Attack tracing method and related node, storage medium, computer program product

By using the interaction and secure communication mechanism between the central node and the tracing node, the problem of low efficiency and poor accuracy of existing network attack tracing methods is solved, achieving efficient and accurate tracing across the entire network, reducing data storage and bandwidth requirements, and ensuring data security.

CN118802287BActive Publication Date: 2026-01-20CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410316139.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-19
Publication Date
2026-01-20
Estimated Expiration
2044-03-19

AI Technical Summary

Technical Problem

Existing methods for tracing network attacks are inefficient and inaccurate, and are limited by the real-time nature of data and the scope of deployment, making it difficult to trace the source.

Method used

The system introduces interaction between the central node and the tracing node. By publishing tracing task information and selecting suitable tracing nodes, network attack tracing is carried out. Public key encryption and private key decryption are used to ensure communication security. A semi-open node registration mechanism is adopted to realize the association of data across the entire network and the circulation of task points and rewards.

Benefits of technology

It improves the accuracy and efficiency of tracing the source of cyberattacks, reduces the waste of data reporting and storage resources, and ensures data security and the reliability of tracing results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802287B_ABST
    Figure CN118802287B_ABST
Patent Text Reader

Abstract

The application discloses an attack tracing method and related nodes, a storage medium and a computer program product. The method applied to a first tracing node comprises the following steps: when a network attack event occurs in a tracing service connected to the first tracing node, sending tracing task information of the network attack event to a center node, so as to send the tracing task information to different tracing nodes through the center node; wherein the center node is used for determining a second tracing node for tracing the network attack event based on response information of at least one tracing node to the tracing task information; after mutual identity authentication with the second tracing node, a communication connection is established, and tracing task details of the network attack event are sent to the second tracing node, so as to trace the network attack event through the second tracing node.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of network security, and in particular to an attack tracing method and related nodes, a storage medium, and a computer program product. BACKGROUND

[0002] With the continuous development of network technology, network space attack and defense confrontation is increasingly fierce, network security problems are concerned, and international range of advanced persistent threat (APT) attack events, distributed denial of service (DDoS) attack events, and ransomware events are emerging in an endless stream.

[0003] Currently, there are two main methods for network attack tracing. The first method is to report all data of security devices and network devices in the jurisdiction network range to a network security data lake, retrieve data in the central data lake according to information clues of attack events, perform correlation analysis on the data through a tracing algorithm model, draw an attack path, give an attacker portrait, a victim portrait, establish a knowledge base, and the like. The second method is to deploy a honeynet and a honeypot device. When an attack occurs, an attacker steps on a preset trap, the honeypot device records all attack behaviors after the attacker enters, traces and analyzes network traces left by the attacker, and performs sample analysis on samples used by the attacker, so as to obtain as many attack habits, sample families, attacker addresses, and tools used by the attacker as possible, and then trace and locate an attack source.

[0004] However, the first method described above has low efficiency in the way of searching and tracing algorithm model calculation of massive data, and is limited by real-time and completeness of underlying data reporting, resulting in a small probability of successfully calculating a tracing result. The second method is limited by the simulation degree and deployment range of the honeypot, and has a small probability of capturing attack events, thereby making it difficult to trace and locate an attack. SUMMARY

[0005] Embodiments of the present application provide an attack tracing method and related nodes, a storage medium, and a computer program product, introduce interaction between a central node and a tracing node, implement publication of tracing task information, and further select a suitable tracing node to trace a network attack, thereby improving accuracy of network attack event tracing and making the tracing method simple and efficient.

[0006] The technical solution of the embodiments of the present application is implemented as follows.

[0007] The embodiments of the present application provide an attack tracing method applied to a first tracing node, and the method includes the following steps.

[0008] When a network attack event occurs in a traceability service connected to the first traceability node, sending traceability task information of the network attack event to a center node to send to different traceability nodes through the center node; wherein the center node is configured to determine a second traceability node for tracing the network attack event based on response information of at least one traceability node to the traceability task information;

[0009] After mutual authentication with the second traceability node, a communication connection is established, and traceability task details of the network attack event are sent to the second traceability node to trace the network attack event through the second traceability node.

[0010] In the above method, before the traceability task details of the network attack event are sent to the second traceability node, the method further comprises:

[0011] The traceability task details are encrypted using a public key of the second traceability node.

[0012] In the above method, before the communication connection with the second traceability node is established, the method further comprises:

[0013] Receiving indication information sent by the center node; wherein the indication information is used to indicate that the second traceability node is a traceability node for tracing the network attack event.

[0014] In the above method, after the traceability task details of the network attack event are sent to the second traceability node, the method further comprises:

[0015] Receiving traceability result information of the network attack event sent by the second traceability node;

[0016] Evaluating the traceability result information to generate reward evaluation information of the second traceability node;

[0017] Sending the reward evaluation information to the center node.

[0018] In the above method, the traceability result information is encrypted by a private key of the second traceability node, and before the traceability result information is evaluated, the method further comprises:

[0019] Decrypting the traceability result information using a public key of the second traceability node.

