Security protection scheme determination method, device and equipment based on attack intelligence

By using attack intelligence-based methods, we can identify high-frequency attack intelligence and target types in big data systems, optimize protection schemes, solve the problem of resource waste in existing technologies, and achieve efficient security protection.

CN118802280BActive Publication Date: 2026-06-16CHINA MOBILE GROUP ZHEJIANG +3
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE GROUP ZHEJIANG
Filing Date
2024-03-07
Publication Date
2026-06-16

Smart Images

  • Figure CN118802280B_ABST
    Figure CN118802280B_ABST
Patent Text Reader

Abstract

The application provides a security protection scheme determination method and device based on attack intelligence, and equipment, wherein the method comprises the following steps: determining a scene type of a to-be-protected scene based on objects in the to-be-protected scene; determining target attack intelligence based on hotness information of the scene type, wherein the hotness information comprises the hotness of various attack intelligences in the scene corresponding to the scene type, and the attack intelligence reflects the information source of an attack launched by an attacker; determining an attack object type in the to-be-protected scene based on the target attack intelligence, wherein the attack object type corresponds to an object with a higher attack possibility than other objects in the to-be-protected scene; determining at least one attack path based on the attack object type, wherein the attack path comprises the object corresponding to the attack object type; and determining a security protection scheme of the to-be-protected scene based on the attack path. The application can effectively reduce the resources required for security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication security technology, and in particular to a method, apparatus, and equipment for determining security protection schemes based on attack intelligence. Background Technology

[0002] Big data systems can collect and analyze people's behavior and preferences to provide intelligent home services, such as smart lighting, automatic temperature control, and intelligent recommendations for goods or services. Furthermore, big data systems can collect and analyze travel and traffic data to provide users with real-time traffic conditions, recommend optimal travel routes, avoid traffic congestion, and shorten travel time. However, while big data systems bring convenience, they also pose risks of information leakage and malicious use by criminals. Therefore, data security is a critical technical issue that requires urgent attention.

[0003] To ensure data security, existing technologies propose methods to generate corresponding protection schemes based on attack paths. However, in reality, there are a large number of possible attack paths, and treating each attack path with the same protection would consume a lot of resources. Summary of the Invention

[0004] This invention provides a method, apparatus, and equipment for determining security protection schemes based on attack intelligence, which solves the problem that security protection in the prior art requires a lot of resources, thereby reducing the resources required to generate security protection schemes.

[0005] This invention provides a method for determining a security protection scheme based on attack intelligence, comprising:

[0006] The scenario type of the scenario to be protected is determined based on the objects in the scenario to be protected, and the target attack intelligence is determined based on the heat information of the scenario type. The heat information includes the heat of various attack intelligences in the scenario corresponding to the scenario type, and the attack intelligence reflects the information source of the attacker's attack.

[0007] Based on the target attack intelligence, the attack target type in the scenario to be protected is determined, and the object corresponding to the attack target type is more likely to be attacked than other objects in the scenario to be protected;

[0008] At least one attack path is determined based on the attack target type, and the attack path includes an object corresponding to the attack target type. A security protection scheme for the scenario to be protected is determined based on the attack path.

[0009] According to the security protection scheme determination method based on attack intelligence provided by the present invention, the step of determining the scenario type of the scenario to be protected based on objects in the scenario to be protected includes:

[0010] Obtain attribute information of at least one object in the scenario to be protected, the attribute information including the object's hardware / software type and hardware / software attributes;

[0011] The scenario type is determined based on the attribute information of the objects in the scenario to be protected.

[0012] According to the security protection scheme determination method based on attack intelligence provided by the present invention, the step of determining the scenario type based on the attribute information of the object in the scenario to be protected includes:

[0013] When the object's software and hardware type is hardware, the object's software and hardware attributes reflect the object's product type, and the scenario type is determined based on the product type corresponding to the object's software and hardware attributes.

[0014] When the object's hardware and software type is software, the object's hardware and software attributes reflect the object's IP address, and the scenario type is determined based on the IP address corresponding to the object's hardware and software attributes.

