A method for mining covert attack behavior

By processing and analyzing attack intelligence data, generating the intensity factor of the fusion vector, and combining attack graph and classifier technology, the problem of insufficient adaptability of existing network attack detection methods to covert attacks is solved, and high-precision attack behavior prediction and identification is achieved.

CN119210812BActive Publication Date: 2025-09-26GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411277019.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-12
Publication Date
2025-09-26
Estimated Expiration
2044-09-12

AI Technical Summary

Technical Problem

Existing network attack detection methods are difficult to deal with hidden and complex attack behaviors, especially attacks with low periodicity or attack patterns that change over time. They have problems such as high false alarm rate, slow response speed and insufficient adaptability to new attack patterns.

Method used

By acquiring attack intelligence data, performing data normalization and information extraction, and using text vectorization and nonlinear transformation to generate the strength factor of the fusion vector, the initial attack graph and attention weight are combined, and a binary classifier is applied to select the focus entity from the related entities, and the prediction probability is calculated to mine hidden attack behaviors.

Benefits of technology

It improves the accuracy of network attack predictions, reduces the false alarm rate, can capture hidden patterns of attack behavior changes, and promptly discover new and highly concealed attack methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119210812B_ABST
    Figure CN119210812B_ABST
Patent Text Reader

Abstract

The present invention provides a method for mining covert attack behaviors, comprising: performing data normalization processing on attack intelligence data and performing information extraction to obtain attack information; performing text vectorization processing on the attack information to obtain a fusion vector, and performing nonlinear transformation based on the fusion vector to obtain an intensity factor; determining related entities, obtaining historical dependency information and non-historical dependency information of the related entities to calculate attention weights for selecting candidate entities; applying a binary classifier to determine a set of focused entities from the candidate entities; calculating the predicted probability of the focused entity set, regulating the predicted probability based on the classifier result of the binary classifier and the intensity factor to obtain a predicted entity, and obtaining the attack behavior corresponding to the predicted entity. Application of this method can optimize the assessment of the degree of attention of related entities and improve prediction accuracy; based on the attack information, an in-depth understanding of the changing patterns of attack behaviors can be achieved, capturing subtle periodic features therein, and timely discovering highly concealed attack methods.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network defense technology, and in particular to a method for mining covert attack behavior. Background Art

[0002] In the field of network defense, as attack methods become increasingly covert and complex, traditional detection methods are no longer able to cope with new, zero-day attacks. Commonly used detection technologies in the industry often suffer from high false positive rates, insufficient adaptability to new attack patterns, and limited ability to identify periodic attacks when facing highly insidious persistent threats. Existing detection technologies are particularly prone to low accuracy and slow response times for attacks with low periodicity, or attacks that exhibit periodicity but whose attack patterns and intensity evolve over time.

[0003] Existing methods for detecting network attack incidents fall into two main categories: rule-based methods, including signature-based and behavior-based detection; and traditional machine learning methods, including supervised and unsupervised learning. However, these existing methods suffer from the following shortcomings: they typically rely on static rules or models and are unable to dynamically adapt to and identify cyclical changes in attack behavior. Supervised learning and signature-based detection methods rely heavily on fixed patterns and feature matching, making them ineffective at addressing dynamic changes in time series. Name-based or behavior-based detection often focuses solely on known attack patterns and specific indicators of compromise (IoCs), making them susceptible to evasion by attackers through variant attacks or the use of unknown IoCs to evade detection.

[0004] Existing detection methods often use a single learner to model multiple attack methods as a single attack type. This coarse-grained setting cannot effectively learn the behavioral characteristics of multiple attack types, making the model inapplicable to multi-type attack warnings. However, attack behaviors often do not occur in isolation but are influenced by the interaction between the attacker's previous behavior and the target entity. Attackers often use mixed attack methods or deliberately imitate normal behavior to avoid model detection.

[0005] Therefore, it is necessary to provide a method for mining the covert attack behaviors of network attackers that can improve the prediction accuracy of network attack events. Summary of the Invention

[0006] The purpose of the present invention is to provide a method for mining covert attack behaviors, so as to accurately mine the covert attack behaviors of network attackers.