[0020] Embodiments of the present application provide an attack traceability method, applied to a center node, the method comprising:

[0021] Receiving traceability task information of a network attack event sent by a first traceability node, and sending the traceability task information to different traceability nodes;

[0022] determine a second tracing node for tracing the network attack event based on response information sent by at least one tracing node in response to the tracing task information.

[0023] In the method described above, the determination of the second tracing node for tracing the network attack event based on the response information sent by the at least one tracing node in response to the tracing task information comprises:

[0024] For the at least one tracing node, one or more tracing nodes are determined as the second tracing node based on the order of sending the response information and the node score.

[0025] In the method described above, after the determination of the second tracing node for tracing the network attack event, the method further comprises:

[0026] sending indication information to the first tracing node, wherein the indication information is used to indicate that the second tracing node is the tracing node for tracing the network attack event.

[0027] In the method described above, after the determination of the second tracing node for tracing the network attack event, the method further comprises:

[0028] receiving reward evaluation information of the second tracing node sent by the first tracing node, wherein the reward evaluation information is determined by the first tracing node based on the tracing result information of the network attack event by the second tracing node.

[0029] updating the node score of the second tracing node based on the reward evaluation information.

[0030] In the method described above, after the receiving of the reward evaluation information of the second tracing node sent by the first tracing node, the method further comprises:

[0031] sending the reward evaluation information to the second tracing node and receiving node evaluation information of the first tracing node sent by the second tracing node, wherein the node evaluation information is determined by the second tracing node based on the reward evaluation information.

[0032] updating the node score of the first tracing node based on the node evaluation information.

[0033] Embodiments of the present application provide an attack tracing method, applied to a second tracing node, and the method comprises:

[0034] establishing a communication connection after mutual identity authentication with a first tracing node and receiving tracing task details of a network attack event sent by the first tracing node.

[0035] trace the network attack event based on the trace task details, to obtain trace result information of the network attack event.

[0036] In the method described above, the trace task details are encrypted by the public key of the second trace node, and before the trace of the network attack event based on the trace task details, the method further comprises:

[0037] decrypting the trace task details by using the private key of the second trace node.

[0038] In the method described above, the trace of the network attack event based on the trace task details, to obtain trace result information of the network attack event, comprises:

[0039] distributing the trace task details to a trace service connected to the second trace node;

[0040] retrieving associated data sources to obtain the trace result information based on the trace task details through the trace service.

[0041] In the method described above, the second trace node supports the task requirements indicated by the trace task information, and before the mutual authentication with the first trace node to establish a communication connection, the method further comprises:

[0042] receiving, by the center node, the trace task information of the network attack event sent by the first trace node;

[0043] sending response information to the center node in response to the trace task information.

[0044] In the method described above, after obtaining the trace result information of the network attack event, the method further comprises:

[0045] sending the trace result information to the first trace node.

[0046] In the method described above, before sending the trace result information to the first trace node, the method further comprises:

[0047] encrypting the trace result information by using the private key of the second trace node.

[0048] In the method described above, after sending the trace result information to the first trace node, the method further comprises:

[0049] receiving, by the center node, reward evaluation information of the second trace node sent by the first trace node; wherein the reward evaluation information is determined by the first trace node based on the trace result information.

[0050] evaluate the first traceability node based on the reward evaluation information, and generate node evaluation information of the first traceability node;

[0051] send the node evaluation information to the center node.

[0052] Embodiments of the present application provide a first traceability node, comprising a first processor, a first memory and a first communication bus;

[0053] The first communication bus is configured to realize communication connection between the first processor and the first memory.

[0054] The first processor is configured to execute one or more computer programs stored in the first memory, so as to realize the attack traceability method applied to the first traceability node.

[0055] Embodiments of the present application provide a second traceability node, comprising a second processor, a second memory and a second communication bus;

[0056] The second communication bus is configured to realize communication connection between the second processor and the second memory.

[0057] The second processor is configured to execute one or more computer programs stored in the second memory, so as to realize the attack traceability method applied to the second traceability node.

[0058] Embodiments of the present application provide a center node, comprising a third processor, a third memory and a third communication bus;

[0059] The third communication bus is configured to realize communication connection between the third processor and the third memory.

[0060] The third processor is configured to execute one or more computer programs stored in the third memory, so as to realize the attack traceability method applied to the center node.

[0061] Embodiments of the present application provide a computer readable storage medium, which stores a computer program, and the computer program is characterized in that, when executed by a processor, the computer program realizes the steps of any attack traceability method.

[0062] Embodiments of the present application provide a computer program product, comprising a computer program, and the computer program realizes the steps of any attack traceability method when executed by a processor.

[0063] The embodiment of the application provides a kind of attack tracing method and related node, storage medium, computer program product, the method applied to first tracing node includes: when the network attack event of the tracing service of first tracing node connection occurs, the tracing task information of network attack event is sent to center node, to be sent to different tracing node by center node;Wherein, center node is used to determine the second tracing node of network attack event tracing based on the response information of at least one tracing node to tracing task information;With the second tracing node mutual identity authentication is established communication connection, and the tracing task details of network attack event are sent to second tracing node, to be traced to network attack event by second tracing node.The technical scheme provided in the embodiment of the application introduces center node and the interaction of tracing node, realizes the publishing of tracing task information, and further selects suitable tracing node to carry out network attack tracing, improves the accuracy of network attack event tracing, and the tracing mode is simple and efficient. BRIEF DESCRIPTION OF DRAWINGS

[0064] Figure 1 An exemplary network architecture schematic diagram is provided for the embodiment of the application.

