An attack detection and tracing method, device, electronic device and storage medium
By building a network event diagram and using preset attack feature recognition models, the problems of inaccurate monitoring of attack events and difficulty in traceability in the existing technology are solved, and automatic determination and accurate traceability of attack events are realized.
Patent Information
- Application Number
- CN202410707745.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-03
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2044-06-03
AI Technical Summary
In the prior art, the monitoring results of attack incidents are inaccurate and cannot be correctly traced, making it difficult to capture and block complex cyber attacks.
By obtaining the entity and interaction event information in the target network environment, a network event graph is constructed, the attack event is determined based on the preset attack feature identification model, and the traceability information is found through the dependency degree.
It realizes automatic determination of attack events and the accuracy of traceability information, and improves attack detection and defense capabilities in network environments.
Smart Images

Figure CN118555110B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to an attack detection and traceability method, device, electronic device, and storage medium. Background Art
[0002] In recent years, along with the continuous evolution of multi-step complex attacks, the attack means have become increasingly complex and diverse, often using a variety of advanced technologies such as unknown vulnerabilities, supply chain penetration, and social engineering, with extremely high concealment, pertinence, and persistence. This type of attack poses a serious threat to computer networks, and traditional detection methods are difficult to accurately capture and timely block related threats.
[0003] In the prior art, graph neural network methods can be used to detect attack events. It realizes attack detection by performing deep representation learning on the graph structure of network events and combining anomaly detection algorithms. However, the opaque characteristics of the graph neural network model conflict with the traceability and interpretability of attack detection in the production environment. The graph neural network is trained by a large amount of data and has millions of neurons. The high complexity of the internal structure makes it difficult for people to understand the decision-making of the neural network, resulting in the detection results being difficult to trust and unable to trace attack events. Therefore, how to trace attack events in the network has become an urgent problem to be solved currently. Summary of the Invention
[0004] The present invention provides an attack detection and traceability method, device, electronic device, and storage medium to solve the problem that the monitoring results of attack events in the prior art are inaccurate and cannot be correctly traced.
[0005] According to one aspect of the present invention, an attack detection and traceability method is provided, wherein the method includes:
[0006] Obtain entities in the target network environment and interaction event information between the entities, and construct a network event graph with the entities and the interaction event information;
[0007] Based on a preset attack feature recognition model, determine the graph embedding vector of each interaction event information in the network event graph as feature information, and determine the attack events in the network event graph according to the feature information;
[0008] Determine the dependence degree between the attack events and the remaining interaction event information in the network event graph, and find the corresponding interaction event information as the traceability information of the attack events according to the dependence degree.
[0009] According to another aspect of the present invention, an attack detection and traceability device is provided, wherein the device includes:
[0010] An event graph construction module, configured to obtain entities in a target network environment and interaction event information between the entities, and construct a network event graph with the entities and the interaction event information;
[0011] An attack event determination module, configured to determine graph embedding vectors of the interaction event information in the network event graph as feature information based on a preset attack feature recognition model, and determine attack events in the network event graph according to the feature information;
[0012] An information tracing module, configured to determine the dependence degree of the attack event on the remaining interaction event information in the network event graph, and find corresponding interaction event information as the tracing information of the attack event according to the dependence degree.
[0013] According to another aspect of the present invention, there is provided an electronic device, including:
[0014] At least one processor; and
[0015] A memory communicatively connected to the at least one processor; wherein,
[0016] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the attack detection and tracing method according to any embodiment of the present invention.
[0017] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the attack detection and tracing method according to any embodiment of the present invention when executed.
[0018] The technical solution of the embodiment of the present invention realizes the automatic determination of attack events and improves the recognition ability of attack events by obtaining entities in a target network environment and interaction event information between the entities, constructing a network event graph with the entities and the interaction event information, then determining graph embedding vectors of the interaction event information in the network event graph as feature information based on a preset attack feature recognition model, and determining attack events in the network event graph according to the feature information; by determining the dependence degree of the attack event on the remaining interaction event information in the network event graph and finding corresponding interaction event information as the tracing information of the attack event according to the dependence degree, the accuracy of the tracing information is improved. At the same time, it is convenient to timely discover potential attack behaviors in the target network environment, perform defense and response in advance, and ensure the security of the target network environment.
[0019] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. Description of the Drawings
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0021] Figure 1 is a flowchart of an attack detection and tracing method provided in Embodiment 1 of the present invention;
[0022] Figure 2 is a flowchart of a method for training a preset attack feature recognition model provided in Embodiment 2 of the present invention;
[0023] Figure 3 is a flowchart of another attack detection and tracing method provided in Embodiment 3 of the present invention;
[0024] Figure 4 is a block diagram of the training structure of an attack detection and tracing system provided in Embodiment 4 of the present invention;
[0025] Figure 5 is a schematic diagram of a method for determining an attack sample provided in Embodiment 4 of the present invention;
[0026] Figure 6 is an example diagram of attack tracing provided in Embodiment 4 of the present invention;
[0027] Figure 7 is a schematic diagram of the structure of an attack detection and tracing device provided in Embodiment 5 of the present invention;
[0028] Figure 8 is a schematic diagram of the structure of an electronic device for implementing the attack detection and tracing method of the embodiments of the present invention. Detailed Embodiments
[0029] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0031] Embodiment 1
[0032] Figure 1 is a flowchart of an attack detection and tracing method provided according to Embodiment 1 of the present invention. This embodiment is applicable to the situation of detecting and tracing attack events in a network environment. This method can be executed by an attack detection and tracing device, which can be implemented in the form of hardware and / or software, and the attack detection and tracing device can be configured in an electronic device. As Figure 1 shown, the method includes:
[0033] S110. Obtain entities in the target network environment and interaction event information between the entities, and construct a network event graph with the entities and the interaction event information.
[0034] Among them, the target network environment can be understood as a network environment that needs to be monitored for network security. Exemplarily, the target network environment may include, but is not limited to, an intranet environment, an extranet environment, and a local area network environment, etc. Entities can include all devices and users participating in network activities. For example, computer devices, servers, network devices, and data centers, etc.; the interaction event information between entities can be understood as the data interaction behavior information between any two entities. Exemplarily, the interaction event information may include the event occurrence direction and the event type. For example, events such as data transmission, access request and response, service call, fault and repair, and traffic control. The network event graph is a graphical representation used to intuitively display and analyze the events occurring between various entities in the target network environment and the relationships between the entities.
[0035] In an embodiment, log information in the target network environment can be extracted, and entities in the log information and interaction event information between the entities can be extracted; alternatively, information such as network traffic and connection status in the target network environment can be monitored in real time, and entities in the target network environment and interaction event information between the entities can be captured. Then, the entities are used as nodes, and the interaction event information is used as the edges connecting the corresponding two entities to generate a network event graph.
[0036] S120. Determine the graph embedding vectors of each interaction event information in the network event graph as feature information based on a preset attack feature recognition model, and determine attack events in the network event graph according to the feature information.
[0037] Among them, the preset attack feature recognition model can be understood as a model pre-trained for attack events in the device network event graph. In one embodiment, the preset attack feature recognition model can be generated based on an encoder-decoder architecture. In the actual operation process, the network event graph can be input into the preset attack feature recognition model to automatically determine attack events in the network event graph. An attack event can be understood as a specific behavior or activity initiated by a malicious actor in the target network environment aimed at causing adverse effects such as damage, destruction, theft, or interference to the network system, device, data, or user. Exemplarily, attack events can include, but are not limited to, events such as data tampering, Distributed Denial of Service (DDoS), and virus attacks. Feature information can refer to the attributes and functions indicating the difference of the network event graph from other network event graphs. Exemplarily, feature information can include graph embedding vectors of interaction event information, embedding vectors of entities, etc.