[0007] In a first aspect, the present invention provides a method for mining covert attack behaviors, including: acquiring attack intelligence data, normalizing the attack intelligence data to obtain a behavior event stream, extracting information from the behavior event stream to obtain attack information, wherein the attack information includes attack patterns, TTPs, and IOCs information; performing text vectorization on the attack information to obtain a corresponding spatial plane expression, performing vector projection based on the spatial plane expression to obtain a fusion vector of the attack information in the unit sphere space, and performing nonlinear transformation based on the fusion vector to obtain an intensity factor of the fusion vector; constructing an initial attack graph based on the attack intelligence data, determining related entities based on the target entity, acquiring historical dependency information of the related entities from the initial attack graph, normalizing the historical dependency information to obtain non-historical dependency information, calculating attention weights of the related entities based on the historical dependency information and the non-historical dependency information, and selecting candidate entities from the related entities based on the attention weights; applying a binary classifier for distinguishing similar samples and dissimilar samples of the target entity to determine a set of focused entities from the candidate entities; calculating a predicted probability of the focused entity set, regulating the predicted probability based on the classifier result and the intensity factor of the binary classifier to obtain a predicted entity, and obtaining attack behaviors corresponding to the predicted entities to obtain the covert attack behaviors of the mined target entity.

[0008] The beneficial effects of the hidden attack behavior mining method provided by the present invention are: introducing theories in the field of statistics, focusing on the relationship between historical dependency information and non-historical dependency information, optimizing the assessment of the degree of attention to related entities through comprehensive analysis of historical dependency information and non-historical dependency information, improving prediction accuracy, and effectively reducing the false alarm rate, solving the problem of the difficulty in capturing deep attack methods in the field of network security. Based on the attack information, the method deeply examines and mines hidden attack behaviors from the perspective of representative high-level features such as attack patterns and TTPs. It provides an in-depth understanding of the changing patterns of attack behaviors, can capture the subtle periodic characteristics of attack behaviors, and can promptly discover and respond to new and highly concealed attack methods.

[0009] In one possible embodiment, the fusion vector includes multiple types of attack behaviors; performing nonlinear transformation based on the fusion vector to obtain the intensity factor of the fusion vector includes: determining the multi-scale spectrum function F(n,m,k,i,t) of the fusion vector according to the original text information of the attack information, wherein n represents the time interval of the multiple types of attack behaviors, m represents the frequency component of the multiple types of attack behaviors in time, k represents the impact factor of the multiple types of attack behaviors on the network topology structure, i represents the attack entity index corresponding to the multiple types of attack behaviors, and t represents the attack event type of the multiple types of attack behaviors; according to the formula The intensity factor reflecting the periodic characteristics of the fusion vector intensity is calculated according to the formula The intensity factor reflecting the temporal periodic characteristics of the fusion vector is calculated, where x(n,m,k,t) represents the result of the nonlinear transformation of the fusion vector, N represents the time length of the time series corresponding to the various types of attack behaviors, j represents the imaginary unit, and e -j2mit / N Represents the rotation factor that transforms the vector information in the fusion vector into the frequency domain, e j2πit / N Represents the rotation factor that transforms the frequency domain information of the fused vector into the time domain.

[0010] In another possible embodiment, related entities are determined based on the target entity, historical dependency information of the related entities is obtained from the initial attack graph, the historical dependency information is normalized and transformed to obtain non-historical dependency information, the attention weights of the related entities are calculated based on the historical dependency information and the non-historical dependency information, and candidate entities are selected from the related entities based on the attention weights, including: determining related entities related to the entity information of the target entity; obtaining historical dependency information of the related entities from the initial attack graph, normalizing the historical dependency information to obtain non-historical dependency information; calculating the attention weight of each related entity based on the historical dependency information and the non-historical dependency information, and selecting related entities whose attention weights are greater than a candidate threshold as candidate entities.

[0011] In other possible embodiments, a binary classifier for distinguishing similar samples and dissimilar samples of a target entity is applied to determine a focus entity set from candidate entities, including: dividing the candidate entities into a historical entity set and a non-historical entity set according to a timestamp associated with the target entity; applying a binary classifier for distinguishing similar samples and dissimilar samples of the target entity to determine whether the correct prediction result exists in the historical entity set or the non-historical combined set; when it is determined that the correct prediction result exists in the historical entity set, the historical entity set is determined to be the focus entity set, and when it is determined that the correct prediction result exists in the non-historical entity set, the non-historical entity set is determined to be the focus entity set.