[0065] Figure 2 An exemplary system configuration schematic diagram of tracing node is provided for the embodiment of the application.

[0066] Figure 3 Flowchart of attack tracing method is provided for the embodiment of the application Figure 1 .

[0067] Figure 4 Flowchart of attack tracing method is provided for the embodiment of the application Figure 2 .

[0068] Figure 5 Flowchart of attack tracing method is provided for the embodiment of the application Figure 3 .

[0069] Figure 6 Structure schematic of first tracing node is provided for the embodiment of the application Figure 1 .

[0070] Figure 7 Structure schematic of first tracing node is provided for the embodiment of the application Figure 2 .

[0071] Figure 8 Structure schematic of second tracing node is provided for the embodiment of the application Figure 1 .

[0072] Figure 9 Structure schematic of second tracing node is provided for the embodiment of the application Figure 2 .

[0073] Figure 10 A structure diagram of a center node provided for an embodiment of the present application Figure 1 ;

[0074] Figure 11 A structure diagram of a center node provided for an embodiment of the present application Figure 2 . DETAILED DESCRIPTION

[0075] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0076] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below through embodiments and in combination with the drawings. The following embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments.

[0077] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0078] The embodiments of the present application provide an attack tracing method, which is applicable to Figure 1 the network architecture as shown. As shown in Figure 1 , the tracing node is connected with a tracing service, and the tracing service is associated with a data source. The interface of the tracing node related to the task and node management is provided by the center node, and the interface related to the tracing service is provided by the local interface. The joining of each tracing node needs to go through the tracing node identity authentication, the tracing node registration to join the cross-network tracing network, the tracing node synchronously distributes its public key to all online tracing nodes, and the tracing node starts the task listening. Each tracing node calls the center node service interface, and the center node serves as the tracing network service management center, and mainly carries the following functions: tracing node management, task management, reward point settlement, quality evaluation, node authentication, node information storage, task information storage, point transaction information storage, authentication information storage, audit information storage.

[0079] Figure 2 An exemplary system configuration diagram of a tracing node provided for an embodiment of the present application. As shown in Figure 2 , the system configuration can run on each tracing node, and the function points involved are described as follows:

[0080] Function point 1: Traceability node management function, which mainly completes the authentication, registration, deregistration and node audit service of the traceability node. The program installed on each traceability node calls the remote application programming interface (API) through the remote procedure call protocol (RPC) to execute;

[0081] Function point 2: Traceability task publishing management function, which mainly completes the traceability node task publishing, task synchronization, task distribution, result confirmation, score distribution acceptance and evaluation function. The program installed on each traceability node calls the remote API through RPC to execute;

[0082] Function point 3: Traceability task receiving management function, which mainly completes the acceptance of traceability tasks, task execution (including point-to-point traceability node communication), traceability task reply confirmation. The program installed on each traceability node calls the remote API through RPC to execute.

[0083] Function point 4: Overall security mechanism guarantee: 1) The traceability node does not accept individual joining, and needs to provide enterprise / unit valid identity proof and verification, and should be nodes in different network areas within the same system, which can ensure that the nodes joining the traceability network are all trusted nodes; 2) The traceability information on the bulletin board does not display the details of the traceability task, and should not involve private information; 3) The communication data between traceability nodes is encrypted and decrypted by public and private keys, and the identity needs to be verified in a zero-trust manner every time the communication is established, to avoid the traceability node being attacked and then misusing the traceability network to search information; 4) Each traceability node is evaluated, to promote the construction of traceability network ecology, and to expand the range of traceability information acquisition in a semi-open and safe mechanism.

[0084] In the embodiment of the application, the implementation of the attack traceability method is realized through cooperation of the first traceability node, the center node and the second traceability node, wherein the first traceability node and the second traceability node are Figure 1 traceability nodes in the network architecture shown.

[0085] The attack traceability method provided in the embodiment of the application is described in detail based on the above Figure 1 and Figure 2 .

[0086] Figure 3 The flowchart of the attack traceability method provided in the embodiment of the application is shown in Figure 1 . As shown in Figure 3 , in the embodiment of the application, the attack traceability method applied to the first traceability node mainly includes the following steps:

[0087] S101, when a network attack event occurs in a traceability service connected to the first traceability node, sending traceability task information of the network attack event to a center node to be sent to different traceability nodes by the center node; wherein the center node is configured to determine a second traceability node for tracing the network attack event based on response information of at least one traceability node to the traceability task information.

[0088] In an embodiment of the present application, the first traceability node can send the traceability task information of the network attack event to the center node when the network attack event occurs in the traceability service connected thereto.

[0089] In an embodiment of the present application, the first traceability node connected to the traceability service sends attack event details to the first traceability node, and the first traceability node generates traceability task information according to a task announcement template.

[0090] In an embodiment of the present application, the traceability task information can include a traceability task identifier, an identifier of the first traceability node, task reward information, a task publishing time, a task expected completion time, a traceability task type, etc. The first traceability node calls a traceability task publishing interface to publish the traceability task information by sending it to the center node. For example, the traceability task information includes the fields shown in Table 1 below.

