Network attack identification method, device and electronic equipment
By constructing a knowledge graph of network assets and generating attack detection rules, the problem of the inability to effectively correlate attack behaviors of specific assets in existing technologies is solved, enabling a comprehensive understanding of threats and attack scenarios of specific assets and improving network security protection capabilities.
Patent Information
- Application Number
- CN202410493358.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-23
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-04-23
AI Technical Summary
Existing technologies cannot effectively correlate attacks on specific assets, resulting in an inability to fully understand the threats and attack scenarios they face.
By acquiring network security data of network assets, a knowledge graph is constructed, and detection rules are transformed to generate attack detection rules. The detection rules are used to determine whether the characteristics of the rules correctly identify attack behaviors or abnormal behaviors, and attack subgraphs are generated for different network assets.
It enables effective correlation of attack behaviors against specific assets, provides a comprehensive understanding of the threats and attack scenarios they face, and improves network security protection capabilities.
Smart Images

Figure CN118802300B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a network attack identification method and device and electronic equipment. BACKGROUND
[0002] With the continuous development of network technology, network security problems are increasingly prominent, and various network attack means emerge in endlessly. In order to improve the network security protection capability, it is necessary to deeply analyze and mine network security data to predict and avoid future network attacks.
[0003] The prior art mainly stores network security data in different relational databases, performs association query through the relational databases, and monitors activities in the system or network by using attack detection rules to discover potential attack behaviors in time.
[0004] However, the existing attack detection rules for monitoring activities in the system or network cannot effectively associate attack behaviors of specific assets, thereby failing to comprehensively understand the threats and attack scenarios faced by specific assets. SUMMARY
[0005] Therefore, the present application provides a network attack identification method and device and electronic equipment, which mainly aims to solve the technical problem that attack behaviors of specific assets cannot be effectively associated, thereby failing to comprehensively understand the threats and attack scenarios faced by specific assets.
[0006] According to a first aspect of the present disclosure, a network attack identification method is provided, which comprises:
[0007] Obtaining network security data of a network asset, constructing a knowledge graph of the network asset based on the network security data, and performing detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules;
[0008] Detecting whether the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and detecting whether the rule coverage of the attack detection rules meets the expected detection target;
[0009] If the rule features can correctly identify attack behaviors or abnormal behaviors, and the rule coverage meets the expected detection target, attack subgraphs for different network assets are generated based on the attack detection rules, and network attacks against different network assets are identified by using multiple attack subgraphs.
[0010] According to a second aspect of the present disclosure, a network attack identification device is provided, which comprises:
[0011] An acquisition module is configured to acquire network security data of a network asset, construct a knowledge graph of the network asset based on the network security data, and perform detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules;
[0012] A detection module is configured to detect whether a rule feature of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and whether a rule coverage range of the attack detection rules meets an expected detection target;
[0013] An identification module is configured to generate attack subgraphs for different network assets based on the attack detection rules if the rule feature can correctly identify attack behaviors or abnormal behaviors and the rule coverage range meets the expected detection target, so as to identify network attacks on different network assets by using multiple attack subgraphs.
[0014] According to a third aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory connected to the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of the first aspect.
[0015] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable a computer to perform the method of the first aspect.
[0016] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the method of the first aspect.
[0017] The network attack identification method, device and electronic equipment provided by the present disclosure can correctly identify attack behaviors or abnormal behaviors through the attack detection rules, and the rule coverage range of the attack detection rules meets the expected detection target, so that the attack subgraphs for different network assets are generated based on the attack detection rules, and the network attacks on different network assets are identified by using the multiple attack subgraphs. For the present disclosure, if the rule characteristics of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and the rule coverage range of the attack detection rules meets the expected detection target, the attack subgraphs for different network assets are generated by using different types of attack detection rules, and the network attacks on different network assets are identified by using the multiple attack subgraphs, so that the attack behaviors on specific assets can be effectively associated, and the threats and attack scenes faced by the specific assets can be comprehensively understood.
[0018] The above description is only a summary of the technical solutions of the present application. In order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented according to the content of the specification, and in order to make the above and other purposes, characteristics and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0019] The accompanying drawings incorporated in the specification and forming a part thereof illustrate embodiments consistent with the present application and together with the description serve to explain the principles of the present application.
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.