[0038] In an embodiment, the network event graph can be input into the preset attack feature recognition model, and the network event graph is graph-embedded through the preset attack feature recognition model to obtain the graph embedding vectors of each interaction event information as feature information. When judging the probability that the feature information belongs to abnormal information, if the probability exceeds the preset threshold, it is considered that the interaction event information is an attack event. In the actual operation process, the node matrix composed of entities in the network event graph and the graph adjacency matrix composed of interaction event information can be used. The encoder embeds according to the node matrix and the graph adjacency matrix to generate node embedding vectors of each node, and then aggregates the node embedding vectors associated with the interaction event information to obtain the graph embedding vector of the interaction event information, and uses the graph embedding vector as feature information. Alternatively, each row in the graph adjacency matrix can be directly regarded as a graph embedding vector as feature information. In one embodiment, when it is determined that there is an attack event in the network environment, an attack alarm can be generated to prompt the user to handle the attack event in a timely manner.
[0039] S130. Determine the degree of dependence of the attack event on the remaining interaction event information in the network event graph, and find the corresponding interaction event information according to the degree of dependence as the traceability information of the attack event.
[0040] Among them, the degree of dependence can be understood as the degree of association between the attack event and the remaining interaction event information in the network event graph, and the degree of dependence can be the association probability. Traceability information refers to the information for finding the source of the attack, and the traceability information may include one or more pieces of interaction event information.
[0041] In the embodiment, the degree of dependence of the attack event on the remaining interaction event information in the network event graph can be determined by polling. Exemplarily, the remaining interaction event information can be sequentially determined for the degree of dependence with the attack event, and the interaction event information can be combined to determine the degree of dependence with the attack event after combination. At least one piece of interaction event information corresponding to the maximum value of the degree of dependence is used as the traceability information of the attack event. In one embodiment, the degree of dependence between the attack event and the remaining interaction event information can be determined through a preset traceability model; or, the degree of dependence between the attack event and the remaining interaction event information can be determined by manual confirmation. In one embodiment, the interaction event information can be generated into a Markov blanket to facilitate the display of the traceability information.
[0042] In the embodiment of the present invention, by obtaining the entities in the target network environment and the interaction event information between the entities, constructing a network event graph with the entities and the interaction event information, then determining the graph embedding vector of each interaction event information in the network event graph as the feature information based on a preset attack feature recognition model, and determining the attack event in the network event graph according to the feature information, the automatic determination of the attack event is realized, and the recognition ability of the attack event is improved; by determining the degree of dependence of the attack event on the remaining interaction event information in the network event graph, and finding the corresponding interaction event information according to the degree of dependence as the traceability information of the attack event, it is convenient to find the interaction event information associated with the attack event, realize the traceability of the attack event, improve the accuracy of the traceability information, and at the same time, it is convenient to timely discover potential attack behaviors in the target network environment, and perform defense and response in advance to ensure the security of the target network environment.
[0043] Embodiment Two
[0044] Figure 2 It is a flowchart of a method for training a preset attack feature recognition model according to Embodiment Two of the present invention. This embodiment is a method for training a preset attack feature recognition model based on the above embodiment, as Figure 2 shown, the training of the preset attack feature recognition model includes:
[0045] S210. Obtain open-source cyber threat intelligence, extract the first entities and the interaction event information between the first entities in the open-source cyber threat intelligence by using natural language processing technology, use each first entity as a first node, and use the interaction event information between the first entities as edges to construct an attack graph.
[0046] Among them, open-source cyber threat intelligence refers to the information related to cyber threats collected, analyzed, and sorted out from publicly available resources. Exemplarily, open-source cyber threat intelligence can be obtained from social media platforms, research institution reports, and news websites. The first entity can be understood as the cyber entities included in the open-source cyber threat intelligence, such as devices, servers, and users, etc.; the interaction event information between the first entities refers to the information interaction events between the first entities.
[0047] In an embodiment, open-source cyber threat intelligence can be extracted from a public platform, and the first entities and the interaction event information between the first entities included in the open-source cyber threat intelligence are extracted. Each first entity is used as a first node, and the interaction event information between the first entities is used as edges to construct an attack graph.
[0048] S220. Extract the traffic logs of the network environment, extract the interaction event information included in the traffic logs, use the second entities corresponding to each interaction event information as second nodes, and use the interaction event information between the second entities as edges to construct an event graph.
[0049] Among them, the traffic logs can be understood as the event records generated when entities such as network devices, systems, and service programs in the network environment are operating. The second entity can be understood as the cyber entities included in the traffic logs, such as devices, servers, and users, etc.
[0050] In an embodiment, the storage area in the network environment can be accessed to obtain the traffic logs in the network environment, the interaction event information included in the traffic logs is extracted, the second entity corresponding to each interaction event information is determined, the second entity is used as a second node, and the interaction event information between the second entities is used as edges to construct an event graph.
[0051] S230. Match each first node with each second node to obtain matching nodes, determine the target attack paths between the matching nodes, and generate an initial attack graph according to the target attack paths.
[0052] Among them, the matching node can be understood as the second node that matches the first node in the event graph, or the first node that matches the second node in the attack graph. In the actual operation process, the second node with the same or similar attribute information as the first node can be used as the matching node. Exemplarily, the first node and the second node with the same name can be used as the matching node; or, when the names are different, the first node and the second node with the same type can be used as the matching node; or, the first node and the second node with the same feature information can be used as the matching node.
[0053] In an embodiment, each first node can be sequentially and circularly matched with the second nodes in the event graph, the matched nodes are used as the matching nodes, the matching nodes in the event graph are connected as the target attack path, and the target attack paths are sequentially connected to generate the initial attack graph.
[0054] In one embodiment, the matching nodes are obtained by matching each first node with each second node, and the target attack path between the matching nodes is determined. Generating the initial attack graph according to the target attack path includes:
[0055] Determine the attribute information of the first node, and match the associated points in the second nodes of the event graph according to the attribute information as the matching nodes; among them, the attribute information at least includes the first node name, type, and feature information;
[0056] Use any matching node as the starting node, traverse the event graph to find the remaining matching nodes, and determine the attack path between each matching node;
[0057] Determine the number of nodes in each attack path, and use the attack paths with the number of nodes less than or equal to the preset number as the target attack paths between the matching nodes;
[0058] Connect each matching node and the target attack path to generate the initial attack graph.
[0059] Among them, the attribute information of the first node can be understood as the information indicating the attributes of the first node, and the attribute information can at least include the first node name, type, and feature information. The influence score can be understood as the possibility for the attacker to control the attack path, that is, the possibility that the attack path can be generated during the attack process.
[0060] In an embodiment, the attribute information of the first node can be determined, such as the first node name, type, and characteristic information, and the second node of the event graph is matched according to the attribute information, and the matched associated points are used as the matching nodes. In the actual operation process, the attribute information of each second node can be determined, and the similarity degree between the attribute information of the first node and the attribute information of the second node can be determined. When the similarity degree is greater than or equal to the preset similarity threshold, it is determined that the first node is associated with the second node; alternatively, the first node and the second node with the same name can be used as the matching nodes; alternatively, when the names are different, the first node and the second node with the same type can be used as the matching nodes; alternatively, the first node and the second node with the same characteristic information can be used as the matching nodes. Any of the matching nodes is used as the starting node, and the remaining matching nodes are searched through traversing the event graph to determine the attack paths between each matching node. In one embodiment, the depth-first strategy can be used to search for the attack paths between each matching node, and the attack paths between each matching node can include at least one. Then, the number of nodes in each attack path is determined, and the attack paths with the number of nodes less than or equal to the preset number are used as the target attack paths between the matching nodes. Alternatively, the attack path with the least number of nodes among the attack paths between every two matching nodes can be used as the target attack path. The matching nodes and the target attack paths are connected to generate an initial attack graph.