[0012] Calculating the predicted probability of the focused entity set includes: generating a historical dependency vector and a non-historical dependency vector for the focused entity set; applying an activation function to integrate the historical dependency vector and the non-historical dependency vector to obtain the predicted probability of the focused entity set, which satisfies the following formula: in, represents the predicted probability, T represents the timestamp, s represents the target entity, and p represents the relationship type. represents the historical dependency vector, represents the non-historical dependency vector, and softmax represents the activation function.

[0013] Applying the binary classifier to distinguish similar samples and dissimilar samples of the target entity, the output classifier result includes a classification value;

[0014] The prediction probability is regulated according to the classifier result and the intensity factor of the binary classifier to obtain a predicted entity, including: multiplying the classification value by the predicted probability to obtain an intermediate result; normalizing the intensity factor, and multiplying the normalized intensity factor by the intermediate result to obtain a regulated product; adding the regulated product to the set bias term to complete the regulation of the prediction probability to obtain the regulated probability; comparing the regulated probabilities corresponding to the entities in the attention entity set, and selecting the entity with the largest regulated probability as the predicted entity.

[0015] After obtaining the hidden attack behavior of the target entity being mined, the method also includes: comparing the hidden attack behavior of the target entity with the initial attack graph to determine whether there is new data in the hidden attack behavior of the target entity that is different from the behavior event stream; when it is determined that there is new data in the hidden attack behavior of the target entity, the new data is stored in a preset incremental database.

[0016] In a second aspect, the present invention further provides a device for mining covert attack behaviors, comprising:

[0017] The information extraction unit is used to obtain attack intelligence data, perform data normalization on the attack intelligence data to obtain a behavior event stream, and perform information extraction on the behavior event stream to obtain attack information, which includes attack mode, TTPs and IOCs information; the conversion unit is used to perform text vectorization processing on the attack information to obtain the corresponding spatial plane expression, perform vector projection based on the spatial plane expression to obtain the fusion vector of the attack information in the unit sphere space, and perform nonlinear transformation based on the fusion vector to obtain the strength factor of the fusion vector; the candidate entity selection unit is used to construct an initial attack graph based on the attack intelligence data, determine related entities based on the target entity, and obtain the target entity from the initial attack graph. The historical dependency information of the related entities is obtained, the historical dependency information is normalized and transformed to obtain non-historical dependency information, the attention weight of the related entities is calculated based on the historical dependency information and the non-historical dependency information, and candidate entities are selected from the related entities based on the attention weight; an attention entity set determination unit is used to apply a binary classifier for distinguishing similar samples and dissimilar samples of the target entity to determine the attention entity set from the candidate entities; a prediction unit is used to calculate the prediction probability of the attention entity set, adjust the prediction probability according to the classifier result and strength factor of the binary classifier to obtain the predicted entity, and obtain the attack behavior corresponding to the predicted entity to obtain the hidden attack behavior of the mined target entity.

[0018] In a third aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the above-mentioned covert attack behavior mining method is implemented.

[0019] In a fourth aspect, the present invention also provides an electronic device comprising: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory, so that the electronic device performs the above-mentioned covert attack behavior mining method.

[0020] For the beneficial effects of the second to fourth aspects, please refer to the description of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 A flowchart of a method for mining covert attack behaviors provided by an embodiment of the present invention;

[0022] Figure 2 An example diagram of a model framework for the method for mining covert attack behaviors provided by an embodiment of the present invention;

[0023] Figure 3 A schematic diagram of attack information text vectorization provided by an embodiment of the present invention;

[0024] Figure 4 A schematic diagram of a covert attack behavior mining device provided by an embodiment of the present invention;

[0025] Figure 5 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0026] In order to make the purpose, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the present invention belongs. The words "including" and similar words used in this article mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects.

[0027] This embodiment provides a method for mining covert attack behaviors. Figures 1 to 3 , the method comprising:

[0028] S101: Acquire attack intelligence data, normalize the attack intelligence data to obtain a behavior event stream, and extract information from the behavior event stream to obtain attack information. The attack information includes attack patterns, TTPs, and IOCs information.

[0029] In one possible embodiment, acquiring attack intelligence data includes collecting threat intelligence, traffic information, system log files, and alarm information generated by security devices. Because this collected attack intelligence data is in raw text format and contains noise and irrelevant data, the collected attack behavior data is normalized. For example, data normalization can be performed using methods such as stop word removal, semantic redundancy elimination, and incorrect word identification to obtain a behavioral event stream.