[0091] Table 1

[0092]

[0093]

[0094] It should be noted that in an embodiment of the present application, the above-mentioned traceability task information includes various information, which is only exemplary optional information. Of course, other feature information or constraint information related to the traceability task can also be set as the traceability task information based on actual needs and application scenarios, and the embodiments of the present application are not limited.

[0095] It can be understood that in an embodiment of the present application, referring to the network architecture shown in Figure 1 The first traceability node can be one of the traceability nodes, which can monitor whether a network attack event occurs in the traceability service connected thereto, so as to send the corresponding traceability task information to the center node when the network attack event occurs, and the center node further publishes the traceability task information to other traceability nodes. The traceability node that obtains the traceability task information can selectively send response information to the center node, so that the center node selects a traceability node, i.e. a second traceability node, to trace the network attack event.

[0096] S102, after mutual identity authentication with the second traceability node, a communication connection is established, and the traceability task details of the network attack event are sent to the second traceability node, so as to trace the network attack event through the second traceability node.

[0097] In the embodiment of the application, after mutual identity authentication between the first traceability node and the second traceability node determined by the center node, a communication connection is established, so that the traceability task details of the network attack event are sent to the second traceability node, and the network attack event is traced by the second traceability node.

[0098] In the embodiment of the application, before the first traceability node establishes a communication connection with the second traceability node, the following step can also be performed: receiving the indication information sent by the center node; wherein the indication information is used to indicate that the second traceability node is a traceability node for tracing the network attack event.

[0099] It can be understood that in the embodiment of the application, after the center node determines the second traceability node, the center node can indicate to the first traceability node that the network attack event is traced by the second traceability node. Specifically, the indication information can be a communication address of the second traceability node to which the first traceability node is instructed to open a point-to-point interface. Based on this, the first traceability node verifies the identity of the other party through the node authentication interface, establishes a communication connection, and then sends the traceability task details of the network attack event to the second traceability node.

[0100] In the embodiment of the application, before the first traceability node sends the traceability task information of the network attack event to the center node, the following step can also be performed: encrypting the traceability task information by using the public key of the second traceability node, so as to improve the security of communication interaction.

[0101] In the embodiment of the application, unlike the traceability task information, the traceability task details can include the fields shown in Table 2.

[0102] Table 2

[0103]

[0104]

[0105] In the embodiment of the application, after the first traceability node sends the traceability task details of the network attack event to the second traceability node, the following step can also be performed: receiving the traceability result information of the network attack event sent by the second traceability node; evaluating the traceability result information to generate reward evaluation information of the second traceability node; and sending the reward evaluation information to the center node.

[0106] It should be noted that, in the embodiments of this application, in order to ensure the security of communication interaction, the second tracing node can use its private key to encrypt the tracing result information before sending it to the first tracing node. That is, the tracing result information can be encrypted by the private key of the second tracing node. Correspondingly, before the first tracing node evaluates the tracing result information, it can also use the public key of the second tracing node to decrypt the tracing result information.

[0107] In the embodiments of this application, the tracing result information sent by the second tracing node may include the fields shown in Table 3 below.

[0108] Table 3

[0109]

[0110] It is understood that, in the embodiments of this application, the first tracing node can evaluate the tracing result information of the network attack event sent by the second tracing node. Specifically, it can evaluate based on the tracing result scoring criteria in Table 1 and generate the reward evaluation information shown in Table 4 below.

[0111] Table 4

[0112]

[0113]

[0114] It is understood that in the embodiments of this application, the first tracing node sends reward evaluation information to the central node, and the central node can then update the node score of the second tracing node based on the reward evaluation information, that is, provide corresponding rewards to the tracing node that performs tracing.

[0115] Figure 4 A flowchart illustrating an attack tracing method provided in this application embodiment. Figure 2 .like Figure 4 As shown in the embodiments of this application, the attack tracing method applied to the central node mainly includes the following steps:

[0116] S201. Receive the network attack event tracing task information sent by the first tracing node, and send the tracing task information to different tracing nodes.

[0117] In the embodiments of this application, the central node can communicate and interact with each source tracing node. Based on this, the central node receives source tracing task information of network attack events sent by the first source tracing node and sends the source tracing task information to different source tracing nodes, thereby realizing the publication of source tracing task information.

[0118] S202. Based on the response information to the tracing task information sent by at least one tracing node, determine the second tracing node for tracing the network attack event.

[0119] In the embodiment of the present application, the center node determines the second traceability node for tracing the network attack event based on the response information of the at least one traceability node sending the traceability task information, comprising: for the at least one traceability node, determining one or more traceability nodes as the second traceability node based on the order of sending the response information and the node score.

[0120] It can be understood that in the embodiment of the present application, referring to Table 1, it is stipulated in the traceability task information that the traceability can be completed by several traceability nodes, which can be customized by the first traceability node according to the urgency of the traceability, if nodeNum=3, it means that the traceability of the network attack event can be assigned to 3 traceability nodes to complete, after the center node sends the traceability task information to different traceability nodes, if the traceability nodes have the intention to trace, they can send response information to the center node, and the center node can determine one or more second traceability nodes according to the order and the node score, for example, the center node determines 3 traceability nodes with relatively high node scores among the first 5 traceability nodes sending the response information as the second traceability nodes. Of course, the center node can also determine the second traceability node based on other information or methods, which is not limited in the embodiment of the present application.