[0015] According to the security protection scheme determination method based on attack intelligence provided by the present invention, before determining the target attack intelligence based on the heat information of the scenario type, the method includes:

[0016] Obtain the attack intelligence of the attack events that occurred in the scene corresponding to the scene type;

[0017] The popularity of the attack intelligence corresponding to the attack event is determined based on the frequency of the attack event.

[0018] According to the security protection scheme determination method based on attack intelligence provided by the present invention, the step of obtaining the attack intelligence corresponding to the attack event occurring in the scenario corresponding to the scenario type includes:

[0019] Obtain the attack record of the attack event, the attack record including the attack logs of each object attacked in the attack event;

[0020] The initial target of the attack event is determined based on the attack records;

[0021] The attack intelligence corresponding to the attack event is determined based on the initial target of the attack.

[0022] According to the security protection scheme determination method based on attack intelligence provided by the present invention, determining the initial target of the attack event based on the attack record includes:

[0023] Obtain the generation time of the attack log for each attacked object in the attack record;

[0024] Based on the generation time, the attacked objects in the attack record are sorted, and the initial attack target of the attack event is determined based on the sorting result.

[0025] The present invention also provides a security protection scheme determination device based on attack intelligence, comprising:

[0026] The attack intelligence analysis module is used to determine the scenario type of the scenario to be protected based on the objects in the scenario to be protected, and to determine the target attack intelligence based on the popularity information of the scenario type. The popularity information includes the popularity of various attack intelligences in the scenario corresponding to the scenario type. The attack intelligence reflects the information source of the attacker's attack.

[0027] An attack target determination module is used to determine the type of attack target in the scenario to be protected based on the target attack intelligence, wherein the object corresponding to the attack target type is more likely to be attacked than other objects in the scenario to be protected.

[0028] The scheme determination module is used to determine at least one attack path based on the attack object type, wherein the attack path includes an object corresponding to the attack object type, and to determine a security protection scheme for the scenario to be protected based on the attack path.

[0029] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the security protection scheme determination method based on attack intelligence as described above.

[0030] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the security protection scheme determination method based on attack intelligence as described above.

[0031] The present invention also provides a computer program product, including a computer program, which, when executed by a processor, implements the security protection scheme determination method based on attack intelligence as described above.

[0032] The present invention provides a method, apparatus, and device for determining security protection schemes based on attack intelligence. By determining the target attack intelligence in a scene based on the popularity of various attack intelligence in the scene type to be protected, the present invention can identify target attack intelligence with high popularity in the scene to be protected. Then, based on the target attack intelligence, the present invention can identify objects in the scene to be protected that have a higher probability of being attacked than other objects. Attack paths are determined only for these objects with a higher probability of being attacked than other objects, and security protection schemes are determined for these attack paths. Compared with the prior art, which does not distinguish attack paths and determines security protection schemes for all possible attack paths, the method provided by the present invention can effectively reduce the resources required for security protection. Attached Figure Description

[0033] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0034] Figure 1 This is a flowchart illustrating the method for determining a security protection scheme based on attack intelligence provided by the present invention.

[0035] Figure 2 This is a schematic diagram illustrating the correspondence between attack intelligence, scenario type, object type, and object in the attack intelligence-based security protection scheme determination method provided by this invention.

[0036] Figure 3 This is a schematic diagram of different attack paths for the same object in the security protection scheme determination method based on attack intelligence provided by the present invention;

[0037] Figure 4 This is a schematic diagram of the security protection scheme determination device based on attack intelligence provided by the present invention;

[0038] Figure 5 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0040] The following is combined with Figures 1-3 The method for determining a security protection scheme based on attack intelligence provided by this invention is described, such as... Figure 1 As shown, the method provided by the present invention includes the following steps:

[0041] S110. Determine the scenario type of the scenario to be protected based on the objects in the scenario to be protected, and determine the target attack intelligence based on the heat information of the scenario type. The heat information includes the heat of various attack intelligences in the scenario corresponding to the scenario type. The attack intelligence reflects the information source of the attacker's attack.