[0030] In one possible embodiment, a large language model is used to extract attack information from a behavioral event stream. Specifically, a GPT is created to extract information from the behavioral event stream using an extraction prompt template. The extracted information specifically includes attack patterns, TTPs (Tactics, Techniques, and Procedures), and IOCs (Indicators of Concern). Specifically, the extraction prompt template is constructed to include the following elements: 1. Task description; 2. Task context; 3. Specific instructions, including imperative language or questions; and 4. Output formatting instructions.

[0031] S102: Perform text vectorization processing on the attack information to obtain the corresponding spatial plane expression, perform vector projection based on the spatial plane expression to obtain a fusion vector of the attack information in the unit sphere space, and perform nonlinear transformation based on the fusion vector to obtain an intensity factor of the fusion vector.

[0032] Text vectorization (also called text embedding) is a method of converting text data from its original symbolic form into points or vectors in a numerical feature space. Each vector represents a text unit, and each dimension of the vector corresponds to a certain feature, including statistical word frequency, semantic relevance, etc. This method can effectively solve the problem that text data is difficult to input into machine learning algorithms efficiently. Figure 3 As shown in Figure 2, the goal of text vectorization is to represent a category of indicators using a single vector. This vector can be used to perform relationship mining at the text level. Once the text is vectorized, these vectors can be explored and manipulated in a multidimensional space.

[0033] In one possible embodiment, attack information is vectorized to obtain a corresponding spatial plane representation. Dimensionality reduction techniques are then used to project the vector representation onto the unit sphere space and find the corresponding spatial plane. In this embodiment, planes representing the three types of indicators (attack patterns, TTPs, and IOCs) are obtained. The intersection of these planes forms a fusion vector, representing the fusion vector of the attack information in the unit sphere space. This fusion vector comprehensively reflects the degree of influence of the three indicators.

[0034] In one possible embodiment, the covert attack behavior method utilizes the temporal characteristics of event streams and aggregates time-coded information into the fusion vector. Time-coded information is obtained from the event stream sequence data and specifically refers to the timestamps of the event stream's occurrence, end, and critical periodic occurrences.

[0035] In one possible embodiment, a fusion vector that aggregates time-coded information undergoes a nonlinear transformation. Leveraging spectral analysis theory's significant advantage in capturing subtle periodic features in time-series data streams, a graph of intensity factor variations is constructed that can discern changes in three types of indicators (attack patterns, TTPs, and IOCs) as well as hidden periodic characteristics. This graph uses time as the independent variable and intensity factor as the dependent variable, recording the evolution of multiple attack entities. From this graph, we can analyze the intensity factor that reflects the periodicity of the fusion vector's intensity and the periodicity of its time.

[0036] In a specific embodiment, the fusion vector includes multiple types of attack behaviors. A nonlinear transformation is performed based on the fusion vector to obtain the intensity factor of the fusion vector, including: determining the multi-scale spectrum function F(n, m, k, i, t) of the fusion vector based on the original text information of the attack information. The information of each part of the multi-scale spectrum function specifically comes from the original text information of the attack pattern, TTPs, and IOCs. Among them, n represents the time interval between the occurrence of multiple types of attack behaviors, which is derived from the serialized data of the network event stream; m represents the frequency component of the multiple types of attack behaviors in time, which is related to the frequency characteristics of the attack behaviors and is derived from the Fourier transform of the time series data to capture the periodicity of the attack behaviors; k represents the impact factor of the multiple types of attack behaviors on the network topology structure, which is determined by the number of attack activities launched within a fixed time range and the number of affected nodes; i represents the attack entity index corresponding to the multiple types of attack behaviors, and t represents the attack event type of the multiple types of attack behaviors, which are automatically labeled with reference to the attack pattern library ATT&CK.

[0037] According to the formula The intensity factor reflecting the periodic characteristics of the fusion vector intensity is calculated according to the formula The intensity factor reflecting the temporal periodic characteristics of the fusion vector is calculated, where x(n,m,k,t) represents the result of nonlinear transformation of the fusion vector for a certain attack event type, N represents the time length of the time series corresponding to multiple types of attack behaviors, j represents the imaginary unit, and e -j2πit / N Represents the rotation factor that transforms the vector information in the fusion vector into the frequency domain, e j2πit / N represents the rotation factor that transforms the frequency domain information of the fusion vector into the time domain. Specifically, e -j2πit / N With e j2πit / Nis the rotation factor (also called phase factor), which represents a vector on the complex plane with a rotation angle of j2πit / N. It corresponds to the basis function in discrete Fourier transform and is used to convert the vector information in the fusion vector to different domains.