[0021] Figure 1 The flowchart of the network attack identification method provided by the present disclosure is shown in the figure;
[0022] Figure 2 The flowchart of another network attack identification method provided by the present disclosure is shown in the figure;
[0023] Figure 3 The flowchart of another network attack identification method provided by the present disclosure is shown in the figure;
[0024] Figure 4A structural schematic diagram of a network attack identification device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0025] Exemplary embodiments of the present disclosure are described below with reference to the accompanying drawings, which include various details of the embodiments of the present disclosure to assist in understanding, which should be considered in their context only. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Also, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.
[0026] A network attack identification method, device and electronic equipment of an embodiment of the present disclosure are described below with reference to the accompanying drawings.
[0027] The present disclosure provides a network attack identification method, device and electronic equipment, which identifies network attacks against different network assets by using multi-class attack sub-graphs, so that attack behaviors against specific assets can be effectively associated, thereby comprehensively understanding the threats and attack scenarios faced by specific assets.
[0028] As shown in Figure 1 The embodiment of the present disclosure provides a network attack identification method, which comprises:
[0029] Step 101, obtaining network security data of a network asset, constructing a knowledge graph of the network asset based on the network security data, and performing detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules.
[0030] The network asset can be valuable information and technical resources in an organization network, which can include servers, workstations, routers, switches, application programs, data storage, websites, etc.
[0031] The network security data can be an important indicator for evaluating and monitoring the state of the network asset, which can include terminal logs, network traffic logs, alarm logs and other network security data, to evaluate the effectiveness and health status of the network asset, and timely discover potential security threats and vulnerabilities, so as to take corresponding protection measures.
[0032] The knowledge graph can be a structured knowledge representation method, which can organize and integrate information in the form of graphs. In the field of network security, the knowledge graph can include entities such as network assets, users, attack types, vulnerabilities, security events, and various relationships between these entities (such as connections between assets, associations between attacks and assets, user behavior paths, etc.), to help analyze complex network security data.
[0033] The attack detection rule can be a set of indications or criteria for identifying and defending against malicious activities, and can be used to define what network activities should be marked as potential attack activities.
[0034] For the embodiments of the present disclosure, network security data of a network asset can be acquired first, a knowledge graph of the network asset can be constructed based on the network security data, and rule conversion processing can be performed based on the knowledge graph to generate corresponding attack detection rules.
[0035] Step 102, whether the rule feature of the attack detection rule can correctly identify attack behavior or abnormal behavior is detected, and whether the rule coverage of the attack detection rule meets the expected detection target is detected.
[0036] For the embodiments of the present disclosure, whether the attack detection rule meets the qualified condition can be judged, in the case that the rule feature of the attack detection rule is qualified and the rule coverage of the attack detection rule is qualified, it is determined that the attack detection rule meets the qualified condition.
[0037] Specifically, whether the rule feature of the attack detection rule is qualified can be judged by detecting whether the rule feature of the attack detection rule can correctly identify attack behavior or abnormal behavior, if the rule feature of the attack detection rule can correctly identify attack behavior or abnormal behavior, it is determined that the rule feature of the attack detection rule is qualified, otherwise it is not qualified.
[0038] Whether the rule coverage of the attack detection rule is qualified can be judged by detecting whether the rule coverage of the attack detection rule meets the expected detection target, if the rule coverage of the attack detection rule meets the expected detection target, it is determined that the rule coverage of the attack detection rule is qualified, otherwise it is not qualified.
[0039] Step 103, if the rule feature can correctly identify attack behavior or abnormal behavior and the rule coverage meets the expected detection target, attack subgraphs for different network assets are generated based on the attack detection rule, so as to identify network attacks against different network assets by using multiple attack subgraphs.
[0040] Among them, the attack subgraph can be part of a specific graph in the knowledge graph, which can be used to represent the relationship between a specific attack type and a network asset.
[0041] The attack subgraph can include attack source, attack path, target asset and attack mode, etc., wherein the attack source can be an asset that initiates an attack, such as an IP address, a user account, etc.; the attack path can be the path from the attack initiation point to the target asset, which can include multiple intermediate assets and communication links; the target asset can be an asset that is attacked, such as a server, a database or other network devices, etc.; the attack mode can be the characteristics and mode of the attack, such as the use of a specific protocol, an abnormal traffic pattern, etc.
[0042] For the embodiments of the present disclosure, as a possible implementation method, the attack subgraph can be separated from the knowledge graph based on the qualified attack detection rule to generate attack subgraphs for different network assets, so that the details of the attack can be more clearly seen without browsing the entire complex network knowledge graph, thereby more effectively identifying and responding to network attacks on different network assets.