[0042] S120. Based on the target attack intelligence, determine the type of attack object in the scene to be protected. The object corresponding to the attack object type is more likely to be attacked than other objects in the scene to be protected.

[0043] S130. Determine at least one attack path based on the attack target type, the attack path including the object corresponding to the attack target type, and determine the security protection scheme for the scenario to be protected based on the attack path.

[0044] The method provided by this invention determines the target attack intelligence in a scene based on the popularity of various attack intelligences within the scene type to be protected. This identifies high-popularity target attack intelligence within the scene, and then, based on this attack intelligence, determines objects with a higher probability of being attacked than other objects within the scene. Attack paths are determined only for these objects with a higher probability of being attacked, and security protection schemes are then determined for these attack paths. Compared to existing technologies that do not differentiate between attack paths and determine security protection schemes for all possible attack paths, the method provided by this invention determines the popularity of attack intelligence based on the scene type of the object, thereby identifying the most likely object type to be attacked in the current scene, further determining the most likely attack path, and selecting the corresponding security protection scheme based on the most likely attack path. This effectively reduces the resources required for security protection, ensuring data security while avoiding excessive resource consumption.

[0045] The method provided by this invention can be executed by a terminal or device with computing capabilities, such as by a platform server of a security protection service platform.

[0046] The scenario type of the scenario to be protected is determined by obtaining information about the objects existing in the scenario to be protected. The objects in the scenario to be protected are the subjects that may be attacked. They can be software devices or hardware devices, such as the CPU, memory, and various controllers in a computer or server, the motherboard and antenna of a personal mobile terminal device, and the vehicle radar, camera, and other hardware devices in a vehicle; and the firmware, image files, and other software devices of the applications installed inside electronic devices.

[0047] The scenarios can be categorized based on the potential applications of security protection services. These scenarios could include connected vehicle scenarios, office scenarios, and personal mobile terminal scenarios.

[0048] The scenario type of the scenario to be protected is determined based on the objects in the scenario to be protected, including:

[0049] Obtain the attribute information of at least one object in the scene to be protected. The attribute information includes the object's hardware and software type and hardware and software attributes.

[0050] The scenario type is determined based on the attribute information of the objects in the scenario to be protected.

[0051] The protected scenario may include multiple objects. The scenario type can be determined based on the object's software and hardware type and attributes. This can accurately identify the type of the protected scenario, and then, by combining the characteristics of the protected scenario type, vulnerable objects in that scenario can be located, thereby improving data security and reducing resource consumption.

[0052] The current scenario of an object can be determined based on the object's hardware or software type, combined with one or more of the target object's attribute information, such as serial number, product number, IP address, and network environment. Specifically, the scenario type is determined based on the attribute information of the object in the scenario to be protected, including:

[0053] When the object's software and hardware type is hardware, the object's software and hardware attributes reflect the object's product type, and the scenario type is determined based on the product type corresponding to the object's software and hardware attributes.

[0054] When the object's hardware or software type is software, the object's hardware or software attributes reflect the object's IP address, and the scenario type is determined based on the IP address corresponding to the object's hardware or software attributes.

[0055] For example:

[0056] If the object is hardware, it can be identified through its serial number or product number, which serves as a unique identifier for accurate product identification. For example, if the serial number identifies the current hardware as automotive radar, then the current scenario is determined to be a connected vehicle scenario.

[0057] If the object is software, the software type can be identified by its serial number. Further analysis of the IP address of the device on which the software is installed can then determine the current scenario of the software. For example, if the serial number identifies the software as video conferencing software, and this software might be installed on a personal computer in a home environment or a computer in an office environment, then the network segment of the IP address of the device on which the software is installed can be used to determine the current scenario of the software. The IP address of the device on which the software is installed can be obtained by parsing the data packets sent by the software. For instance, if the network segment of the IP address of the device on which the software is installed belongs to a company that has signed a security service contract with the unified service platform, then the current scenario of the software can be determined to be an office environment.

