the asset relationship graph through the APT organization of the IP node to obtain the extended asset information includes: finding a second target IP node in the asset relationship graph that has the same APT organization as the IP node; determining a second target asset node corresponding to the second target IP node based on the asset relationship graph, wherein the second target asset node is an asset node connected to the target IP node in the asset relationship graph; connecting the IP node to the second target asset node in the asset relationship graph, and connecting the IP node to a target fingerprint feature node in the asset relationship graph to obtain the extended asset information.
9. An asset extension device for an APT organization, characterized in that, The device includes: a fingerprint feature determination module, configured to acquire fingerprint features corresponding to a selected IP node, wherein the fingerprint features include application layer fingerprint features and / or protocol layer fingerprint features; and a compression module, configured to: identify fingerprint feature nodes in the asset relationship diagram that have the same fingerprint features as the IP node as target fingerprint feature nodes; identify asset nodes in the asset relationship diagram that are connected to the target fingerprint feature nodes as first target asset nodes corresponding to the IP node; identify other IP nodes in the asset relationship diagram that have the same first target asset node as the IP node as first target IP nodes corresponding to the IP node; and, based on the IP node and other nodes corresponding to the IP node... The system uses a graph neural network algorithm to predict the APT organization of the IP node by inputting the sub-asset relationship graph corresponding to the IP node, the fingerprint feature, and the assets. The algorithm includes a target fingerprint feature node and a first target asset node. An APT organization prediction module is used to input the sub-asset relationship graph corresponding to the IP node into a preset graph neural network algorithm to predict the APT organization of the IP node. An asset extension module is used to extend the asset relationship graph using the APT organization of the IP node to obtain the extended asset information.
10. An electronic device, characterized in that, The method includes at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that are executed by the at least one processor; the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1-8.
11. A computer storage medium, characterized in that, The computer storage medium stores a computer program for performing the method according to any one of claims 1-8.
Citation Information
Patent Citations
Network security information processing method and device, electronic equipment and storage medium
CN111787001A
Network attack organization tracking method and device based on space-time correlation
CN116112287A