[0043] In summary, compared with the prior art, the network attack identification method of the present disclosure acquires network security data of network assets, constructs a knowledge graph of the network assets based on the network security data, and performs detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules; detects whether the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and whether the rule coverage of the attack detection rules meets the expected detection target; if the rule features can correctly identify attack behaviors or abnormal behaviors, and the rule coverage meets the expected detection target, attack subgraphs for different network assets are generated based on the attack detection rules to identify network attacks on different network assets using multiple attack subgraphs. For the present disclosure scheme, if the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and the rule coverage of the attack detection rules meets the expected detection target, attack subgraphs for different network assets are generated using different types of attack detection rules, and network attacks on different network assets are identified using multiple attack subgraphs, so that attack behaviors on specific assets can be effectively associated, and the threats and attack scenarios faced by specific assets can be comprehensively understood.
[0044] Further, as a refinement and extension of the above-mentioned embodiments, in order to fully describe the specific implementation process of the present embodiment method, the present embodiment provides a specific method as shown in Figure 2 The method comprises the following steps:
[0045] Step 201, extract key entities from network security data to use the key entities as key nodes of the knowledge graph; extract the mutual relationship between the key entities from the network security data to use the mutual relationship as the key edges between the key nodes in the knowledge graph; extract the attribute information of the key entities from the network security data to use the attribute information as the node features of the key nodes in the knowledge graph.
[0046] The knowledge graph comprises a plurality of key nodes, key edges between the plurality of key nodes, and node features corresponding to the plurality of key nodes.
[0047] For the embodiments of the present disclosure, as shown in Figure 3 The network security data can be processed by entity extraction, relationship extraction, attribute extraction, and data layer fusion to construct a knowledge graph for network assets.
[0048] The entity extraction processing can be to identify and extract key entities such as hosts, processes, IPs, ports, files, registries, named pipes, etc. from the network security data, and assign unique identifiers to the key entities for representation as key nodes in the knowledge graph.
[0049] The relationship extraction processing can be to identify the interactions or associations between key entities from the network security data. In the security knowledge graph, the interactions or associations can include behaviors such as process operating registries, process operating files, and process injection, etc. to form key edges in the knowledge graph.
[0050] The attribute extraction processing can be to extract specific attributes (i.e. attribute information) of key entities from the network security data, such as file creation time, modification time, size, etc. The attribute information is used as node features of key nodes in the knowledge graph to provide more detailed descriptions of key entities and enhance the richness of the knowledge graph.
[0051] The data layer fusion processing can be to integrate and fuse key entities extracted from network security data from different sources to eliminate redundancies and conflicts in the data and improve the quality and usability of the knowledge graph.
[0052] In step 202, the alarm rules are formulated based on the knowledge graph, and quality check processing is performed on the alarm rules to ensure that the rule features in the alarm rules can correctly identify attack behaviors or abnormal behaviors. It is determined whether the required fields of the alarm rules that pass the quality check are in the knowledge graph to generate attack detection rules.
[0053] The alarm rules can be rules formulated based on known attack patterns and attack behavior features to issue an alarm when similar activities are detected. The alarm rules can include specific IP addresses, port communications, abnormal access patterns, known vulnerability exploits, etc.
[0054] For the embodiments of the present disclosure, as shown in Figure 3 The detection rules can be converted based on the knowledge graph to convert the formulated alarm rules into query statements that can be executed in a graph database. The query statement can be a Cypher statement.
[0055] The Cypher statement can be a language for graph database queries and operations that allows users to query and manipulate data in a graphical manner.
[0056] For the embodiments of the present disclosure, as shown in Figure 3As shown, the conversion rule for converting the formulated alarm rule into a query statement executable in the graph database can be divided into four parts, which are rule quality check, rule field analysis, rule field mapping, and rule conversion into Cypher statement.
[0057] In the embodiment, the rule quality check can be used to detect whether the rule feature of each alarm rule can correctly identify attack behavior or abnormal behavior, so as to determine whether the rule feature judgment of the alarm rule is accurate.
[0058] In the embodiment, as a possible implementation method, the quality check processing of the alarm rule can be to first check whether the alarm rule conforms to the preset syntax logic of the type of rule, otherwise the alarm rule will not be correctly parsed or executed. For example, when a sigma rule is written, it is necessary to ensure that the sigma rule follows the syntax format of sigma.