[0058] Attack intelligence is the source of information that attackers obtain about their targets. Based on attack intelligence, attackers can accurately attack their targets. Therefore, the methods for obtaining attack intelligence are very important for the analysis of security protection.

[0059] Attack intelligence can include asset intelligence, fingerprint intelligence, traffic intelligence, vulnerability intelligence, and malware intelligence.

[0060] Specifically, asset intelligence refers to the precise discovery of network IP and domain name assets and their attributes using passive and active information collection methods, such as DNS resolution records, ICP filing information, and WHOIS information.

[0061] Fingerprint intelligence is a subset of asset intelligence, including operating system, port services, web container (such as Apache), website building language (such as PHP), website front-end framework (such as jQuery), website back-end framework (such as Django), firewall information, etc.

[0062] Traffic intelligence refers to traffic information collected based on full network traffic mirroring monitoring, SNMP (Simple Network Management Protocol) monitoring, or Netflow monitoring, such as data flow quintuple information and traffic volume.

[0063] Vulnerability intelligence refers to information such as the basic vulnerability database and the latest exploitation methods of 0-day vulnerabilities (vulnerabilities in the wild), as well as intelligence on various software and hardware vulnerabilities and / or unknown vulnerabilities.

[0064] Malware intelligence refers to the basic database of malware and the latest active malware data, such as: C2 domains or IP addresses, malware MD5 values, vulnerabilities exploited by malware, malware file and process behavior, and other information.

[0065] After determining the scenario type, the attack intelligence with higher popularity within that scenario type is further identified as target attack intelligence. High popularity indicates a high frequency of occurrence of the attack intelligence within a preset time period. In other words, the higher the frequency of a certain attack intelligence occurrence within a specific scenario type, the higher the popularity of that attack intelligence within that scenario type. Therefore, before determining target attack intelligence based on scenario type popularity information, the following steps are taken:

[0066] Obtain attack intelligence on attack events that occur in the scene corresponding to the scene type;

[0067] The frequency of attack events determines the heat of attack intelligence corresponding to those events.

[0068] The frequency of attack intelligence in different scenarios is obtained by analyzing the attack history database of the current scenario. As the attack history database continues to grow, the popularity of different attack intelligence may change.

[0069] Analyze each record in the history database to determine the attack intelligence corresponding to each attack history record within a certain period of time (e.g., one week). Sum the different attack intelligence corresponding to all attack history records to obtain the frequency of each type of attack intelligence within a certain period of time.

[0070] Specifically, it obtains attack intelligence corresponding to attack events occurring in the scene corresponding to the scene type, including:

[0071] Obtain the attack logs of the attack event, which include the attack logs of each object attacked in the attack event;

[0072] Identify the initial target of the attack based on the attack log;

[0073] The attack intelligence corresponding to the attack event is determined based on the initial target of the attack.

[0074] System manufacturers and users often enhance the security protection level of their targets, making direct attacks on these targets difficult for malicious actors. Instead, to achieve their goal, malicious actors typically first exploit weaknesses in the system (such as those with low security levels), then further attack other components within the system to reach their ultimate objective. Such attacks are often only detected when they reach the target, leading to a search of log files and the creation of an attack record. Therefore, the method provided by this invention traces back from the final attack target to obtain the initial attack target. This initial target is precisely the target identified by the malicious actors based on attack intelligence. Thus, the method provided by this invention can effectively determine the frequency of attack intelligence based on attack records.

[0075] It should be noted that a single record is a summary of attack logs for all objects attacked by the same attacker. The same attacker can be identified by the same address accessed by each object in the attack log and / or the same address responded to by each object in the attack log.

[0076] Specifically, the initial target of the attack event is determined based on the attack log, including:

[0077] Obtain the generation time of the attack log for each attacked object in the attack log;

[0078] The attacked objects in the attack records are sorted according to each generation time, and the initial attack target of the attack event is determined based on the sorting results.