[0038] It should be noted that the intensity factor derived from the fused vector through nonlinear transformation is used for subsequent covert attack behavior mining. There are multiple ways to obtain the intensity factor. For example, the intensity factor can be directly calculated for subsequent covert attack behavior mining. Alternatively, the intensity factor can be analyzed from the intensity factor variation pattern diagram, which can be used to assist in understanding and demonstrating the intensity factor's temporal trends.

[0039] S103: Construct an initial attack graph based on the attack intelligence data, determine related entities based on the target entity, obtain historical dependency information of the related entities from the initial attack graph, normalize the historical dependency information to obtain non-historical dependency information, calculate the attention weights of the related entities based on the historical dependency information and the non-historical dependency information, and select candidate entities from the related entities based on the attention weights.

[0040] In a possible embodiment, constructing the initial attack graph according to the attack intelligence data includes: constructing the initial attack graph according to a behavior event stream obtained by normalizing the acquired attack intelligence data.

[0041] In one possible embodiment, the initial attack graph divides the attack situations under different circumstances by timestamps. Therefore, the object during processing is a graph set, and there may be too much noise between different nodes, which requires noise cleaning. After completing the statistical historical dependency, in order to avoid the graph being too large, the initial attack graph is automatically screened for nodes so that each node is connected to 3-hop neighbors as much as possible.

[0042] In a possible embodiment, related entities are determined based on the target entity, historical dependency information of the related entities is obtained from the initial attack graph, the historical dependency information is normalized and transformed to obtain non-historical dependency information, the attention weights of the related entities are calculated based on the historical dependency information and the non-historical dependency information, and candidate entities are selected from the related entities based on the attention weights, including: determining related entities related to the entity information of the target entity; obtaining historical dependency information of the related entities from the initial attack graph, normalizing the historical dependency information to obtain non-historical dependency information; calculating the attention weight of each related entity based on the historical dependency information and the non-historical dependency information, and selecting related entities whose attention weights are greater than a candidate threshold as candidate entities.

[0043] In a specific embodiment, all entities directly or indirectly related to the target entity whose covert attack behavior is to be mined are considered relevant entities. Historical dependency information for the relevant entities is obtained based on the initial attack graph. For example, this historical dependency information includes the historical frequency of the relevant entity's occurrence, information about the relevant entity's 3-hop neighborhood subgraph, and information about the closest entity in time and space. The historical dependency information is normalized to obtain the corresponding non-historical dependency information. For each relevant entity, an attention weight is calculated based on the corresponding historical and non-historical dependency information. Specifically, the attention weight of each relevant entity is obtained by calculating the combined score of its historical and non-historical dependency information and applying a normalization function (oftmax function) to the combined score. The attention weight of each relevant entity represents the degree of attention that should be given to each entity when predicting covert attack behavior. Due to the large number of related entities directly or indirectly related to the target entity, it is difficult to fully consider all of them. Therefore, in this embodiment, candidate entities are screened based on the attention weights of the relevant entities. Specifically, a candidate threshold is set. When the attention weight of a relevant entity exceeds the candidate threshold, the relevant entity is retained as a candidate entity.

[0044] S104: Apply a binary classifier for distinguishing similar samples and dissimilar samples of the target entity to determine a set of focused entities from candidate entities.

[0045] In one possible embodiment, supervised learning is used to construct positive examples similar to the target entity and negative examples dissimilar to the target entity. These examples are then fed into a binary classifier using contrastive learning to learn the differences between different types of entities. After training, a binary classifier is obtained that can distinguish between relevant and irrelevant entities of the target entity. Using this method to train a binary classifier can overcome the problem of limited training data.