[0059] Among them, the preset syntax logic can be the corresponding type of syntax rule that each alarm rule must follow.
[0060] If the alarm rule conforms to the preset syntax logic, it can be evaluated whether the attack behavior vector or abnormal behavior vector detected by the alarm rule conforms to the expected target, and whether the rule range of the alarm rule conforms to the expected target, so as to regularly obtain information from multiple threat intelligence sources, understand the current attack trend and threat vector, and optimize the rule to cover emerging threats.
[0061] If the attack behavior vector or abnormal behavior vector of the alarm rule conforms to the expected target, and the rule range of the alarm rule conforms to the expected target, it is determined that the rule feature in the alarm rule can correctly identify attack behavior or abnormal behavior.
[0062] In the embodiment, as a possible implementation method, whether the attack behavior vector or abnormal behavior vector of the alarm rule conforms to the expected target can be calculated by calculating the quality score value of the alarm rule to preliminarily judge the good or bad of the alarm rule.
[0063] In the embodiment, the rule field analysis can be to judge whether the required field of the alarm rule that passes the quality check is in the knowledge graph. If the required field of the alarm rule that passes the quality check is not in the knowledge graph, it is judged whether there is other field in the knowledge graph that can replace the required field. If there is no other field in the knowledge graph to replace the required field, the alarm rule is adjusted to match the available field in the knowledge graph.
[0064] The rule field mapping can be that, if the required field of the alarm rule passing the quality check is in the knowledge graph, the required field is mapped to the attribute information of the corresponding key entity of the knowledge graph, to establish a mapping relationship between the required field in the alarm rule and the attribute information of the key entity in the knowledge graph.
[0065] Finally, the rule conversion to a Cypher statement can be that, according to different rule syntaxes and Cypher syntaxes, the required field after the field mapping is converted into a query statement (i.e. a Cypher statement), to generate an attack detection rule.
[0066] For the embodiments of the present disclosure, since poor quality of the Cypher query statement can cause problems such as low query performance, inaccurate results, and excessive memory consumption, the quality of the Cypher query statement needs to be checked.
[0067] Among them, the key factors affecting the performance of the Cypher query statement are:
[0068] Data size: When the data volume is large, executing complex queries can have a significant impact on performance. Therefore, optimizing the query statement is particularly important when running on large data sets.
[0069] Query complexity: The complexity of the query includes various operations in the query statement, such as pattern matching, traversal depth, number of nodes and relationships involved, etc. These factors can all cause the query to take longer.
[0070] Structure and syntax of the query statement: The structure and syntax of the query statement will affect the query time. Optimizing the structure of the query statement, avoiding unnecessary operations and redundancies, can improve the query performance.
[0071] Parameterized query: Avoid using string concatenation to improve the execution efficiency of the query and prevent potential security problems.
[0072] Hardware resources and configuration: Finally, the hardware resources allocated to the database and the configuration of the database itself also affect the query performance. Ensuring sufficient hardware resources and appropriate configuration can ensure that the Cypher query can run efficiently.
[0073] When the query has no results for more than half an hour, or the query statement execution time exceeds the expected time, it is usually a sign that there are serious problems with the query statement performance. The Cypher statement can be optimized from the following aspects:
[0074] 1. Using indexes can improve query performance and reduce the overhead of data traversal and comparison. The specific method is to create indexes for properties frequently used for matching and filtering in queries, using the "CREATE INDEX" statement to create;
[0075] 2. Use appropriate conditions and filters to limit the amount of data returned, add "WHERE" and "LIMIT" to the statement;
[0076] 3. Simplify query logic, avoid unnecessary multiple nesting and repeated operations, use subqueries or WITH clauses to decompose and combine queries to improve readability and execution efficiency;
[0077] 4. Use relational pattern caching, which caches query patterns and results in memory to improve the performance of repeated queries;
[0078] 5. Neo4j configuration and hardware resources, adjust the configuration parameters of Neo4j, such as memory allocation, concurrent connection number, etc., increase hardware resources, and improve the concurrent processing capacity and overall performance of the query.
[0079] Through the above optimization operations of Cpyher statements, the specific attack subgraph is queried and saved in json format.
[0080] Step 203, detect whether the rule characteristics of the attack detection rule can correctly identify attack behavior or abnormal behavior.