[0061] S240. Determine the similarity score between the attack graph and the initial attack graph, determine the target attack graph in the initial attack graph according to the similarity score, and perform data augmentation on the target attack graph as an attack sample.
[0062] Among them, the similarity score is used to indicate the similarity degree between the attack graph and the initial attack graph. The higher the similarity score, the higher the similarity degree between the attack graph and the initial attack graph can be considered.
[0063] In the actual operation process, the similarity score between the attack graph and the initial attack graph can be calculated, and the initial attack graph with the similarity score greater than or equal to the preset similarity score is used as the target attack graph. The target attack graph is subjected to data augmentation as an attack sample to increase the number of attack samples. In one embodiment, node perturbation, edge perturbation, attribute masking, random subgraph sampling and other methods can be used to perform data augmentation on the target attack graph.
[0064] In one embodiment, determining the similarity score between the attack graph and the initial attack graph, determining the target attack graph in the initial attack graph according to the similarity score, and performing data augmentation on the target attack graph as an attack sample includes:
[0065] Determine the connection paths of each matching node in the attack graph, determine the number of nodes in each connection path, determine the reciprocal of the number of nodes in the connection paths corresponding to two matching nodes, and use the maximum value of the reciprocals as the influence score of the two matching nodes;
[0066] Determine the total sum of the number of all connection paths, and add up the influence scores to obtain the sum of influence scores;
[0067] Use the product of the sum of influence scores and the total sum as the similarity score;
[0068] When the similarity score is greater than or equal to the preset similarity score, determine the initial attack graph as the target attack graph, and perform data augmentation on the target attack graph as an attack sample.
[0069] In the embodiment, each matching node can be connected in the attack graph to determine the connection paths between the matching nodes. For every two matching nodes, the number of connection paths can be one or more. The number of nodes in each connection path can be determined, the reciprocal of the number of nodes in the connection paths corresponding to two matching nodes can be determined, and the maximum value of the reciprocals is used as the influence score of the two matching nodes. Determine the total sum of the number of connection paths, add up the influence scores corresponding to each edge to obtain the sum of influence scores, and multiply the sum of influence scores by the total sum. Use the product as the similarity score. When it is determined that the similarity score is greater than or equal to the preset similarity score, determine the initial attack graph as the target attack graph. Data augmentation can be performed on the target attack graph as an attack sample. Among them, data augmentation includes at least one of the following: node perturbation, edge perturbation, attribute masking, and random subgraph sampling. Exemplarily, some nodes and associated edges can be discarded in the random target attack graph, or additional associated nodes and associated edges can be randomly selected in the random target attack graph and added to the target attack graph; or, some edge elements in the target attack graph can be randomly discarded, or the associated edges corresponding to events can be randomly selected and added to the target attack graph; or, some or all of the attribute information of some nodes in the target attack graph can be randomly masked; or, by combining the associated nodes and associated edges in the target attack graph, random subgraph sampling can be achieved through random walks to automatically generate attack samples that are closer to real network attack behaviors through data augmentation.
[0070] S250. Obtain entities in the network environment at at least one moment and the interaction event information between the entities, and construct a positive sample event graph according to the entities and the interaction event information.
[0071] In the embodiment, the traffic logs of the network environment at at least one moment can be obtained, the entities and the interaction event information between the entities in the traffic logs can be extracted, the entities are used as nodes, and the interaction event information is used as edges to construct a positive sample event graph.
[0072] S260. Extract real network attack samples from the configuration file, and input the positive sample event graph, real network attack samples, and attack samples into a preset attack feature recognition model to train the preset attack feature recognition model.
[0073] Among them, real network attack samples can be understood as attack samples that actually exist in the network environment and can be pre-stored.
[0074] In an embodiment, the positive sample event graph, real network attack samples, and attack samples can be input into a preset attack feature recognition model to train the preset attack feature recognition model.
[0075] In one embodiment, inputting the positive sample event graph, real network attack samples, and attack samples into a preset attack feature recognition model to train the preset attack feature recognition model includes S261 - S267.
[0076] S261. Use the positive sample event graph and attack samples as pre-training samples, input the pre-training samples into the preset attack feature recognition model, and respectively extract the local features of the pre-training samples through the preset attack feature recognition model, and aggregate the local features as global features.
[0077] Among them, the preset attack feature recognition model is composed based on an encoder-decoder architecture.
[0078] In an embodiment, the positive sample event graph and attack samples can be used as pre-training samples to pre-train the preset attack feature recognition model. The local features of the pre-training samples can include the edge embedding vectors in the pre-training samples, and the local features can be aggregated as global features. In a specific implementation, the positive sample event graph can be represented as (X, A), where X is the node feature matrix of the positive sample event graph and A is the adjacency matrix of the positive sample event graph. Represent the attack sample as where is the node feature matrix of the attack sample, is the adjacency matrix of the attack sample. The encoder uses message passing, aggregation, storage update, and embedding generation to obtain the local features H = ε(X, A) = (h 1 , h 2 ,..., h n ) of the positive sample event graph, where ε represents the encoder, and h 1 -h n represents the embedding representation of the nodes in the positive sample event graph; the local features of the attack sample where ε represents the encoder, represents the embedding representation of the nodes in the attack sample. Then use a readout function to aggregate all the obtained local features as global features. The readout function averages the local features of all nodes in the positive sample event graph to Take R(H) as the global feature of the positive sample event graph, denoted by s; average the local features of all nodes in the attack sample to Take as the global feature of the attack sample, denoted by .
[0079] S262. Determine the loss value of the preset attack feature recognition model based on the preset pre-training network loss function;
[0080] Among them, the pre-training network loss function includes at least binary cross-entropy.
[0081] In the embodiment, the loss value of the preset attack feature recognition model can be determined by the preset pre-training network loss function. Exemplarily, the pre-training network loss function can include where F represents the discriminator function, which is used to score the local feature and the global feature. Exemplarily, when the pre-training sample is a positive sample event graph, the value of F(h i , s) is relatively large, and when the pre-training sample is an attack sample, the value of F(h i , s) is relatively small; conversely, when the pre-training sample is a positive sample event graph, the value of is relatively small, and when the pre-training sample is an attack sample, the value of is relatively large. N and M respectively represent the number of nodes in the positive sample event graph and the attack sample. E (X,A) represents the mathematical expectation of the positive sample event graph; represents the mathematical expectation of the attack sample.
[0082] S263. Iterate the preset attack feature recognition model through the loss value until the iteration times are reached. During the iteration process, adjust the parameters of the preset attack feature recognition model to obtain the pre-trained preset attack feature recognition model.
[0083] In the actual operation process, the preset attack feature recognition model can be iterated according to the loss value until the iteration times are reached, and during the iteration process, parameters such as the learning rate and step size of the preset attack feature recognition model are adjusted, and the pre-trained preset attack feature recognition model.
[0084] S264. Take the entities in the real network attack sample as nodes, take the event information between the entities as edges, generate a real network attack sample graph, label the attack events in the real network attack sample graph with attack labels, and input the real network attack sample graph and the attack labels into the pre-trained preset attack feature recognition model.
[0085] In an embodiment, entities in a real network attack sample and event information between the entities can be determined. The entities in the real network attack sample are used as nodes, and the event information between the entities is used as edges to generate a real network attack sample graph. The attack events in the real network attack sample graph are labeled with attack labels to indicate the attack events in the real network attack sample. The real network attack sample graph and the attack labels are input into a pre-trained preset attack feature recognition model for training.
[0086] S265. Determine the probability that each edge belongs to an attack event through the fully connected layer of the initial model. When the determined probability is greater than or equal to a preset threshold, determine that the event information corresponding to the edge is an attack event.
[0087] In an embodiment, the embedding mapping of each edge in the real network attack sample graph can be determined, and the embedding of the edge is mapped to the probability that it belongs to an attack event through the fully connected layer. When the determined probability is greater than or equal to a preset threshold, determine that the event information corresponding to the edge is an attack event.