[0046] In a specific embodiment, a binary classifier for distinguishing similar samples and dissimilar samples of a target entity is applied to determine a focus entity set from candidate entities, including: dividing the candidate entities into a historical entity set and a non-historical entity set according to a timestamp associated with the target entity; applying a binary classifier for distinguishing similar samples and dissimilar samples of the target entity to determine whether a correct prediction result exists in the historical entity set or the non-historical combined set; when it is determined that the correct prediction result exists in the historical entity set, the historical entity set is determined to be the focus entity set, and when it is determined that the correct prediction result exists in the non-historical entity set, the non-historical entity set is determined to be the focus entity set.

[0047] In one possible embodiment, classifying candidate entities into a historical entity set and a non-historical entity set based on a timestamp associated with the target entity includes: classifying the candidate entities based on a timestamp T associated with the target entity, wherein all object entities in events before timestamp T are classified as the historical entity set, and the remaining objects are classified as the non-historical entity set. Exemplarily, when performing the classification, a query (s, p, ?, T) is given, where s represents the target entity, p represents the relationship type, ? represents the candidate entity, and T represents the timestamp. The historical entity set and the non-historical entity set are classified based on this query.

[0048] By inputting the historical entity set and the non-historical entity set into a binary classifier trained to distinguish between similar and dissimilar samples of the target entity, the predicted entity related to the target entity can be determined to exist in the historical entity set or the non-historical entity set. Based on the judgment result, the entity set containing the correct prediction result is determined as the focus entity set. The determination of the focus entity set is used to regulate the scope of candidate entities and help eliminate entities that do not need attention.

[0049] S105: Calculate the prediction probability of each focus entity in the focus entity set, adjust the prediction probability according to the classifier result and strength factor of the binary classifier to obtain the predicted entity, obtain the attack behavior corresponding to the predicted entity to obtain the hidden attack behavior of the mined target entity.

[0050] In one possible embodiment, calculating the predicted probability of the focused entity set includes: generating a historical dependency vector and a non-historical dependency vector for the focused entity set; and applying an activation function to integrate the historical dependency vector and the non-historical dependency vector to obtain the predicted probability of the focused entity, which satisfies the following formula: in, represents the predicted probability, T represents the timestamp, s represents the target entity, and p represents the relationship type. Indicates historical dependence, represents non-historical dependency, and softmax represents the activation function.

[0051] In a specific embodiment, two context vectors (history dependency and non-historical dependence ) to reflect the historical and non-historical relevance between the target entity and the entity of interest. Specifically, the historical dependency context vector is generated by the following formula: Among them, W his and b hisDenotes training parameters, ⊕ denotes a join operation, E denotes the embedding matrix of all entities in the focused entity set, r1 denotes a parameter used to improve the score of historical entities, s denotes the target entity, p denotes the relationship type between the target entity and the entity in the focused entity set, and T denotes the timestamp associated with the target entity. The non-historical dependent context vector is generated by the following formula: Among them, W nhis and b nhis represents the training parameter, and r2 represents the parameter used to reduce the score of non-historical entities. The predicted probability calculation formula of the focused entity set obtained by integration of the activation function is as follows: in, represents the predicted probability, and softmax represents the activation function.

[0052] For example, assume that the target entity s calculates the historical dependency of all relations pi in the 3-hop neighborhood in turn and non-historical dependence After applying the activation function softmax, two probability distributions will be obtained, and then the average of the two probability distributions will be taken as the probability. For example: if The result is [0.2, 0.1, 0.7], The result is [0.4, 0.4, 0.2], then will be [0.3, 0.25, 0.45].

[0053] In a possible embodiment, a binary classifier is applied to distinguish similar samples and dissimilar samples of a target entity, and the output classifier result includes a classification value; the prediction probability is regulated according to the classifier result of the binary classifier and the intensity factor to obtain a predicted entity, including: multiplying the classification value by the prediction probability to obtain an intermediate result; normalizing the intensity factor, and multiplying the normalized intensity factor by the intermediate result to obtain a regulated product; adding the regulated product to a set bias term to complete the regulation of the prediction probability to obtain a regulated probability; comparing the regulated probabilities corresponding to entities in the focus entity set, and selecting the entity with the largest regulated probability as the predicted entity.

[0054] The training goal of a binary classifier is to predict whether a missing entity exists in a historical entity set for a given target entity or relationship. Applying the trained binary classifier to a judgment returns a numerical value. This means that applying the binary classifier to distinguish between similar and dissimilar samples of the target entity includes returning a classification value.