[0081] For the embodiments of the present disclosure, whether the rule characteristics of the attack detection rule can correctly identify attack behavior or abnormal behavior is detected, specifically, the quality score value of the attack detection rule can be calculated by using a quality score calculation function Q(s, n), wherein the quality score calculation function can be used to represent the change of the quality score.
[0082] The quality score calculation function is as follows:
[0083]
[0084] In the formula, s can represent the detection quantity, n can represent the periodic frequency time, a can represent the alarm rate, b can represent the alarm accuracy, x can represent the alarm number, and y can represent the total flow package.
[0085] Among them, the detection quantity is used to represent the number of abnormalities or attacks detected in a period of time; the periodic frequency time (usually in seconds) is used to define the time interval of the quality of the attack detection rule; the alarm accuracy can be used to represent the ratio of correct identification as abnormal in all attack detection rules; the alarm number can be the total number of alarms issued by the attack detection rule in a period of time; and the total flow package can be the total number of all flow packages detected in the same period of time.
[0086] The quality score value can be calculated according to the test rule by periodically acquiring the alarm rate and the alarm accuracy rate to preliminarily judge the rule. If the quality score value is greater at a fixed time frequency, it means that the attack behavior or the abnormal (or threat) behavior is closer to the target attack behavior and the target abnormal (or threat) behavior. If the quality score value is greater than a preset quality score value, it is determined that the rule feature of the attack detection rule can correctly identify the attack behavior or the abnormal behavior, and the feature data at this frequency is selected as the next step of the object to be detected.
[0087] Correspondingly, the alarm rate, the alarm accuracy rate, the detection quantity and the detection frequency of the attack detection rule can be acquired.
[0088] The quality score value of the attack detection rule is calculated based on the alarm rate, the alarm accuracy rate, the detection quantity and the detection frequency.
[0089] If the quality score value is greater than a preset quality score value, it is determined that the rule feature of the attack detection rule can correctly identify the attack behavior or the abnormal behavior.
[0090] Step 204, detecting whether the rule coverage of the attack detection rule meets the expected detection target.
[0091] For the embodiment of the present disclosure, the attack behavior can appear in multiple forms. To cover different variants of attacks, a semantic analysis model can be used to perform semantic correlation analysis processing on the feature keywords corresponding to the attack detection rule, so as to reduce the conflict with normal activities. At the same time, a real attack sample is used for testing to ensure that the semantic analysis model can accurately capture the known attack features.
[0092] In the embodiment, whether the rule coverage of the attack detection rule meets the expected detection target is detected, which can specifically include:
[0093] The feature keywords corresponding to the attack detection rule are acquired, wherein the feature keywords are words or phrases used to represent attack behaviors or abnormal behaviors.
[0094] The semantic analysis model is used to perform semantic correlation analysis processing on the feature keywords to obtain a semantic set composed of the semantics or semantics corresponding to the feature keywords and the semantic combination of the feature keywords.
[0095] The keyword coverage rate in the semantic set is calculated. If the keyword coverage rate is greater than a preset coverage rate threshold, it is determined that the rule coverage of the attack detection rule meets the expected detection target. The keyword coverage rate is used to represent the coincidence proportion of the semantics or semantics in the semantic set and the actual attack behavior semantics or semantics.
[0096] Analyze the existing attack behavior description and case, extract the attack feature keywords, and evaluate whether the attack feature keywords can cover all possible attack behavior situations to ensure that the alarm rule can comprehensively identify various attack forms.
[0097] Verify the existing keywords and regular expression rules to check whether they can identify and cover the attack feature keywords extracted by the keyword analysis model. If the rules can identify and cover the keywords analyzed by the keyword analysis model, it can be considered that the system has the ability to accurately identify attack behavior. Specifically, the coverage rate of keywords (i.e., keyword coverage) in the set compared to the keywords corresponding to the attack behavior description and case can be calculated. When the keyword coverage rate is greater than the preset coverage threshold, it is considered that the attack detection rule coverage range is qualified (i.e., the attack detection rule coverage range meets the expected detection target), otherwise it is not qualified (i.e., the attack detection rule coverage range does not meet the expected detection target).
[0098] Combine the results of keyword analysis with other technologies (such as behavior analysis, anomaly detection, etc.) to comprehensively determine whether an attack has occurred, thereby improving the accuracy and reliability of attack detection.
[0099] Step 205, fuse the attack sub-graphs of multiple network assets to obtain an attack scene knowledge graph containing different network assets; and use the attack scene knowledge graph to identify network attacks against different network assets.