[0121] In the embodiment of the present application, after the center node determines the second traceability node for tracing the network attack event, the following steps can also be performed: sending indication information to the first traceability node; wherein the indication information is used to indicate that the second traceability node is the traceability node for tracing the network attack event, so as to trigger the first traceability node and the second traceability node to authenticate each other to establish a communication connection.

[0122] In the embodiment of the present application, after the center node determines the second traceability node for tracing the network attack event, the following steps can also be performed: receiving the reward evaluation information of the second traceability node sent by the first traceability node; wherein the reward evaluation information is determined by the first traceability node based on the traceability result information of the second traceability node for the network attack event; updating the node score of the second traceability node based on the reward evaluation information.

[0123] In the embodiment of the present application, after the center node receives the reward evaluation information of the second traceability node sent by the first traceability node, the method further comprises: sending the reward evaluation information to the second traceability node, and receiving the node evaluation information of the first traceability node sent by the second traceability node; wherein the node evaluation information is determined by the second traceability node based on the reward evaluation information; updating the node score of the first traceability node based on the node evaluation information.

[0124] In the embodiment of the present application, the content of the reward evaluation information is shown in Table 4 above, and the node evaluation information includes the fields shown in Table 5 below.

[0125] Table 5

[0126]

[0127]

[0128] It is understood that, in the embodiments of this application, the first traceability node and the second traceability node can evaluate each other and provide the relevant evaluation information to the central node. The traceability nodes are uniformly managed by the central node, and the central node updates the node scores as the basis for subsequent traceability node management.

[0129] Figure 5 A flowchart illustrating an attack tracing method provided in this application embodiment. Figure 3 .like Figure 5 As shown in the embodiments of this application, the attack tracing method applied to the second tracing node mainly includes the following steps:

[0130] S301. After mutual authentication with the first tracing node, establish a communication connection and receive the tracing task details of the network attack event sent by the first tracing node.

[0131] In the embodiments of this application, corresponding to the method applied to the first tracing node described above, the second tracing node establishes a communication connection with the first tracing node after mutual authentication, and receives the tracing task details of the network attack event sent by the first tracing node.

[0132] It should be noted that, in the embodiments of this application, the relevant descriptions of the tracing task information are detailed in the above-described method applied to the first tracing node, and will not be repeated here.

[0133] In the embodiments of this application, the second tracing node supports the task requirements indicated by the tracing task information. Before the second tracing node and the first tracing node establish a communication connection after mutual authentication, the following steps can also be performed: receiving the tracing task information of the network attack event sent by the first tracing node through the central node; and sending response information to the tracing task information to the central node.

[0134] It can be understood that in the embodiments of the present application, the second traceability node is determined by the center node based on the received response information of the at least one traceability node, and the traceability nodes sending the response information can all support the task demand indicated by the traceability task information. Therefore, the finally selected second traceability node can actually support the task demand indicated by the traceability task information, and it needs to send response information to the center node after receiving the traceability task information published by the first traceability node through the center node, so as to be selected by the center node.

[0135] S302, trace the network attack event based on the traceability task details, and obtain traceability result information of the network attack event.

[0136] In the embodiments of the present application, the second traceability node can trace the network attack event based on the traceability task details after receiving the traceability task details, and obtain the traceability result information of the network attack event.

[0137] In the embodiments of the present application, in order to ensure the security of communication interaction, the first traceability node can encrypt the traceability task details by using the public key of the second traceability node before sending them to the second traceability node, that is, the traceability task details can be encrypted by the public key of the second traceability node. Correspondingly, before the second traceability node traces the network attack event based on the traceability task details, the traceability task details can be decrypted by using the private key of the second traceability node. For specific description of the traceability task details, please refer to the above-mentioned content applied to the method of the first traceability node, which will not be repeated here.

[0138] In the embodiments of the present application, the second traceability node traces the network attack event based on the traceability task details, and obtains the traceability result information of the network attack event, which includes: issuing the traceability task details to the traceability business connected to the second traceability node; and searching the associated data source based on the traceability task details through the traceability business to obtain the traceability result information.

[0139] It can be understood that in the embodiments of the present application, referring to the network result shown in Figure 1 The traceability business of each traceability node is associated with a data source, based on which the second traceability node can issue the traceability task details to the traceability business connected to the second traceability node for traceability search in the data source.

[0140] In the embodiments of the present application, after the second traceability node obtains the traceability result information of the network attack event, it can also perform the following steps: sending the traceability result information to the first traceability node. In order to ensure the security of communication interaction, the traceability result information can also be encrypted by using the private key of the second traceability node before being sent to the first traceability node.

[0141] In an embodiment of the present application, after the second traceability node sends the traceability result information to the first traceability node, the following steps can be further performed: receiving, by the central node, reward evaluation information of the second traceability node sent by the first traceability node; wherein the reward evaluation information is determined by the first traceability node based on the traceability result information; performing node evaluation on the first traceability node based on the reward evaluation information, generating node evaluation information of the first traceability node; and sending the node evaluation information to the central node.