[0088] S266. When it is determined that the attack event has an attack label, determine that the judgment mark of the attack event is 1. When it is determined that the attack event does not have an attack label, determine that the judgment mark of the attack event is 0.
[0089] S267. When it is determined that the judgment mark is 1, determine the product of the natural logarithm of each probability and the corresponding judgment mark as the first parameter. When it is determined that the judgment mark is 0, determine the natural logarithm of the probability that does not belong to the attack event as the second parameter. Take the sum of the first parameter and the second parameter corresponding to the real network attack sample graph as the loss function value of the pre-trained preset attack feature recognition model, and optimize the parameters of the preset attack feature recognition model according to the loss function value.
[0090] In an embodiment, when it is determined that the judgment mark is 1, it can be considered that the model judges the real situation, and determine the product of the natural logarithm of the probability and the corresponding judgment mark as the first parameter; when it is determined that the judgment mark is 0, it can be considered that the model does not judge the real situation, and determine the natural logarithm of the probability that does not belong to the attack event as the second parameter. Take the sum of the first parameter and the second parameter corresponding to the real network attack sample as the loss function value of the pre-trained preset attack feature recognition model, and optimize the parameters of the preset attack feature recognition model according to the loss function value. That is to say, each edge in the real network attack sample graph is judged, and the sum of the first parameter or the second parameter determined for each edge is used as the loss function value of the pre-trained preset attack feature recognition model. In one embodiment, the determination method of the loss function value is Loss = ∑ x [y x log(p x )+(1 - yx ) log(1 - p x )], where y x represents the judgment flag on whether edge x is an attack event, and p x represents the predicted probability that x belongs to an attack event.
[0091] In the embodiment of the present invention, the preset attack feature recognition model is pre-trained through positive sample events graph and attack samples, and then re-trained according to real network attack samples on the pre-trained preset attack feature recognition model, so as to improve the accuracy of the preset attack feature recognition model, so as to more accurately judge attack events according to the preset attack feature recognition model and enhance the accuracy of attack detection.
[0092] Embodiment III
[0093] Figure 3 is a flowchart of another attack detection and tracing method provided according to Embodiment III of the present invention. This embodiment is further optimized and extended based on the above implementation manner and can be combined with each optional technical solution in the above implementation manner. As Figure 3 shown, the method includes:
[0094] S310. Obtain entities in the target network environment and interaction event information between entities, and construct a network event graph with the entities and the interaction event information.
[0095] S320. Extract a node matrix composed of entities in the network event graph and a graph adjacency matrix composed of interaction event information based on the preset attack feature recognition model.
[0096] Among them, the node matrix is a matrix used to represent nodes in the graph; the graph adjacency matrix is a matrix used to represent the connection relationship between nodes in the graph.
[0097] In the embodiment, the node matrix and the graph adjacency matrix can be constructed in advance according to the network event graph, and the node matrix composed of entities in the network event graph and the graph adjacency matrix composed of interaction event information can be extracted through the preset attack feature recognition model.
[0098] S330. Determine the node embedding vectors of each node according to the node matrix and the graph adjacency matrix.
[0099] Among them, the node embedding vector can be understood as a vector that maps each node in the graph to a low-dimensional vector space. The purpose of node embedding is to convert the nodes in the network event graph into vectors.
[0100] In the embodiment, after determining the node matrix and the graph adjacency matrix, the node embedding vectors of each node can be determined based on the preset attack feature recognition model. Exemplarily, a graph embedding algorithm can be used to determine the node embedding vectors of each node.
[0101] S340. Concatenate the node embedding vectors associated with the interaction event information to obtain the graph embedding vector of the interaction event information, and use the graph embedding vector as the feature information.
[0102] In an embodiment, the nodes associated with each interaction event information can be determined, the node embedding vectors of the nodes can be determined, the node embedding vectors associated with the interaction event information can be concatenated as the graph embedding vector of the interaction event information, and the graph embedding vector can be used as the feature information.
[0103] S350. Confirm the probability that each piece of feature information belongs to an attack event, and use the interaction event information corresponding to the feature information with a probability greater than or equal to the preset probability threshold as the attack event.
[0104] In an embodiment, each piece of feature information can be mapped to the probability of an attack event through the fully connected layer of the preset attack feature recognition model. When it is determined that the probability is greater than or equal to the preset probability threshold, the interaction event information corresponding to the feature information is determined as the attack event.
[0105] S360. Input the attack event and the network event graph into a preset traceability model; wherein, the preset traceability model is constructed based on a Bayesian network.
[0106] S370. Poll through the preset traceability model to determine the correlation probability between the attack event and at least one remaining interaction event information in the network event graph as the degree of dependence, and use the at least one remaining interaction event information with the highest degree of dependence as the traceability information of the attack event.
[0107] In an embodiment, the degree of dependence between the attack event and the remaining interaction event information in the network event graph can be determined by polling through the preset traceability model. For example, the remaining interaction event information can be sequentially determined for the degree of dependence with the attack event, and the interaction event information can be combined to determine the degree of dependence with the attack event after combination, and the at least one interaction event information corresponding to the maximum value of the degree of dependence is used as the traceability information of the attack event. In an embodiment, the quantitative dependence relationship between the attack event and other interaction event information can be expressed in the form of conditional probability to achieve attack traceability.
[0108] In an embodiment of the present invention, by obtaining entities in a target network environment and interaction event information between the entities, a network event graph is constructed with the entities and the interaction event information. Based on a preset attack feature recognition model, a node matrix composed of entities in the network event graph and a graph adjacency matrix composed of the interaction event information are extracted. According to the node matrix and the graph adjacency matrix, the node embedding vectors of each node are determined. The node embedding vectors associated with the interaction event information are concatenated to obtain the graph embedding vector of the interaction event information. The graph embedding vector is used as feature information to confirm the probability that each feature information belongs to an attack event. The interaction event information corresponding to the feature information with a probability greater than or equal to a preset probability threshold is used as an attack event, achieving accurate confirmation of the attack event. By inputting the attack event and the network event graph into a preset tracing model, the relevant probability of the attack event and at least one remaining interaction event information in the network event graph is determined by polling the preset tracing model as the dependence degree, and at least one remaining interaction event information with the highest dependence degree is used as the tracing information of the attack event, realizing the determination of the tracing information and improving the accuracy and convenience of determining the tracing information.
[0109] In one embodiment, the training of the preset tracing model includes:
[0110] Extract the attack events output by the preset attack feature recognition model and the network event graph input to the preset attack feature recognition model, and perform data augmentation on the attack events and the network event graph as samples to obtain training samples;
[0111] Determine the Markov blanket of the attack event in the training samples according to the growth and contraction algorithm, and use the data in the Markov blanket as sample data;
[0112] Determine the sample quantity of the sample data and the log-likelihood value of the sample data and the model parameters, determine the product of the natural logarithm of the sample quantity and the dimension of the model parameters, and use the difference between the product and the log-likelihood value as the Bayesian information criterion score of the sample data and the model parameters in the preset attack feature recognition model;
[0113] Adjust the model parameters based on the Bayesian information criterion score until the Bayesian information criterion score reaches the target score, and complete the training of the preset tracing model.
[0114] Among them, the Markov blanket is an algorithm used to determine the dependence relationship between training samples. In the actual operation process, methods such as the Grow-Shrink (GS) algorithm can be used to determine it. The log-likelihood value can be used to measure the likelihood of sample data appearing under the model parameters, and can be used to compare the fitting degree of different model parameter settings to the sample data. By adjusting the parameters to maximize the log-likelihood value, the optimal preset traceability model fitting can be obtained. The Bayesian Information Criterion (BIC) score is a standard used to measure the goodness of fit of the preset traceability model. When the Bayesian Information Criterion score reaches the target score, it can be considered that the training of the preset traceability model is completed.
