An expert knowledge assisted construction APT spying action monitoring system and method
The APT data theft monitoring system, built with the assistance of expert knowledge, solves the problem of low efficiency in APT attack analysis and judgment that relies on experts. It enables real-time application and tool-based support of expert knowledge, thereby improving the efficiency and accuracy of network security defense.
Patent Information
- Application Number
- CN202411112316.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-14
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-08-14
AI Technical Summary
The analysis and assessment of APT attacks in existing technologies rely on practical experts, which is inefficient and cannot be applied in real time, resulting in passive defense and a lack of effective tools.
Design an APT (Advanced Persistent Threat) data theft monitoring system assisted by expert knowledge, including a rule building module, a script generation module, an APT analysis and judgment module, an APT profiling module, an APT rule base module, and an APT example library module. By transforming the experience of cybersecurity experts into automated rules and visual displays, the system enables real-time application and tool-based support of expert knowledge.
It has improved the security defense coefficient, reduced reliance on experts, increased the efficiency and accuracy of analysis and judgment, and enhanced the initiative and training support for network security defense.
Smart Images

Figure CN118944944B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of APT threat monitoring technology, specifically to an APT espionage monitoring system and method constructed with the assistance of expert knowledge. Background Technology
[0002] Currently, highly persistent and covert APT attacks have become a crucial area of national cybersecurity countermeasures. my country faces a particularly severe situation with numerous and complex sources of risk. These attacks target government agencies, universities, military institutions, and enterprises on a large scale, over extended periods, and systematically. They are characterized by long latency periods, numerous backdoor exploits, and widespread deployment of jump servers, often aiming to steal critical data and posing serious threats to national defense, critical infrastructure security, financial security, and citizens' personal information.
[0003] The analysis and assessment of APT attacks for data theft in existing technologies have the following problems:
[0004] First, it requires APT experts to perform professional analysis of large amounts of data, and this is usually done after an APT attack occurs. As a result, the expert knowledge of APT analysis and judgment cannot be applied to the network environment in real time, leaving the network in a passive defense state.
[0005] Secondly, the analysis and assessment of APTs relies excessively on practical experts, and there are no effective tools or systems to support the analysis of common APT attack methods. This leads to experts being overworked and the efficiency of analysis and assessment being low. In wartime conditions, it is unable to effectively support wartime analysis.
[0006] Based on the above reasons, this invention designs an APT espionage monitoring system and method that is constructed with the assistance of expert knowledge. It can provide the experience and knowledge of network security experts to operation and maintenance personnel in a tool-like manner, greatly improve the security defense coefficient, effectively reduce the over-reliance on experts, and effectively deliver expert capabilities to the network defense system. Summary of the Invention
[0007] The purpose of this invention is to overcome the shortcomings of the prior art and provide an APT espionage monitoring system and method that is built with the assistance of expert knowledge. This system can provide the experience and knowledge of network security experts to operation and maintenance personnel in a tool-like manner, greatly improve the security defense coefficient, effectively reduce the over-reliance on experts, and effectively deliver expert capabilities to the network defense system.
[0008] To achieve the above objectives, the present invention provides an APT espionage monitoring system constructed with the assistance of expert knowledge, including a rule construction module, a script generation module, an APT analysis and judgment module, an APT profiling module, an APT rule base module, and an APT example library module;
[0009] The rule building module sets different instrumentation rules, data filtering rules, and security behavior baselines based on different terminal business applications to be monitored;
[0010] The script generation module generates script programs that can be compiled and executed by terminal devices from the instrumentation rules, data filtering rules, and security behavior baselines formulated by cybersecurity experts. These scripts are, in order, the instrumentation rule script, the data filtering rule script, and the behavior baseline script.
[0011] The APT analysis and judgment module provides analysis and judgment rules, which are based on the global network perspective and cover all terminal business applications within the network.
[0012] The APT profiling module provides visualized results of APT attack analysis, displaying APT attack profiles in the form of knowledge graphs.
[0013] The APT rule base module stores instrumentation rules, data filtering rules, security behavior baselines, and analysis and judgment rules. Cybersecurity personnel can directly use existing rules to issue them in order to monitor APT attack behavior.
[0014] The APT example library module provides existing APT case analysis functions, simulating and reproducing APT attack paths for network security personnel to learn and train, thereby improving their APT attack analysis and judgment capabilities.
[0015] The specified steps for the rule building module are as follows:
[0016] S2-1, Experts formulate instrumentation rules for the business application of the terminal to be monitored, which are the entry function of the business application and the function call stack during program execution;
[0017] S2-2, Experts conduct a preliminary analysis of the program, formulate instrumentation rules for the terminal business application, and formulate data filtering rules for the business application;
[0018] S3-3: Based on the application results of instrumentation rules and data filtering rules, experts formulate the behavioral baseline rules for this business application.