[0100] The attack scene knowledge graph can be an integrated graph of multiple network asset attack sub-graphs, which can be used to describe and analyze the entire attack scene.
[0101] For the embodiments of the present disclosure, after determining that the corresponding attack detection rule is qualified, the qualified attack detection rule is used to detect various alarm logs, and multiple attack sub-graphs are generated according to the alarm rules. By fusing the attack sub-graphs from different network asset perspectives, the details of the attack on the assets can be intuitively known, thereby constructing an attack scene knowledge graph containing different network assets, obtaining a more comprehensive attack view, and analyzing the attack scene knowledge graph to jointly analyze the attack pattern, attack intention, and attack strategy of the attacker, thereby making up for the deficiencies of the prior art in multi-dimensional analysis and correlation query, effectively defending against network attacks against different network assets, and improving the protection capability of network security.
[0102] In summary, compared with the prior art, the network attack identification method disclosed in the present application obtains network security data of a network asset, constructs a knowledge graph of the network asset based on the network security data, and performs detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules; detects whether the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and whether the rule coverage of the attack detection rules meets the expected detection target; if the rule features can correctly identify attack behaviors or abnormal behaviors, and the rule coverage meets the expected detection target, attack subgraphs for different network assets are generated based on the attack detection rules to identify network attacks against different network assets by using multiple attack subgraphs. For the present application, if the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and the rule coverage of the attack detection rules meets the expected detection target, attack subgraphs for different network assets are generated based on different types of attack detection rules, and network attacks against different network assets are identified by using multiple attack subgraphs, so that attack behaviors against specific assets can be effectively associated, and threats and attack scenarios faced by specific assets can be comprehensively understood.
[0103] Based on the specific implementation of the method shown in the above Figure 1 and Figure 2 The present application provides a network attack identification device, as shown in the above Figure 4 The device comprises an acquisition module 31, a detection module 32, and an identification module 33.
[0104] The acquisition module 31 is configured to obtain network security data of a network asset, construct a knowledge graph of the network asset based on the network security data, and perform detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules.
[0105] The detection module 32 is configured to detect whether the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and whether the rule coverage of the attack detection rules meets the expected detection target.
[0106] The identification module 33 is configured to, if the rule features can correctly identify attack behaviors or abnormal behaviors, and the rule coverage meets the expected detection target, generate attack subgraphs for different network assets based on the attack detection rules to identify network attacks against different network assets by using multiple attack subgraphs.
[0107] In a specific application scenario, the knowledge graph comprises a plurality of key nodes, a plurality of key edges between the key nodes, and a plurality of node features corresponding to the key nodes, and the acquisition module 31 can be configured to extract key entities from the network security data to use the key entities as the key nodes of the knowledge graph.
[0108] extracting mutual relationships between the key entities from the network security data to take the mutual relationships as key edges between the key nodes in the knowledge graph;
[0109] extracting attribute information of the key entities from the network security data to take the attribute information as node features of the key nodes in the knowledge graph.
[0110] In a specific application scenario, the obtaining module 31 can be configured to formulate an alarm rule based on the knowledge graph, and perform quality check processing on the alarm rule to ensure that a rule feature in the alarm rule can correctly identify an attack behavior or an abnormal behavior.
[0111] determine whether a required field of the alarm rule that passes the quality check is in the knowledge graph;
[0112] If the required field of the alarm rule that passes the quality check is in the knowledge graph, the required field is mapped to attribute information of a corresponding key entity of the knowledge graph, and the required field after field mapping is converted into a query statement to generate the attack detection rule.
[0113] In a specific application scenario, the obtaining module 31 can be configured to, if the required field of the alarm rule that passes the quality check is not in the knowledge graph, determine whether there is another field in the knowledge graph to replace the required field.
[0114] If there is no other field in the knowledge graph to replace the required field, the alarm rule is adjusted to match available fields in the knowledge graph.
[0115] In a specific application scenario, the detection module 32 can be configured to obtain an alarm rate, an alarm accuracy rate, a detection quantity, and a detection frequency of the attack detection rule.
[0116] calculate a quality score value of the attack detection rule based on the alarm rate, the alarm accuracy rate, the detection quantity, and the detection frequency.
[0117] If the quality score value is greater than a preset quality score value, it is determined that a rule feature of the attack detection rule can correctly identify an attack behavior or an abnormal behavior.