[0115] In the embodiment, the attack events output by the preset attack feature recognition model and the network event graph input to the preset attack feature recognition model can be extracted, that is, the input and output of the preset attack feature recognition model are obtained. The input and output of the feature recognition model are used as samples for data augmentation to obtain training samples. In the actual operation process, the methods of data augmentation can include but are not limited to node perturbation, edge perturbation, attribute masking, and random subgraph sampling. The Markov blanket of the attack events in the training samples is determined according to the Grow-Shrink algorithm, and the data in the Markov blanket is used as sample data. That is, important variables can be screened out and unimportant variables can be filtered. The sample number of the sample data and the log-likelihood value of the sample data and the model parameters are determined, and then the product of the natural logarithm of the sample number and the dimension of the model parameters is determined. The difference between the product and the log-likelihood value is used as the Bayesian Information Criterion score of the sample data and the model parameters in the preset attack feature recognition model. The model parameters can be adjusted according to the Bayesian Information Criterion score until the Bayesian Information Criterion score reaches the target score, and the training of the preset traceability model is completed.
[0116] Embodiment 4
[0117] Figure 4 It is a training structure block diagram of an attack detection and traceability system provided according to Embodiment 4 of the present invention. In this embodiment, taking the preset attack feature recognition model and the preset traceability model as an example to form an attack detection and traceability system, the training of the attack detection and traceability system is further described. As Figure 4 shown, the attack detection and traceability system includes a preset attack feature recognition model and a preset traceability model. Among them, the preset attack feature recognition model is composed of an encoder and a decoder; the preset traceability model is composed of a Bayesian network interpretation model. The training of the attack detection and traceability system includes:
[0118] Various entities in the network environment and various interactive behaviors between entities at various moments in continuous time are obtained to construct a dynamic heterogeneous event graph; the dynamic heterogeneous event graph is used as a positive sample event graph.
[0119] By widely collecting open source network threat intelligence related to known network attacks, and using natural language processing technology to extract the entities involved in known network attacks and the interactive relationships between entities, a corresponding attack graph is formed, which is an abstract representation of the attack path and context information of the known attack behavior, denoted as G a Using the “subject-action-object@time” event graph generation method, the traffic log and other information of the target network are modeled as an event graph, which is denoted as G e , and further based on the depth-first graph traversal algorithm in the event graph G e Search the attack graph G in a , and get the initial attack graph.
[0120] In one embodiment, the attack graph G may be a Each node v in k , according to the name, type, and attribute information of the node, in the event graph G e Find all matching nodes (v k,i )(i=1,…,n a ), recorded as the matching point (v k , v k,i ),n a G a The number of nodes in the attack graph G a Each node v in k , in turn, the node in the event graph G e For each matching node v in k,i As the search starting node, in the event graph G e Traverse until the attack graph G is found a The next node v in k 'In the event graph G e The matching node v in k,i '. At this point, the search is performed based on the depth-first strategy, that is, starting from the current matching node, repeating the above steps until the next matching node is not found and backtracking is performed.
[0121] For node v i With v j The path between them, its impact score represents the possibility that the attacker can control the entire attack path and is defined as follows:
[0122]
[0123] Among them, Nmin (e i →e j ) represents the minimum number of nodes that the attacker needs to control for all nodes on this path of e, and its value is equal to e i →e j ; the minimum number of common ancestor nodes of all nodes involved in the attack path; N i →e j is a preset threshold. When N thr min (e i →e j ) > N thr then it is considered that this attack path cannot exist. When the influence score between the current node and the search start node is 0, stop the search. To improve the search efficiency, pruning is performed by scoring the influence of each path.
[0124] For the attack graph Ga, the set of initial attack graphs matched in the event graph Ge is {G a,e}. The target attack graph is screened by calculating the similarity score between the attack graph Ga and the initial attack graph {G a,e}. The similarity score is calculated as follows:
[0125]
[0126] where v i , v j are nodes in Ga, v k , v l are nodes in Ga, e, v i →v j is the attack path from node v i to node v j in Ga, M(Ga, e) represents the set of corresponding paths of all paths in Ga in the similar subgraph Ga, e, and |M(Ga, e)| represents the number of such corresponding paths. When the node v k matches v i , and v l matches v j , under this condition, this formula first calculates the paths in the graph Ga,e that satisfy from node v k to v l The sum of the influence scores between all node pairs (k, l) of at least one path. Then, it is normalized by dividing this sum by the maximum possible value |M(Ga,e)|, where |M(Ga,e)| is the number of paths in Ga,e. Since the maximum value of the influence score I between two nodes is equal to 1, the number of paths automatically represents the maximum value of the sum of the influence scores. When Sim(Ga, Ga,e) = 0, there is no similarity relationship between Ga and Ga,e (i.e., there are neither matching nodes nor paths between the corresponding matching nodes); when Sim(Ga, Ga,e) = 1, Ga and Ga,e are isomorphic. Therefore, when the similarity score Sim(Ga, Ga,e) exceeds a pre-set threshold S thr the initial attack graph is added to the set of target attack graphs.
[0127] Based on the searched target attack graph, and based on the event graph, combined with the graph data perturbation method, various variants of the attack subgraph with prior knowledge are embedded into the normal network entity behavior to obtain attack samples, that is, the construction of strong negative examples. In one embodiment, the node perturbation method can be adopted to randomly discard some nodes and associated edges in the target attack graph, or randomly select additional associated nodes and associated edges in the event graph Ga and add them to Ga,e; the edge perturbation method can also be adopted to randomly discard some edge elements in the target attack graph Ga,e, or randomly select associated edges in the event Ga and add them to Ga,e; or the attribute masking method can be adopted to randomly mask some or all of the attribute information of some nodes in the target attack graph Ga,e; or the random subgraph method can be used to combine the associated nodes and associated edges in the event graph Ga, and random subgraph sampling is achieved through random walk to obtain attack samples, that is, negative sample event graphs.
[0128] In one embodiment, Figure 5 is a schematic diagram of a method for determining an attack sample according to Embodiment 4 of the present invention. As Figure 5 shown, after determining the attack graph according to the threat intelligence and determining the event graph according to the system and traffic logs, matching nodes can be determined in the event graph through the nodes in the attack graph to obtain the initial attack graph, and data augmentation is performed on the initial attack graph to obtain attack samples.
[0129] Taking file copying in the dataset as an example, the normal behavior sequence is "log in to the computer -> insert the USB flash drive -> copy out the file -> remove the USB flash drive -> log out of the computer", and the generated negative sample behavior sequences can include "log in to the computer -> insert the USB flash drive -> execute malicious code -> copy out the file -> establish a CC channel -> remove the USB flash drive -> log out of the computer".
[0130] The preset attack feature recognition model is a continuous-time dynamic heterogeneous graph network based on the encoder-decoder paradigm. Using the contrastive learning method, the encoder of the preset attack feature recognition model is pre-trained by inputting the positive sample event graph and the negative sample event graph generated above.
[0131] The positive sample event graph is represented as (X, A), where X is the node feature matrix of the positive sample event graph and A is the adjacency matrix of the positive sample event graph. The corresponding negative sample event graph generated based on (X, A) is represented as where is the node feature matrix of the negative sample event graph, is the adjacency matrix of the negative sample event graph. The preset attack feature recognition model uses message passing, aggregation, storage update, and embedding generation to obtain the local feature H = ε(X, A) = (h 1 , h 2 ,..., h n ), where ε represents the encoder, and h 1 -h n represents the embedding representation of the nodes in the positive sample event graph; the local feature of the negative sample event graph where ε represents the encoder, represents the embedding representation of the nodes in the negative sample event graph. Then, a readout function is used to aggregate all the obtained local features as the global feature. The readout function averages the local features of all the nodes in the positive sample event graph to the global feature s of the positive sample event graph = R(H); the local features of all the nodes in the negative sample event graph are averaged to Taking as the global feature of the attack sample, which is represented by . The pre-training of the preset attack feature recognition model is completed using the standard binary cross entropy loss function.