[0142] It can be understood that, in an embodiment of the present application, the second traceability node can evaluate the first traceability node according to the reward evaluation information of the first traceability node, for example, whether the reward evaluation information of the first traceability node is accurate, whether the traceability task information or the traceability task details published are accurate, etc., and provide the central node for node score updating as a basis for subsequent traceability node management.

[0143] Based on the above attack traceability method applied to the first traceability node, the central node and the second traceability node, the technical solution provided by the present application has the following advantages: first, in the existing traceability technology, more consideration is given to traceability algorithms and details, and it is impossible to provide a full-network cross-network range attack traceability from the solution level, which leads to certain limitations of traceability data, affecting the traceability efficiency and attack traceability success rate. The technical solution provided by the present application can solve the above problems, starting from the whole, associating all node data of the whole network intentionally added to the attack traceability network, and circulating attack traceability demand in the form of tasks and integral rewards, so as to obtain more data of the whole network when attacking traceability, and then efficiently and accurately complete attack traceability positioning; second, in the existing attack traceability technology, data is more concentrated for retrieval and association, and underlying data is stored in a centralized manner through reporting, which affects data effectiveness and wastes network bandwidth and storage resources. The technical solution provided by the present application does not require data reporting and data migration, saves network bandwidth and storage resources, and the database hung under each traceability node is equivalent to a distributed database, which only needs to circulate task data and feedback traceability result data; third, the semi-open node registration and joining mechanism ensures data security through identity authentication, privacy encryption and point-to-point communication mechanism.

[0144] The present application embodiment provides a first traceability node. Figure 6 The structure of the first traceability node provided in the present application embodiment is shown in Figure 1 . As shown in Figure 6 , in an embodiment of the present application, the first traceability node comprises:

[0145] The first communication module 301 is used to send the tracing task information of the network attack event to a central node when a network attack event occurs in the tracing service connected to the first tracing node, so as to send it to different tracing nodes through the central node; wherein, the central node is used to determine a second tracing node for tracing the network attack event based on the response information of at least one tracing node to the tracing task information; establish a communication connection with the second tracing node after mutual authentication, and send the tracing task details of the network attack event to the second tracing node so as to trace the network attack event through the second tracing node.

[0146] In one embodiment of this application, the first tracing node further includes: a first processing module 302;

[0147] The first processing module 302 is used to encrypt the traceability task details using the public key of the second traceability node.

[0148] In one embodiment of this application, the first communication module 301 is further configured to receive indication information sent by the central node; wherein the indication information is used to indicate that the second tracing node is the tracing node for tracing the network attack event.

[0149] In one embodiment of this application, the first communication module 301 is further configured to receive the tracing result information of the network attack event sent by the second tracing node;

[0150] The first processing module 302 is further configured to evaluate the tracing result information and generate reward evaluation information for the second tracing node;

[0151] The first communication module 301 is also used to send the reward evaluation information to the central node.

[0152] In one embodiment of this application, the tracing result information is encrypted by the private key of the second tracing node, and the first processing module 302 is further configured to decrypt the tracing result information using the public key of the second tracing node.

[0153] Figure 7 A schematic diagram of the structure of a first traceability node provided in an embodiment of this application. Figure 2 .like Figure 7 As shown in the embodiments of this application, the first traceability node includes: a first processor 401, a first memory 402, and a first communication bus 403;

[0154] The first communication bus 403 is used to realize the communication connection between the first processor 401 and the first memory 402;

[0155] The first processor 401 is configured to execute one or more computer programs stored in the first memory 402 to implement an attack tracing method of an application domain first tracing node.

[0156] The second tracing node is provided in the embodiments of the present application. Figure 8 The second tracing node is provided in the embodiments of the present application. Figure 1 As shown in the figure, in the embodiments of the present application, the second tracing node comprises: Figure 8

[0157] The second communication module 501 is configured to establish a communication connection after mutual identity authentication with the first tracing node, and receive tracing task details of a network attack event sent by the first tracing node;

[0158] The second processing module 502 is configured to trace the network attack event based on the tracing task details to obtain tracing result information of the network attack event.

[0159] In an embodiment of the present application, the tracing result information is encrypted by a private key of the second tracing node, and the second processing module 502 is configured to decrypt the tracing task details by using the private key of the second tracing node.

[0160] In an embodiment of the present application, the second processing module 502 is configured to distribute the tracing task details to a tracing service connected to the second tracing node; and retrieve associated data sources based on the tracing task details by the tracing service to obtain the tracing result information.

[0161] In an embodiment of the present application, the second tracing node supports a task requirement indicated by the tracing task information, and the second communication module 501 is further configured to receive, through a center node, tracing task information of the network attack event sent by the first tracing node; and send, to the center node, response information to the tracing task information.

[0162] In an embodiment of the present application, the second communication module 501 is further configured to send the tracing result information to the first tracing node.

[0163] In an embodiment of the present application, the second processing module 502 is further configured to encrypt the tracing result information by using a private key of the second tracing node.

[0164] In an embodiment of the present application, the second communication module 501 is further configured to receive, through a center node, reward evaluation information of the second tracing node sent by the first tracing node; wherein the reward evaluation information is determined by the first tracing node based on the tracing result information.