[0118] In a specific application scenario, the detection module 32 can be configured to obtain a feature keyword corresponding to the attack detection rule, wherein the feature keyword is a word or a phrase used to represent an attack behavior or an abnormal behavior.
[0119] The semantic association analysis model is used for semantic association analysis and processing of the feature keywords, so as to obtain a semantic set composed of the semantics corresponding to the feature keywords and the semantics corresponding to the associated combination of the feature keywords.
[0120] The keyword coverage in the semantic set is calculated, and if the keyword coverage is greater than a preset coverage threshold, it is determined that the rule coverage range of the attack detection rule meets the expected detection target, wherein the keyword coverage is used to represent the coincidence proportion of the semantics in the semantic set and the actual attack behavior semantics.
[0121] In a specific application scenario, the identification module 33 can be used for fusion processing of attack sub-graphs of multiple types of network assets to obtain an attack scenario knowledge graph containing different network assets.
[0122] The attack scenario knowledge graph is used to identify network attacks against different network assets.
[0123] It should be noted that other corresponding descriptions of each functional unit involved in the network attack identification device provided by the present disclosure can be referred to the corresponding descriptions in Figure 1 and Figure 2 , which will not be repeated here.
[0124] Based on the above methods as shown in Figure 1 and Figure 2 , accordingly, the present disclosure also provides a computer readable storage medium having a computer program stored thereon, which is executed by a processor to implement the above methods as shown in Figure 1 and Figure 2 .
[0125] Based on such understanding, the technical solutions of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a U disk, a mobile hard disk, etc.) and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of various implementation scenarios of the present disclosure.
[0126] Based on the above methods as shown in Figure 1 and Figure 2 , and the virtual device embodiment as shown in Figure 4 , in order to achieve the above purpose, the present disclosure further provides an electronic device which can be configured at the side of a vehicle (such as an electric vehicle) and includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to implement the above methods as shown in Figure 1 and Figure 2 .
[0127] Optionally, the above-mentioned entity device can further include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a WI-FI module, and the like. The user interface can include a display, an input unit such as a keyboard, and the like. Optionally, the user interface can further include a USB interface, a card reader interface, and the like. The network interface can optionally include a standard wired interface, a wireless interface (such as a WI-FI interface), and the like.
[0128] Those skilled in the art can understand that the above-mentioned entity device structure provided by the present disclosure does not constitute a limitation on the entity device, and can include more or fewer components, or combine certain components, or different component arrangements.
[0129] The storage medium can further include an operating system, a network communication module. The operating system is a program for managing hardware and software resources of the above-mentioned entity device, supporting the running of information processing programs and other software and / or programs. The network communication module is used to realize the communication between the components in the storage medium and the communication with other hardware and software in the information processing entity device.
[0130] Through the description of the above embodiments, those skilled in the art can clearly understand that the present disclosure can be realized by means of software plus necessary general hardware platforms, or by hardware. Compared with the prior art, the network attack identification method, device and electronic equipment provided by the present disclosure can obtain network security data of network assets, construct a knowledge graph of the network assets based on the network security data, and perform detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules; detect whether the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and whether the rule coverage range of the attack detection rules meets the expected detection target; if the rule features can correctly identify attack behaviors or abnormal behaviors, and the rule coverage range meets the expected detection target, then generate attack subgraphs for different network assets based on the attack detection rules, so as to identify network attacks against different network assets by using multiple types of attack subgraphs. For the present disclosure scheme, if the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and the rule coverage range of the attack detection rules meets the expected detection target, then attack subgraphs for different network assets are generated based on different types of attack detection rules, and network attacks against different network assets are identified by using multiple types of attack subgraphs, so that the attack behaviors of specific assets can be effectively associated, and the threats and attack scenarios faced by specific assets can be comprehensively understood.
[0131] It has to be noted that, in the present document, relational terms are intended only to convey a possible relationship between elements or
[0132] The above detailed description merely describes certain implementations of the disclosure, and is not intended to limit the scope of the disclosure. Various modifications to these implementations can be apparent to those of ordinary skill in the art, and the general principles defined herein can be applied to other implementations without departing from the spirit or scope of the disclosure. Accordingly, the disclosure is not to be restricted except as by the appended claims and their equivalents.