[0132] Among them, the loss function can be:
[0133] where F represents the discriminator function, which is used to score the local features and the global features. Exemplarily, when the pre-training sample is the positive sample event graph, the value of F(h i , s) is relatively large, and when the pre-training sample is the attack sample, the value of F(h i , s) is relatively small; conversely, when the pre-training sample is the positive sample event graph, the value of is relatively small, and when the pre-training sample is the attack sample, the value of is relatively large. N and M respectively represent the number of nodes in the positive sample event graph and the attack sample. E (X,A)represents the mathematical expectation of the positive sample event graph; represents the mathematical expectation of the attack sample.
[0134] Based on rare real complex network attack samples, generate strong negative sample event graphs, and further fine-tune and train the above pre-trained preset attack feature recognition model to make it more sensitive to complex network attack behaviors, and obtain the trained preset attack feature recognition model.
[0135] In the fine-tuning stage, inherit the parameters of the encoder in the pre-training stage, and continue to train the detection model using real attack samples. The embedding of each edge in the real attack sample is obtained by splicing the embeddings of the nodes on both sides. Then, map the embedding of the edge to the probability space of its belonging to the attack event through a fully connected layer. The following cross-entropy loss function is used in the fine-tuning stage to complete the training of the preset attack feature recognition model.
[0136] Loss = ∑ x [y x log(p x ) + (1 - y x )log(1 - p x )];
[0137] where y x represents the true situation of whether the edge x is an attack event, and p x represents the predicted probability that x belongs to the attack event.
[0138] Based on the output results of the above preset attack feature recognition model, the original graph, and the attack samples, further train a preset tracing model, which expresses the dependence degree between the attack event and other process events in the form of conditional probability.
[0139] Obtain the attack events output by the preset attack feature recognition model and the network event graph input to the preset attack feature recognition model, and use the attack events and the network event graph as samples. Perturb the network event graph and record the predictions of anomalies on these graphs, which is called the perturbed data (that is, generate → preprocess → record a set of [input, output] pair data for the predictions to be explained).
[0140] Specifically, for the attack event et (the attack event variable corresponding to it in the probabilistic graph network is represented by boldface et), generate a set of perturbed sampling data D et (the perturbed data variable corresponding to it in the probabilistic graph network is represented by boldface D et ), that is, a set of [input, output] pairs, for the correlation degree between each variable and the detection result in the preset tracing model.
[0141] It is difficult to find an optimal preset traceability model in the data after full-scale perturbation because the L-hop neighbor set Neighb(et, Ge) of the target event et on the event graph Ge may contain thousands of nodes, and the computational cost of searching for an optimal preset traceability model is very large. Therefore, to reduce the number of variables in the filtered data, it is possible to determine which variables are unimportant and eliminate them. It is possible to adopt generating the Markov blanket corresponding to the attack event et to represent all the events important for the attack event et. That is, the Markov blanket contains all the statistical information of the attack event et. Therefore, selecting important data and filtering out unimportant data from the perturbed sampled data D et is equivalent to reducing all the L-hop neighbor events Neighb(et, Ge) of the attack event et to the Markov blanket M(et) of the attack event et, thereby reducing the computational space for the explanatory model to learn the optimal preset traceability model. Among them, the Markov blanket M(et) is obtained by calculating with the existing algorithm Grow-Shrink (GS). The data in the Markov blanket is used as sample data.
[0142] Taking the sample data as input, learning the preset traceability model B for the target event et, and the objective function is the Bayesian information criterion (BIC) score OBJ et (B). On the premise that the samples satisfy the independent and identically distributed assumption, the log-likelihood is used to measure the fitting degree of the network structure β and the observed data D et [M(et)]:
[0143] OBJ et (B) = BICscore(β, D et [M(et)]) = Dim[B]·logn - L(θ′ B , D et [M(et)]);
[0144] Among them, D et [M(et)] is the data corresponding to the variable M(et), n is the sample number of D et [M(et)], Dim[B] is the dimension of the model parameters to be estimated by the Bayesian network B. The function L(θ′ B , D et [M(et)]) is the log-likelihood estimate (log-likelihood) between D et [M(et)] and θ′ B . θ β is the parameter of the Bayesian network, and θ′ β is the value of θ β when maximizing the log-likelihood, that is, the maximum likelihood estimator.
[0145] Based on the BIC objective function, the exhaustive method can be used to solve the preset traceability model, and the dependency of the target event on other events can be reflected through the network.
[0146] In one embodiment, Figure 6 is an example diagram of attack tracing provided according to the fourth embodiment of the present invention. Take an example in which an employee logs into another employee's machine and searches for a copy of a private file and sends it to a private mailbox via email. When the event t7 is detected as an abnormal event, the attention scores of the neighboring nodes are analyzed, among which the node E has the highest attention score. The query data set finds that node E sends private files via email. By analogy, the attention scores of the neighboring nodes of node E are further explored and the recursive tracing is always forward. It can be found that the source of this attack behavior is that the employee logs into another employee's computer E at time t4, sends a job application email to F at time t5, accesses private files at time t6, and sends private files via email at time t7, finally forming a complete abnormal behavior. In contrast, an explanatory model based on a spatiotemporal probability graph is used to obtain a causal chain that is closer to real cognition. The behavior chain formed by t1, t4, t5, and t6 has a gain effect on the abnormal judgment probability of the t7 event, which is consistent with the result of the attention score method. Exemplarily, the output of the preset tracing model can be a conditional probability table: p(e t7 |e t6 )=0.754; p(e t7 |e t5 e t6 )=0.775;p(e t7 |e t4 e t5 e t6 )=0.790;p(e t7 |e t1 e t4 e t5 e t6 )=0.809. As can be seen from the conditional probability table, the preset traceability model can display the Markov blanket of the target event and filter out unimportant events, which is more intuitive than the attention score method that requires step-by-step recursion.
[0147] Embodiment 5
[0148] Figure 7 FIG. 1 is a schematic diagram of the structure of an attack detection and source tracing device provided according to Embodiment 5 of the present invention. Figure 7 As shown, the device includes: an event graph construction module 71, an attack event determination module 72 and an information tracing module 73.
[0149] Among them, the event graph construction module 71 is used to obtain entities in the target network environment and interaction event information between the entities, and construct a network event graph with the entities and the interaction event information;
[0150] The attack event determination module 72 is used to determine the graph embedding vector of each interaction event information in the network event graph as feature information based on a preset attack feature recognition model, and determine the attack events in the network event graph according to the feature information;
[0151] The information traceability module 73 is used to determine the dependence degree of the attack event on the remaining interaction event information in the network event graph, and find the corresponding interaction event information as the traceability information of the attack event according to the dependence degree.
[0152] In an embodiment of the present invention, the event graph construction module obtains entities in the target network environment and interaction event information between the entities, and constructs a network event graph with the entities and the interaction event information. The attack event determination module determines the graph embedding vector of each interaction event information in the network event graph as feature information based on a preset attack feature recognition model, and determines the attack events in the network event graph according to the feature information, realizing the automatic determination of attack events and improving the recognition ability of attack events; the information traceability module determines the dependence degree of the attack event on the remaining interaction event information in the network event graph, and finds the corresponding interaction event information as the traceability information of the attack event according to the dependence degree, facilitating the search for interaction event information associated with the attack event, realizing the traceability of the attack event, improving the accuracy of the traceability information, and at the same time, facilitating the timely discovery of potential attack behaviors in the target network environment, and taking defensive measures and responses in advance to ensure the security of the target network environment.