[0165] ​The second processing module 502 is further configured to perform node evaluation on the first traceability node based on the reward evaluation information, and generate node evaluation information of the first traceability node.

[0166] The second communication module 501 is further configured to send the node evaluation information to the center node.

[0167] Figure 9 A structure of a second traceability node provided in an embodiment of the present application Figure 2 As shown in Figure 9 in an embodiment of the present application, the second traceability node comprises a second processor 601, a second memory 602 and a second communication bus 603.

[0168] The second communication bus 603 is configured to realize communication connection between the second processor 601 and the second memory 602.

[0169] The second processor 601 is configured to execute one or more computer programs stored in the second memory 602, so as to realize the attack traceability method applied to the second traceability node.

[0170] An embodiment of the present application provides a center node. Figure 10 A structure of a center node provided in an embodiment of the present application Figure 1 As shown in Figure 10 in an embodiment of the present application, the center node comprises:

[0171] The third communication module 701 is configured to receive the traceability task information of the network attack event sent by the first traceability node, and send the traceability task information to different traceability nodes.

[0172] The third processing module 702 is configured to determine a second traceability node for the network attack event based on the response information of the traceability task information sent by at least one traceability node.

[0173] In an embodiment of the present application, the third processing module 702 is further configured to determine one or more traceability nodes as the second traceability node based on the order of the sent response information and the node score of the at least one traceability node.

[0174] In an embodiment of the present application, the third communication module 701 is further configured to send indication information to the first traceability node, wherein the indication information is used to indicate that the second traceability node is a traceability node for the network attack event.

[0175] In an embodiment of the present application, the third communication module 701 is further configured to receive reward evaluation information of the second traceability node sent by the first traceability node, wherein the reward evaluation information is determined by the first traceability node based on the traceability result information of the network attack event by the second traceability node.

[0176] The third processing module 702 is further configured to update the node score of the second traceability node based on the reward evaluation information.

[0177] In an embodiment of the present application, the third communication module 701 is further configured to send the reward evaluation information to the second traceability node and receive node evaluation information of the first traceability node sent by the second traceability node, wherein the node evaluation information is determined by the second traceability node based on the reward evaluation information.

[0178] The third processing module 702 is further configured to update the node score of the first traceability node based on the node evaluation information.

[0179] Figure 11 A structure of a center node provided in an embodiment of the present application Figure 2 As shown in FIG. 8, in an embodiment of the present application, the center node includes a third processor 801, a third memory 802 and a third communication bus 803. Figure 11

[0180] The third communication bus 803 is configured to realize the communication connection between the third processor 801 and the third memory 802.

[0181] The third processor 801 is configured to execute one or more computer programs stored in the third memory 802 to realize the attack traceability method applied to the center node.

[0182] An embodiment of the present application provides a computer program product including a computer program, which, when executed by a processor, realizes the steps of any of the above attack traceability methods.

[0183] ​The embodiments of the present application provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of any attack tracing method. The computer readable storage medium can be a volatile memory, such as a random-access memory (RAM), or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD). The computer readable storage medium can also be a device including one or any combination of the above memories, such as a mobile phone, a computer, a tablet device, a personal digital assistant, and the like.

[0184] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. In addition, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage, etc.) containing computer-usable program code.

[0185] The present application is described with reference to the implementation flowcharts and / or block diagrams of the method, device (system), and computer program product according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks Figure 1 The functions specified in one or more flows and / or blocks

[0186] These computer program instructions can also be stored in a computer readable memory capable of guiding the computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including instruction means, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks Figure 1 The functions specified in one or more flows and / or blocks

[0187] These computer program instructions can also be loaded into a computer or other programmable data processing devices, so that a series of operational steps are generated to realize the computer-implemented process, and the instructions executed on the computer or other programmable devices provide the functions specified in the flowchart Figure 1 or multiple flows and / or blocks Figure 1 or multiple blocks or steps of the functions specified in the flowchart

[0188] The above description is merely one specific implementation of the application. However, it is to be understood that the application is not limited in its application to the details indicated above, but is capable of carrying out various changes or modifications. Accordingly, other implementations of the application are possible. Therefore, the scope of the application should be determined by the following claims.

Claims

1. An attack tracing method, characterized in that, Applied to a first traceability node, the method comprises: When a network attack event occurs in a traceability service connected to the first traceability node, sending traceability task information of the network attack event to a central node to be sent to different traceability nodes through the central node; wherein the central node is used to determine a second traceability node for tracing the network attack event based on response information of the traceability task information from at least one traceability node; After mutual identity authentication with the second traceability node, a communication connection is established, and traceability task details of the network attack event are sent to the second traceability node to trace the network attack event through the second traceability node.

2. The method of claim 1, wherein, Before the traceability task details of the network attack event are sent to the second traceability node, the method further comprises: The traceability task details are encrypted using a public key of the second traceability node.

3. The method of claim 1, wherein, Before the communication connection with the second traceability node is established, the method further comprises: Receiving indication information sent by the central node; wherein the indication information is used to indicate that the second traceability node is a traceability node for tracing the network attack event.