[0079] The process of tracing back from the final target of attack to find the initial target of attack can be as follows: obtain the generation time of each corresponding attack log in a record, arrange the attacked objects in the order of generation time, and trace back to the initial target of attack.

[0080] At a given point in time, identifying high-priority attack intelligence within different scenarios can be achieved by comparing the frequency of different types of attack intelligence occurring within that scenario over a given period with a pre-set frequency threshold for that scenario. If the frequency of a certain type of attack intelligence occurring over a given period exceeds the corresponding frequency threshold, then that type of attack intelligence is considered high-priority.

[0081] Alternatively, attack intelligence can be sorted from highest to lowest frequency over a period of time, and the attack intelligence that ranks first or second after sorting can be considered as the most popular attack intelligence.

[0082] In a specific example, assuming the above processing method yields the following high-profile attack intelligence:

[0083] In the context of connected vehicles, the most popular attack intelligence is vulnerability intelligence.

[0084] In an office setting, the most frequently used attack intelligence includes asset intelligence, traffic intelligence, and vulnerability intelligence.

[0085] In the context of personal mobile terminals, the most frequently reported attack intelligence is malware intelligence.

[0086] Of course, the popularity of each type of attack intelligence is not static; it changes with factors such as continuous technological upgrades and the emergence of new user needs.

[0087] Based on the attack intelligence with high activity in the scenario types to be protected, the types of objects most likely to be attacked in the protected scenario are identified as attack target types. Specifically, objects can be categorized into various types based on their function, such as control, communication, and execution types. Different types of attack intelligence correspond to different most likely attack target types in different scenarios. Figure 2 As shown.

[0088] For vulnerability intelligence in the context of connected vehicles, the most likely target type is control-related, such as script-based vulnerabilities (e.g., script execution vulnerabilities) and server-side SQL injection vulnerabilities that could attack driver assistance systems; among these, driver assistance systems belong to the control category of intelligent driving.

[0089] For asset intelligence in office scenarios, the most likely target type is execution-type objects, such as attacking the enterprise's SOC (Security Operations Center) based on the enterprise's asset intelligence, and memory devices (object type is hardware) that store network logs, alarm information, etc. to obtain the enterprise's private information; among them, SOC and memory are both execution-type objects.

[0090] For traffic intelligence in office scenarios, the most likely target type is communication-related, such as obtaining mirror detection information based on network traffic or traffic intelligence information based on NetFlow related to office equipment by attacking the gateway; among them, the gateway is a communication-related object.

[0091] For vulnerability intelligence in office scenarios, the most likely target type is the execution class, such as attacking the OA office system through script vulnerabilities, or attacking the computer or server operating system through operating system vulnerabilities; both the OA office system and the operating system are execution class objects.

[0092] For malware intelligence in personal mobile terminal scenarios, the most likely target type is the execution class, such as malware that obtains the terminal's private information and attacks applications installed on the terminal that require private information for login; applications are execution class objects.

[0093] This invention identifies the initial target of an attack by recording historical attacks, thereby determining the corresponding attack intelligence. Based on the frequency of occurrence of different attack intelligence, the popularity of different attack intelligence is determined. Attack intelligence with higher popularity is further analyzed, reducing the amount of analysis and saving protection costs.

[0094] Based on the most likely target object type in the scenario to be protected, the attack path can be determined. The attack path includes at least one object corresponding to the target object type. Specifically, if the object corresponding to the target object type determined above is actually attacked, then after attacking the object corresponding to the target object type, other objects may be attacked in sequence. The path formed from the object corresponding to the target object type to the other objects that are attacked in sequence is the attack path, that is, the attack path includes multiple objects.

[0095] For example, in an office setting, if the most likely target type is identified as communication-related, and the target is the gateway, the most likely attack paths could be the gateway, server, database, or memory, aiming to obtain enterprise data. Similarly, using the gateway as the target, attack paths could also include the gateway, employee work terminals, and applications (or stored files) on the terminals, aiming to obtain work data or personal information. Likewise, using the gateway as the target, attack paths could also include the gateway, personal computers, and smart speakers, aiming to obtain the sound of the current environment. Figure 3 As shown.