[0153] In an embodiment, the attack event determination module 72 includes:
[0154] The matrix determination unit is used to extract the node matrix composed of entities in the network event graph and the graph adjacency matrix composed of interaction event information based on a preset attack feature recognition model;
[0155] The vector determination unit is used to determine the node embedding vector of each node according to the node matrix and the graph adjacency matrix;
[0156] The feature information determination unit is used to splice the node embedding vectors associated with the interaction event information to obtain the graph embedding vector of the interaction event information, and use the graph embedding vector as the feature information;
[0157] The attack event determination unit is used to confirm the probability that each feature information belongs to an attack event, and use the interaction event information corresponding to the feature information with a probability greater than or equal to a preset probability threshold as an attack event.
[0158] In an embodiment, the attack detection and traceability device further includes:
[0159] An attack graph determination module, configured to obtain open-source network threat intelligence, extract first entities and interaction event information between the first entities in the open-source network threat intelligence by using natural language processing technology, use each first entity as a first node, and use the interaction event information between the first entities as edges to construct an attack graph;
[0160] An event graph determination module, configured to extract traffic logs of a network environment, extract interaction event information included in the traffic logs, use second entities corresponding to each interaction event information as second nodes, and use the interaction event information between the second entities as edges to construct an event graph;
[0161] An initial graph generation module, configured to obtain matching nodes according to the matching of each first node and each second node, determine target attack paths between the matching nodes, and generate an initial attack graph according to the target attack paths;
[0162] A sample determination module, configured to determine a similarity score between the attack graph and the initial attack graph, determine a target attack graph in the initial attack graph according to the similarity score, and perform data augmentation on the target attack graph as an attack sample;
[0163] A positive sample determination module, configured to obtain entities in a network environment at at least one moment and interaction event information between the entities, and construct a positive sample event graph according to the entities and the interaction event information;
[0164] A model training module, configured to extract real network attack samples from a configuration file, and input the positive sample event graph, the real network attack samples, and the attack samples into a preset attack feature recognition model to train the preset attack feature recognition model.
[0165] In one embodiment, the initial graph generation module is specifically configured to:
[0166] Determine the attribute information of the first node, and match associated points in the second nodes of the event graph according to the attribute information as matching nodes; wherein, the attribute information includes at least the first node name, type, and feature information;
[0167] Use any one of the matching nodes as a starting node, traverse the event graph to find the remaining matching nodes, and determine the attack paths between the matching nodes;
[0168] Determine the number of nodes in each attack path, and use the attack paths with the number of nodes less than or equal to a preset number as the target attack paths between the matching nodes;
[0169] Connect each matching node and the target attack paths to generate an initial attack graph.
[0170] In one embodiment, the sample determination module is specifically configured to:
[0171] Determine the connection paths of each matching node in the attack graph, determine the number of nodes in each connection path, determine the reciprocal of the number of nodes in the connection paths corresponding to two matching nodes, and use the maximum value of the reciprocals as the influence score of the two matching nodes;
[0172] Determine the total sum of the number of all connection paths, and add up the influence scores to obtain the sum of influence scores;
[0173] Use the product of the sum of influence scores and the total sum as the similarity score;
[0174] When the similarity score is greater than or equal to the preset similarity score, determine the initial attack graph as the target attack graph, and perform data augmentation on the target attack graph as an attack sample; wherein, the data augmentation includes at least one of the following: node perturbation, edge perturbation, attribute masking, and random subgraph sampling.
[0175] In one embodiment, the model training module is specifically configured to:
[0176] Use the positive sample event graph and the attack sample as pre-training samples, input the pre-training samples into a preset attack feature recognition model, extract the local features of the pre-training samples through the preset attack feature recognition model respectively, and aggregate the local features as global features; wherein, the preset attack feature recognition model is composed of an encoder-decoder architecture;
[0177] Determine the loss value of the preset attack feature recognition model based on a preset pre-training network loss function; wherein, the pre-training network loss function includes at least binary cross-entropy;
[0178] Iterate the preset attack feature recognition model through the loss value until the number of iterations is reached, and adjust the parameters of the preset attack feature recognition model during the iteration to obtain the pre-trained preset attack feature recognition model;
[0179] Use the entities in the real network attack sample as nodes, use the event information between the entities as edges, generate a real network attack sample graph, label the attack events in the real network attack sample graph with attack labels, and input the real network attack sample graph and the attack labels into the pre-trained preset attack feature recognition model;
[0180] Determine the probability that each edge belongs to an attack event through the fully connected layer of the initial model. When the determined probability is greater than or equal to the preset threshold, determine the event information corresponding to the edge as an attack event;
[0181] When it is determined that the attack event has an attack label, determine the judgment mark of the attack event as 1. When it is determined that the attack event does not have an attack label, determine the judgment mark of the attack event as 0;
[0182] When it is determined that the judgment flag is 1, the product of the natural logarithm of each probability and the corresponding judgment flag is determined as the first parameter. When it is determined that the judgment flag is 0, the natural logarithm of the probability that does not belong to the attack event is determined as the second parameter. The sum of the first parameter and the second parameter corresponding to the real network attack sample graph is used as the loss function value of the pre-trained preset attack feature recognition model, and the parameters of the preset attack feature recognition model are optimized according to the loss function value.
[0183] In one embodiment, the information tracing module 73 includes:
[0184] A model input unit, configured to input the attack event and the network event graph into a preset tracing model; wherein, the preset tracing model is constituted based on a Bayesian network;
[0185] An information tracing unit, configured to poll through the preset tracing model to determine the relevant probability of at least one remaining interaction event information in the attack event and the network event graph as the degree of dependence, and use at least one remaining interaction event information with the highest degree of dependence as the tracing information of the attack event.
[0186] In one embodiment, the attack detection and tracing device further includes:
[0187] A sample generation module, configured to extract the attack event output by the preset attack feature recognition model and the network event graph input to the preset attack feature recognition model, and use the attack event and the network event graph as samples for data augmentation to obtain training samples;
[0188] A data determination module, configured to determine the Markov blanket of the attack event in the training samples according to the growth-shrinkage algorithm, and use the data in the Markov blanket as sample data;
[0189] A score determination module, configured to determine the sample quantity of the sample data and the log-likelihood value of the sample data and the model parameters, determine the product of the natural logarithm of the sample quantity and the dimension of the model parameters, and use the difference between the product and the log-likelihood value as the Bayesian information criterion score of the sample data and the model parameters in the preset attack feature recognition model;
[0190] A parameter adjustment module, configured to adjust the model parameters based on the Bayesian information criterion score until the Bayesian information criterion score reaches the target score, and complete the training of the preset tracing model.
[0191] The attack detection and tracing device provided by the embodiment of the present invention can execute the attack detection and tracing method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0192] Embodiment Six
[0193] Figure 8 It is a schematic structural diagram of an electronic device for implementing an attack detection and traceability method according to an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0194] As Figure 8 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0195] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0196] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as an attack detection and traceability method.
[0197] In some embodiments, an attack detection and tracing method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the attack detection and tracing method described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute an attack detection and tracing method by any other suitable means (e.g., by means of firmware).
[0198] The various embodiments of the systems and techniques described above in this document may be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: being implemented in one or more computer programs that may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0199] The computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0200] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0201] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0202] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0203] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0204] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0205] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for attack detection and tracing, characterized in that: include: Acquire entities in a target network environment and interaction event information between the entities, and construct a network event graph with the entities and the interaction event information; Determine a graph embedding vector of each of the interactive event information in the network event graph as feature information based on a preset attack feature recognition model, and determine an attack event in the network event graph according to the feature information; Determine the degree of dependence between the attack event and the remaining interaction event information in the network event graph, and search for corresponding interaction event information as the tracing information of the attack event according to the degree of dependence; The step of determining the degree of dependency between the attack event and the remaining interaction event information in the network event graph, and searching for corresponding interaction event information as the tracing information of the attack event according to the degree of dependency, includes: Inputting the attack event and the network event graph into a preset tracing model; wherein the preset tracing model is based on a Bayesian network; The preset tracing model is used to poll and determine the correlation probability between the attack event and at least one remaining interaction event information in the network event graph as the degree of dependence, and the at least one remaining interaction event information with the highest degree of dependence is used as the tracing information of the attack event.