4. The method of claim 1, wherein, After the traceability task details of the network attack event are sent to the second traceability node, the method further comprises: Receiving traceability result information of the network attack event sent by the second traceability node; Evaluating the traceability result information to generate reward evaluation information of the second traceability node; Sending the reward evaluation information to the central node.

5. The method of claim 4, wherein, The traceability result information is encrypted by a private key of the second traceability node, and before the traceability result information is evaluated, the method further comprises: The traceability result information is decrypted using a public key of the second traceability node.

6. A method of attack attribution, comprising: Applied to a central node, the method comprises: Receiving traceability task information of a network attack event sent by a first traceability node, and sending the traceability task information to different traceability nodes; Determining a second traceability node for tracing the network attack event based on response information of the traceability task information sent by at least one traceability node; Wherein the second traceability node is used to establish a communication connection after mutual identity authentication with the first traceability node, receive traceability task details of the network attack event sent by the first traceability node, and trace the network attack event.

7. The method of claim 6, wherein, The determination of the second traceability node for tracing the network attack event based on the response information of the traceability task information sent by at least one traceability node comprises: For the at least one traceability node, one or more traceability nodes are determined as the second traceability node based on the order of the sent response information and the node score.

8. The method of claim 6, wherein, After the second traceability node for tracing the network attack event is determined, the method further comprises: Sending indication information to the first traceability node; wherein the indication information is used to indicate that the second traceability node is a traceability node for tracing the network attack event.

9. The method of claim 6, wherein, After the second traceability node for tracing the network attack event is determined, the method further comprises: receive reward evaluation information of the second traceability node sent by the first traceability node; wherein the reward evaluation information is determined by the first traceability node based on the traceability result information of the second traceability node on the network attack event; update the node score of the second traceability node based on the reward evaluation information.

10. The method of claim 9, wherein, After the receiving the reward evaluation information of the second traceability node sent by the first traceability node, the method further comprises: send the reward evaluation information to the second traceability node, and receive node evaluation information of the first traceability node sent by the second traceability node; wherein the node evaluation information is determined by the second traceability node based on the reward evaluation information; update the node score of the first traceability node based on the node evaluation information.

11. An attack attribution method, characterized in that, Applied to the second traceability node, the method comprises: establish a communication connection after mutual identity verification with the first traceability node, and receive traceability task details of a network attack event sent by the first traceability node; trace the network attack event based on the traceability task details, and obtain traceability result information of the network attack event; wherein the second traceability node is determined by a center node based on response information of at least one traceability node on traceability task information of the network attack event, and the traceability task information is sent by the first traceability node to the center node.

12. The method of claim 11, wherein, The traceability task details are encrypted by a public key of the second traceability node, and before the tracing the network attack event based on the traceability task details, the method further comprises: decrypt the traceability task details by using a private key of the second traceability node.

13. The method of claim 11, wherein, The tracing the network attack event based on the traceability task details, and obtaining the traceability result information of the network attack event, comprises: distribute the traceability task details to a traceability service connected to the second traceability node; retrieve associated data sources to obtain the traceability result information based on the traceability task details through the traceability service.

14. The method of claim 11, wherein, The second traceability node supports task requirements indicated by the traceability task information, and before the establishing a communication connection after mutual identity verification with the first traceability node, the method further comprises: receive traceability task information of the network attack event sent by the first traceability node through the center node; send response information on the traceability task information to the center node.

15. The method of claim 11, wherein, After the obtaining the traceability result information of the network attack event, the method further comprises: send the traceability result information to the first traceability node.

16. The method of claim 15, wherein, Before the sending the traceability result information to the first traceability node, the method further comprises: encrypt the traceability result information by using a private key of the second traceability node.

17. The method of claim 15, wherein, After the sending the traceability result information to the first traceability node, the method further comprises: receive reward evaluation information of the second traceability node sent by the first traceability node through the center node; wherein the reward evaluation information is determined by the first traceability node based on the traceability result information; performing node evaluation on the first traceability node based on the reward evaluation information, and generating node evaluation information of the first traceability node; sending the node evaluation information to the center node.

18. A first provenance node, comprising: comprising: a first processor, a first memory, and a first communication bus; the first communication bus is configured to realize communication connection between the first processor and the first memory; the first processor is configured to execute one or more computer programs stored in the first memory, so as to realize the attack traceability method in any one of claims 1-5.

19. A second traceability node, characterized in that, comprising: a second processor, a second memory, and a second communication bus; the second communication bus is configured to realize communication connection between the second processor and the second memory; the second processor is configured to execute one or more computer programs stored in the second memory, so as to realize the attack traceability method in any one of claims 11-17.

20. A central node, characterized by comprising: a third processor, a third memory, and a third communication bus; the third communication bus is configured to realize communication connection between the third processor and the third memory; the third processor is configured to execute one or more computer programs stored in the third memory, so as to realize the attack traceability method in any one of claims 6-10.

21. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the attack traceability method in any one of claims 1-17.

22. A computer program product comprising a computer program, characterised in that, The computer program is executed by the processor to realize the attack traceability method in any one of claims 1-17.

Citation Information

Patent Citations

  • Attack tracing method and system for power industrial control network

    CN110336808A

  • Network attack event traceability processing method and device, equipment and storage medium

    CN111935192A