[0019] The scripting program includes Python scripts, LUA scripts, FDS scripts, NASL scripts, and PIT scripts. An expert-knowledge-assisted method for detecting APT (Aggressive Phantom Threat) espionage activities includes the following steps:
[0020] S4-1, experts develop rule building modules through instrumentation rules, data filtering rules, and security behavior baselines;
[0021] S4-2, Experts develop an APT analysis and judgment module based on analysis and judgment rules from a global network perspective;
[0022] S4-3, the APT analysis and assessment module constructs an APT profile module using knowledge graphs based on the analysis and assessment results; the APT analysis and assessment module, together with cybersecurity personnel, develops an APT rule base module based on the analysis and assessment rules.
[0023] S4-4, the APT profiling module generates an APT example library module through analysis and judgment; the APT example library module then feeds information back to cybersecurity personnel.
[0024] S4-5, the rule building module is an APT rule base module that develops rules based on instrumentation rules, data filtering rules, and security behavior baselines;
[0025] S4-6, the rule building module and the APT rule base module jointly formulate a script generation module based on instrumentation rules, data filtering rules and security behavior baselines. The script generation module monitors the business applications of each terminal to be monitored according to the instrumentation rules, data filtering rules and security behavior baselines.
[0026] Compared with existing technologies, this invention transforms the knowledge and experience of cybersecurity experts into automated instrumentation rules, data filtering rules, and behavioral baselines through a rule-building module, enabling real-time application of expert knowledge. The automated architecture designed in this invention allows for the systematic and standardized organization of expert knowledge, reducing reliance on single experts and forming a technical system supporting experience reuse.
[0027] The script generation module of this invention transforms expert-defined rules into executable scripts, while the APT profiling module visualizes APT attack behaviors using a knowledge graph. This invention's method, combining script automation and visual analysis, enables operations and maintenance personnel to more intuitively understand and respond to APT attacks, improving the efficiency and accuracy of analysis and judgment, and also providing strong support for security training.
[0028] The APT rule base module and APT example library module of this invention provide a knowledge resource library. The rule base enables the rapid deployment of existing best practices and defense strategies, while the example library helps personnel learn and improve their ability to analyze and judge APT attacks by simulating and reproducing APT attack paths. The combined design of these two modules enhances the initiative in building network security defense capabilities. Attached Figure Description
[0029] Figure 1 This is a schematic diagram of the monitoring method of the present invention. Detailed Implementation
[0030] The present invention will now be further described with reference to the accompanying drawings.
[0031] join Figure 1This invention provides an APT (Advanced Persistent Threat) espionage monitoring system built with expert knowledge assistance.
[0032] It includes a rule building module, a script generation module, an APT analysis and judgment module, an APT profiling module, an APT rule base module, and an APT example library module;
[0033] The rule building module sets different instrumentation rules, data filtering rules, and security behavior baselines based on different terminal business applications to be monitored;
[0034] The script generation module generates script programs that can be compiled and executed by terminal devices from the instrumentation rules, data filtering rules, and security behavior baselines formulated by cybersecurity experts. These scripts are, in order, the instrumentation rule script, the data filtering rule script, and the behavior baseline script.
[0035] The APT analysis and judgment module provides analysis and judgment rules, which are based on the global network perspective and cover all terminal business applications within the network.
[0036] The APT profiling module provides visualized results of APT attack analysis, displaying APT attack profiles in the form of knowledge graphs.
[0037] The APT rule base module stores instrumentation rules, data filtering rules, security behavior baselines, and analysis and judgment rules. Cybersecurity personnel can directly use existing rules to issue them in order to monitor APT attack behavior.
[0038] The APT example library module provides existing APT case analysis functions, simulating and reproducing APT attack paths for network security personnel to learn and train, thereby improving their APT attack analysis and judgment capabilities.
[0039] The specified steps for the rule building module are as follows:
[0040] S2-1, Experts formulate instrumentation rules for the business application of the terminal to be monitored, which are the entry function of the business application and the function call stack during program execution;
[0041] S2-2, Experts conduct a preliminary analysis of the program, formulate instrumentation rules for the terminal business application, and formulate data filtering rules for the business application;
[0042] S3-3: Based on the application results of instrumentation rules and data filtering rules, experts formulate the behavioral baseline rules for this business application.
[0043] The scripting programs include Python scripts, LUA scripts, FDS scripts, NASL scripts, and PIT scripts. An expert-knowledge-assisted method for detecting APT (Aggressive Phantom Threat) espionage activities includes the following steps:
[0044] S4-1, experts develop rule building modules through instrumentation rules, data filtering rules, and security behavior baselines;
[0045] S4-2, Experts develop an APT analysis and judgment module based on analysis and judgment rules from a global network perspective;
[0046] S4-3, the APT analysis and assessment module constructs an APT profile module using knowledge graphs based on the analysis and assessment results; the APT analysis and assessment module, together with cybersecurity personnel, develops an APT rule base module based on the analysis and assessment rules.