[0096] After determining the attack path based on the type of attack target, a security protection scheme is determined based on the attack path. The security protection scheme can be the protection scheme provided by the corresponding vendor for each object on the attack path during the development or use phase. The protection schemes for each object on the attack path are combined to obtain the security protection scheme for the scenario to be protected.

[0097] The following describes the security protection scheme determination device based on attack intelligence provided by the present invention. The security protection scheme determination device based on attack intelligence described below and the security protection scheme determination method based on attack intelligence described above can be referred to in correspondence. Figure 4 As shown, the security protection scheme determination device based on attack intelligence provided by the present invention includes:

[0098] The attack intelligence analysis module 410 is used to determine the scenario type of the scenario to be protected based on the objects in the scenario to be protected, and to determine the target attack intelligence based on the heat information of the scenario type. The heat information includes the heat of various attack intelligences in the scenario corresponding to the scenario type. The attack intelligence reflects the information source of the attacker's attack.

[0099] The attack target determination module 420 is used to determine the type of attack target in the scene to be protected based on the target attack intelligence. The object corresponding to the attack target type is more likely to be attacked than other objects in the scene to be protected.

[0100] The scheme determination module 430 is used to determine at least one attack path based on the attack object type. The attack path includes the object corresponding to the attack object type, and the security protection scheme for the scenario to be protected is determined based on the attack path.

[0101] Figure 5 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 5 As shown, the electronic device may include a processor 510, a communications interface 520, a memory 530, and a communication bus 540. The processor 510, communications interface 520, and memory 530 communicate with each other via the communication bus 540. The processor 510 can call logical instructions in the memory 530 to execute a security protection scheme determination method based on attack intelligence. This method includes: determining the scenario type of the scenario to be protected based on objects in the scenario to be protected; determining target attack intelligence based on the popularity information of the scenario type, where the popularity information includes the popularity of various attack intelligences in the scenario corresponding to the scenario type, and the attack intelligence reflects the information source of the attacker's attack; determining the attack object type in the scenario to be protected based on the target attack intelligence, where the probability of the object corresponding to the attack object type is greater than that of other objects in the scenario to be protected; determining at least one attack path based on the attack object type, where the attack path includes objects corresponding to the attack object type; and determining a security protection scheme for the scenario to be protected based on the attack path.

[0102] Furthermore, the logical instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0103] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the security protection scheme determination method based on attack intelligence provided by the above methods. The method includes: determining the scenario type of the scenario to be protected based on objects in the scenario to be protected; determining target attack intelligence based on the popularity information of the scenario type, wherein the popularity information includes the popularity of various attack intelligences in the scenario corresponding to the scenario type, and the attack intelligence reflects the information source of the attacker's attack; determining the attack object type in the scenario to be protected based on the target attack intelligence, wherein the probability of the object corresponding to the attack object type being attacked is greater than that of other objects in the scenario to be protected; determining at least one attack path based on the attack object type, wherein the attack path includes the object corresponding to the attack object type; and determining a security protection scheme for the scenario to be protected based on the attack path.

[0104] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements a method for determining a security protection scheme based on attack intelligence provided by the above-described methods. This method includes: determining the scenario type of the scenario to be protected based on objects in the scenario to be protected; determining target attack intelligence based on the popularity information of the scenario type, wherein the popularity information includes the popularity of various attack intelligences in the scenario corresponding to the scenario type, and the attack intelligence reflects the information source of the attacker's attack; determining the attack object type in the scenario to be protected based on the target attack intelligence, wherein the probability of the object corresponding to the attack object type being attacked is greater than that of other objects in the scenario to be protected; determining at least one attack path based on the attack object type, wherein the attack path includes the object corresponding to the attack object type; and determining a security protection scheme for the scenario to be protected based on the attack path.