Claims
1. A method for identifying network attacks, characterized in that, The method includes: The system acquires network security data of network assets, constructs a knowledge graph of the network assets based on the network security data, and performs detection rule transformation processing based on the knowledge graph to generate corresponding attack detection rules. The detection function checks whether the rule features of the attack detection rule can correctly identify attack behavior or abnormal behavior, and whether the rule coverage of the attack detection rule meets the expected detection target. If the rule features can correctly identify attack behavior or abnormal behavior, and the rule coverage meets the expected detection target, then attack subgraphs for different network assets are generated based on the attack detection rules, so as to use multiple types of attack subgraphs to identify network attacks against different network assets.
2. The method according to claim 1, characterized in that, The knowledge graph includes multiple key nodes, key edges between the multiple key nodes, and node features corresponding to the multiple key nodes; The construction of the knowledge graph of the network assets based on the network security data includes: Key entities are extracted from the network security data and used as key nodes in the knowledge graph. Extract the relationships between the key entities from the network security data, and use these relationships as key edges between the key nodes in the knowledge graph; The attribute information of the key entities is extracted from the network security data, and the attribute information is used as the node features of the key nodes in the knowledge graph.
3. The method according to claim 1, characterized in that, The step of performing detection rule transformation based on the knowledge graph to generate corresponding attack detection rules includes: Alarm rules are formulated based on the knowledge graph, and the alarm rules are subjected to quality checks to ensure that the rule features in the alarm rules can correctly identify attack behavior or abnormal behavior. Determine whether the required fields of the alarm rules that passed the quality check are in the knowledge graph; If the required fields of the alarm rules that pass the quality check are in the knowledge graph, then the required fields are mapped to the attribute information of the corresponding key entities in the knowledge graph, and the required fields after field mapping are converted into query statements to generate the attack detection rules.
4. The method according to claim 3, characterized in that, Whether the required fields for determining whether an alarm rule that has passed the quality check are in the knowledge graph includes: If the required field of the alarm rule that passed the quality check is not in the knowledge graph, then determine whether there are other fields in the knowledge graph that can replace the required field; If no other field exists in the knowledge graph to replace the required field, the alarm rule is adjusted to match the available field in the knowledge graph.
5. The method according to claim 1, characterized in that, The detection of whether the rule features of the attack detection rule can correctly identify attack behavior or abnormal behavior includes: Obtain the alarm rate, alarm accuracy, number of detections, and detection frequency of the attack detection rules; The quality score of the attack detection rule is calculated based on the alarm rate, the alarm accuracy, the number of detections, and the detection frequency. If the quality score is greater than the preset quality score, then the rule features of the attack detection rule are determined to correctly identify attack behavior or abnormal behavior.
6. The method according to claim 1, characterized in that, The process of detecting whether the rule coverage of the attack detection rule meets the expected detection target includes: Obtain the feature keywords corresponding to the attack detection rules, wherein the feature keywords are words or phrases used to characterize attack behavior or abnormal behavior; The semantic association analysis of the feature keywords is performed using a semantic analysis model to obtain a semantic set consisting of the semantic meaning of the feature keyword and the semantic meaning of the associated combination of the feature keyword. Calculate the keyword coverage rate in the semantic set. If the keyword coverage rate is greater than a preset coverage threshold, then determine that the rule coverage of the attack detection rule meets the expected detection target. The keyword coverage rate is used to characterize the overlap ratio between the word meaning or semantics in the semantic set and the keyword meaning or semantics of the actual attack behavior.
7. The method according to claim 1, characterized in that, The method of identifying network attacks targeting different network assets using multiple types of attack subgraphs includes: By fusing attack subgraphs of multiple types of network assets, an attack scenario knowledge graph containing different network assets is obtained. The attack scenario knowledge graph is used to identify network attacks targeting different network assets.
8. A network attack identification device, the device comprising: The acquisition module is used to acquire network security data of network assets, construct a knowledge graph of the network assets based on the network security data, and perform detection rule transformation processing based on the knowledge graph to generate corresponding attack detection rules. The detection module is used to detect whether the rule features of the attack detection rule can correctly identify attack behavior or abnormal behavior, and to detect whether the rule coverage of the attack detection rule meets the expected detection target. The identification module is used to generate attack subgraphs for different network assets based on the attack detection rules if the rule features can correctly identify attack behavior or abnormal behavior and the rule coverage meets the expected detection target, so as to use multiple types of attack subgraphs to identify network attacks against different network assets.
9. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-7.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-7.
Citation Information
Patent Citations
Network attack prediction method and device based on knowledge graph
CN115296924A
Network attack security risk assessment system and method based on knowledge graph
CN116527288A