[0047] S4-4, the APT profiling module generates an APT example library module through analysis and judgment; the APT example library module then feeds information back to cybersecurity personnel.
[0048] S4-5, the rule building module is an APT rule base module that develops rules based on instrumentation rules, data filtering rules, and security behavior baselines;
[0049] S4-6, the rule building module and the APT rule base module jointly formulate a script generation module based on instrumentation rules, data filtering rules and security behavior baselines. The script generation module monitors the business applications of each terminal to be monitored according to the instrumentation rules, data filtering rules and security behavior baselines.
[0050] The above are merely preferred embodiments of the present invention, intended only to aid in understanding the method and core ideas of this application. The scope of protection of the present invention is not limited to the above embodiments; all technical solutions falling within the scope of the present invention's concept are within its protection. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.
[0051] This invention comprehensively addresses the problems of existing technologies that rely on lagging manual analysis by experts in the analysis and judgment of APT attacks, resulting in a passive defense approach and low efficiency and high error rates due to the lack of supporting tools. By automating the application of expert knowledge, generating scripts, visualizing APT behavior, and constructing APT rule bases and example libraries, this invention enables real-time application of expert knowledge, reduces reliance on single experts, and forms a technical system supporting experience reuse. This allows operations and maintenance personnel to more intuitively understand and respond to APT attacks, improving the efficiency and accuracy of analysis and judgment. It also provides strong support for security training. Furthermore, by combining the APT rule base module and the APT example library module, this invention enhances the initiative in building network security defense capabilities.
Claims
1. An APT (Advanced Persistent Threat) espionage monitoring system constructed with expert knowledge assistance, characterized in that, It includes a rule building module, a script generation module, an APT analysis and judgment module, an APT profiling module, an APT rule base module, and an APT example library module; The rule building module sets different instrumentation rules, data filtering rules, and security behavior baselines according to different terminal business applications to be monitored; The script generation module generates script programs that can be compiled and executed by terminal devices from the instrumentation rules, data filtering rules, and security behavior baselines formulated by network security experts. These scripts are, in order, the instrumentation rule script, the data filtering rule script, and the behavior baseline script. The APT analysis and judgment module provides analysis and judgment rules, which are based on the global network perspective and cover all terminal business applications within the network. The APT profiling module provides visualized results of APT attack analysis, displaying APT attack profiles in the form of a knowledge graph. The APT rule base module stores instrumentation rules, data filtering rules, security behavior baselines, and analysis and judgment rules. Network security personnel can directly use existing rules to issue them in order to monitor APT attack behavior. The APT example library module provides existing APT case analysis functions, simulates and reproduces APT attack paths, and provides network security personnel with learning and training to improve their APT attack analysis and judgment capabilities.
2. The APT eavesdropping activity monitoring system constructed with expert knowledge assistance according to claim 1, characterized in that, The specified steps of the rule construction module are as follows: S2-1, Experts formulate instrumentation rules for the business application of the terminal to be monitored, which are the entry function of the business application and the function call stack during program execution; S2-2, Experts conduct a preliminary analysis of the program, formulate instrumentation rules for the terminal business application, and formulate data filtering rules for the business application; S3-3: Based on the application results of instrumentation rules and data filtering rules, experts formulate the behavioral baseline rules for this business application.
3. The APT eavesdropping activity monitoring system constructed with expert knowledge assistance according to claim 1, characterized in that, The scripting programs include Python scripts, LUA scripts, FDS scripts, NASL scripts, and PIT scripts.
4. A method for monitoring APT (Advanced Persistent Threat) espionage activities using expert knowledge-assisted construction, characterized in that, Includes the following steps: S4-1, experts develop rule building modules through instrumentation rules, data filtering rules, and security behavior baselines; S4-2, Experts develop an APT analysis and judgment module based on analysis and judgment rules from a global network perspective; S4-3, the APT analysis and assessment module constructs an APT profile module using knowledge graphs based on the analysis and assessment results; the APT analysis and assessment module, together with cybersecurity personnel, develops an APT rule base module based on the analysis and assessment rules. S4-4, the APT profiling module generates an APT example library module through analysis and judgment; the APT example library module then feeds information back to cybersecurity personnel. S4-5, the rule building module is an APT rule base module that develops rules based on instrumentation rules, data filtering rules, and security behavior baselines; S4-6, the rule building module and the APT rule base module jointly formulate a script generation module based on instrumentation rules, data filtering rules and security behavior baselines. The script generation module monitors the business applications of each terminal to be monitored according to the instrumentation rules, data filtering rules and security behavior baselines.
Citation Information
Patent Citations
APT attack clue expansion method and device based on hypergraph association
CN115208684A
Domain business auxiliary analysis method based on expert thinking model
CN115238197A