2. The method according to claim 1, characterized in that The step of determining the graph embedding vector of each interactive event information in the network event graph as feature information based on a preset attack feature recognition model, and determining the attack event in the network event graph according to the feature information includes: Extracting a node matrix composed of the entities in the network event graph and a graph adjacency matrix composed of the interaction event information based on a preset attack feature recognition model; Determine a node embedding vector of each of the nodes according to the node matrix and the graph adjacency matrix; splicing the node embedding vectors associated with the interaction event information to obtain a graph embedding vector of the interaction event information, and using the graph embedding vector as feature information; The probability that each of the feature information belongs to an attack event is determined, and the interaction event information corresponding to the feature information whose probability is greater than or equal to a preset probability threshold is taken as the attack event.
3. The method according to claim 1, characterized in that The training of the preset attack feature recognition model includes: Obtain open source network threat intelligence, extract first entities and interaction event information between the first entities in the open source network threat intelligence using natural language processing technology, take each of the first entities as a first node, take the interaction event information between the first entities as an edge, and construct an attack graph; Extracting a traffic log of a network environment, extracting interaction event information contained in the traffic log, taking a second entity corresponding to each interaction event information as a second node, taking interaction event information between the second entities as an edge, and constructing an event graph; Obtain matching nodes by matching each of the first nodes with each of the second nodes, determine a target attack path between the matching nodes, and generate an initial attack graph according to the target attack path; Determine a similarity score between the attack graph and the initial attack graph, determine a target attack graph in the initial attack graph according to the similarity score, and perform data augmentation on the target attack graph as an attack sample; Acquire entities in a network environment at at least one moment and information about interaction events between the entities, and construct a positive sample event graph according to the entities and the information about interaction events; A real network attack sample is extracted from the configuration file, the positive sample event graph, the real network attack sample and the attack sample are input into the preset attack feature recognition model, and the preset attack feature recognition model is trained.
4. The method according to claim 3, characterized in that The step of obtaining matching nodes by matching each of the first nodes with each of the second nodes, determining a target attack path between the matching nodes, and generating an initial attack graph according to the target attack path includes: Determine the attribute information of the first node, and match the associated point in the second node of the event graph as a matching node according to the attribute information; wherein the attribute information at least includes the name, type and feature information of the first node; Taking any of the matching nodes as the starting node, traversing the event graph to find the remaining matching nodes, and determining the attack path between the matching nodes; Determine the number of nodes in each of the attack paths, and use the attack paths in which the number of nodes is less than or equal to a preset number as the target attack paths between the matching nodes; Each of the matching nodes and the target attack path is connected to generate an initial attack graph.
5. The method according to claim 3, characterized in that: The determining of the similarity score between the attack graph and the initial attack graph, determining a target attack graph in the initial attack graph according to the similarity score, and performing data augmentation on the target attack graph as an attack sample comprises: Determine a connection path of each matching node in the attack graph, determine the number of nodes in each connection path, determine the reciprocal of the number of nodes in the connection path corresponding to two matching nodes, and use the maximum value of the reciprocal as the influence score of the two matching nodes; Determine the total number of all the connection paths, and add the influence scores to obtain a sum of the influence scores; The product of the sum of the impact scores and the sum of the quantities is taken as a similarity score; When the similarity score is greater than or equal to a preset similarity score, the initial attack graph is determined as a target attack graph, and data augmentation is performed on the target attack graph as the attack sample; wherein the data augmentation includes at least one of the following: node perturbation, edge perturbation, attribute masking, and random subgraph sampling.
6. The method according to claim 3, characterized in that The step of inputting the positive sample event graph, the real network attack sample, and the attack sample into the preset attack feature recognition model to train the preset attack feature recognition model includes: The positive sample event graph and the attack sample are used as pre-training samples, the pre-training samples are input into the preset attack feature recognition model, local features of the pre-training samples are respectively extracted by the preset attack feature recognition model, and the local features are aggregated as global features; wherein the preset attack feature recognition model is based on an encoder-decoder architecture; Determining the loss value of the preset attack feature recognition model based on a preset pre-trained network loss function; wherein the pre-trained network loss function at least includes binary cross entropy; Iterating the preset attack feature recognition model by using the loss value until the number of iterations is reached, and adjusting the parameters of the preset attack feature recognition model during the iteration process to obtain the pre-trained preset attack feature recognition model; Using entities in the real network attack sample as nodes and event information between the entities as edges to generate a real network attack sample graph, marking attack events in the real network attack sample graph with attack labels, and inputting the real network attack sample graph and the attack labels into the pre-trained preset attack feature recognition model; Determine the probability that each edge belongs to an attack event through the fully connected layer of the preset attack feature recognition model, and when it is determined that the probability is greater than or equal to a preset threshold, determine that the event information corresponding to the edge is an attack event; When it is determined that the attack event has an attack tag, the judgment mark of the attack event is determined to be 1; when it is determined that the attack event does not have an attack tag, the judgment mark of the attack event is determined to be 0; When it is determined that the judgment mark is 1, the product of the natural logarithm of each probability and the corresponding judgment mark is determined as the first parameter. When it is determined that the judgment mark is 0, the natural logarithm of the probability that it does not belong to an attack event is determined as the second parameter. The sum of the first parameter and the second parameter corresponding to the real network attack sample graph is used as the loss function value of the pre-trained preset attack feature recognition model, and the parameters of the preset attack feature recognition model are optimized according to the loss function value.
7. The method according to claim 1, characterized in that The training of the preset traceability model includes: Extracting the attack event output by a preset attack feature recognition model and the network event graph input by the preset attack feature recognition model, and performing data augmentation using the attack event and the network event graph as samples to obtain training samples; Determine a Markov blanket of attack events in the training samples according to a growth-shrink algorithm, and use the data in the Markov blanket as sample data; Determine the sample size of the sample data and the log-likelihood value of the sample data and the model parameter, determine the product of the natural logarithm of the sample size and the model parameter dimension, and use the difference between the product and the log-likelihood value as the Bayesian information criterion score of the sample data and the model parameter in the preset attack feature recognition model; The model parameters are adjusted based on the Bayesian information criterion score until the Bayesian information criterion score reaches the target score, thereby completing the training of the preset traceability model.
8. An attack detection and tracing device, characterized in that: include: An event graph construction module is used to obtain entities in a target network environment and interaction event information between the entities, and construct a network event graph with the entities and the interaction event information; An attack event determination module, configured to determine a graph embedding vector of each of the interactive event information in the network event graph as feature information based on a preset attack feature recognition model, and determine an attack event in the network event graph according to the feature information; An information tracing module, used to determine the degree of dependence between the attack event and the remaining interaction event information in the network event graph, and to search for corresponding interaction event information as tracing information of the attack event according to the degree of dependence; Wherein, the information tracing module includes: A model input unit, used to input the attack event and the network event graph into a preset tracing model; wherein the preset tracing model is based on a Bayesian network; An information tracing unit is used to determine the correlation probability between the attack event and at least one remaining interaction event information in the network event graph as the degree of dependence through polling of the preset tracing model, and to use at least one remaining interaction event information with the highest degree of dependence as the tracing information of the attack event.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the attack detection and tracing method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the attack detection and tracing method according to any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
Threat intelligence intelligent analysis method and system facing attack traceability
CN114422224A
Network attack reconstruction method, model training method and related device
CN116886379A