[0105] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0106] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0107] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for determining a security protection scheme based on attack intelligence, characterized in that, include: The scenario type of the scenario to be protected is determined based on the objects in the scenario to be protected, and the target attack intelligence is determined based on the heat information of the scenario type. The heat information includes the heat of various attack intelligences in the scenario corresponding to the scenario type, and the attack intelligence reflects the information source of the attacker's attack. Based on the target attack intelligence, the attack target type in the scenario to be protected is determined, and the object corresponding to the attack target type is more likely to be attacked than other objects in the scenario to be protected; At least one attack path is determined based on the attack target type, and the attack path includes an object corresponding to the attack target type. A security protection scheme for the scenario to be protected is determined based on the attack path. Before determining the target attack intelligence based on the heat information of the scene type, the following steps are included: Obtain the attack intelligence of the attack events that occurred in the scene corresponding to the scene type; The popularity of the attack intelligence corresponding to the attack event is determined based on the frequency of the attack event.

2. The method for determining a security protection scheme based on attack intelligence according to claim 1, characterized in that, Determining the scenario type of the scenario to be protected based on objects in the scenario to be protected includes: Obtain attribute information of at least one object in the scenario to be protected, the attribute information including the object's hardware / software type and hardware / software attributes; The scenario type is determined based on the attribute information of the objects in the scenario to be protected.

3. The method for determining a security protection scheme based on attack intelligence according to claim 2, characterized in that, Determining the scenario type based on the attribute information of the objects in the scenario to be protected includes: When the object's software and hardware type is hardware, the object's software and hardware attributes reflect the object's product type, and the scenario type is determined based on the product type corresponding to the object's software and hardware attributes. When the object's hardware and software type is software, the object's hardware and software attributes reflect the object's IP address, and the scenario type is determined based on the IP address corresponding to the object's hardware and software attributes.

4. The method for determining a security protection scheme based on attack intelligence according to claim 1, characterized in that, The step of obtaining the attack intelligence corresponding to the attack events occurring in the scene corresponding to the scene type includes: Obtain the attack record of the attack event, the attack record including the attack logs of each object attacked in the attack event; The initial target of the attack event is determined based on the attack records; The attack intelligence corresponding to the attack event is determined based on the initial target of the attack.

5. The method for determining a security protection scheme based on attack intelligence according to claim 4, characterized in that, The process of determining the initial target of the attack event based on the attack record includes: Obtain the generation time of the attack log for each attacked object in the attack record; Based on the generation time, the attacked objects in the attack record are sorted, and the initial attack target of the attack event is determined based on the sorting result.

6. A security protection scheme determination device based on attack intelligence, characterized in that, include: The attack intelligence analysis module is used to determine the scenario type of the scenario to be protected based on the objects in the scenario to be protected, and to determine the target attack intelligence based on the popularity information of the scenario type. The popularity information includes the popularity of various attack intelligences in the scenario corresponding to the scenario type. The attack intelligence reflects the information source of the attacker's attack. An attack target determination module is used to determine the type of attack target in the scenario to be protected based on the target attack intelligence, wherein the object corresponding to the attack target type is more likely to be attacked than other objects in the scenario to be protected. The scheme determination module is used to determine at least one attack path based on the attack object type, wherein the attack path includes an object corresponding to the attack object type, and to determine a security protection scheme for the scenario to be protected based on the attack path. Before determining the target attack intelligence based on the heat information of the scene type, the following steps are included: Obtain the attack intelligence of the attack events that occurred in the scene corresponding to the scene type; The popularity of the attack intelligence corresponding to the attack event is determined based on the frequency of the attack event.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the security protection scheme determination method based on attack intelligence as described in any one of claims 1 to 5.

8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the security protection scheme determination method based on attack intelligence as described in any one of claims 1 to 5.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the security protection scheme determination method based on attack intelligence as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Permeation test method, device and equipment based on machine learning and storage medium

    CN112733146A

  • Interactive automatic restoration method for network threat event attack scene

    CN112839039A