[0055] Normalizing intensity factors allows for comparison and processing of variables of different scales (e.g., attack patterns, tactics, techniques, procedures, and attack intensity) on the same scale. Normalization unifies the intensity information of different attack behaviors into a standard range, enabling more accurate spectrum analysis and other mathematical operations, effectively identifying covert attack behaviors. In this field, applied normalization methods include, but are not limited to, min-max normalization, z-score normalization, and decimal scaling normalization.

[0056] The bias term is a parameter obtained by applying the covert attack behavior mining method of the present invention. It is designed to minimize the gap between the predicted result (predicted entity) and the actual label (target entity) and can be learned through an optimization algorithm (such as gradient descent). The bias term can be obtained by designing training data, applying the covert attack behavior mining method of the present invention to construct a corresponding model, and training the model based on the training data. The bias term is continuously adjusted during training until an optimal or relatively good value is found.

[0057] In a possible embodiment, after obtaining the hidden attack behavior of the target entity to be mined, it also includes: comparing the hidden attack behavior of the target entity with the initial attack graph to determine whether there is new data different from the behavior event stream in the hidden attack behavior of the target entity; when it is determined that new data exists in the hidden attack behavior of the target entity, the new data is stored in a preset incremental database.

[0058] In a specific embodiment, determining whether there is new data different from the behavioral event stream in the hidden attack behavior of the target entity includes: comparing the hidden attack behavior of the mined target entity with the data of the existing attack graph (i.e., the initial attack graph used when mining the hidden attack behavior), and confirming whether there are identical data entries based on identifiers (such as timestamps, attack patterns, TTPs, IOCs, etc.) during the comparison. If the hidden attack behavior of the mined target entity does not exist in the existing attack graph, it is considered to be new data. The new data is stored in an incremental database, and the timestamp is used to divide the new data at different times.

[0059] The preset incremental database is a database for storing new data obtained after performing covert attack behavior mining, that is, when completing a covert attack behavior mining, it is determined whether the information obtained by mining includes new data, and when new data exists, the new data is stored in the incremental database. When the method of the present invention is applied for the first time to perform covert attack behavior mining, there is no data stored in the incremental database, and the initial attack graph constructed for the first time is the attack graph constructed by the behavioral event stream obtained after data normalization based on the attack intelligence data. When it is not the first time to construct the initial attack graph, that is, when there is an existing attack graph, constructing the initial attack graph based on the attack intelligence data includes: obtaining the existing attack graph, supplementing the graph data of the existing attack graph based on the data stored in the incremental database, so as to realize the construction of a new attack graph as the initial attack graph for performing covert attack behavior mining. The newly obtained attack graph is an attack subgraph at a certain moment, and performing covert attack behavior mining based on the new attack graph can achieve a comprehensive consideration of the data and avoid repeated statistics of large old data sets.

[0060] In one possible embodiment, after supplementing the existing attack graph with data stored in the incremental database, covert attack behavior mining is performed to obtain new covert attack behavior mining results. These new covert attack behavior mining results are then combined with the existing mining results. Specifically, by comparing the new covert attack behavior mining results with the existing mining results, it is possible to determine which new covert attack behaviors were previously unidentified. These new behaviors are then added to the existing list of covert attack behaviors. If a new attack behavior conflicts with an existing attack behavior, the old behavior is replaced with the new attack behavior to update the list.

[0061] The covert attack behavior mining method provided by the present invention introduces theories from the field of statistics, focuses on the relationship between historical dependency information and non-historical dependency information, optimizes the evaluation of the degree of attention to related entities through comprehensive analysis of historical dependency information and non-historical dependency information, improves prediction accuracy, can effectively reduce the false alarm rate, and solves the problem that deep attack methods are difficult to capture in the field of network security.

[0062] Through semantic analysis technology, we synthesize multiple semantic information for various attack behaviors and set up various learning functions based on spectral analysis to improve the model's learning and perception capabilities for complex attack behaviors. Identifying highly similar attack events across multiple semantic spaces enables us to identify potential attack events with high credibility for the target attack entity, addressing the current difficulties and inaccuracies in network security research.

[0063] Faced with massive amounts of multidimensional and sparse data, a covert attack behavior mining method based on multi-scale spectral analysis completes the attack chain in the graph. Based on the attack information, the hidden attack behaviors are deeply examined and mined from the perspective of representative high-level features such as attack patterns and TTPs. This provides a deep understanding of the changing patterns of attack behaviors, can capture subtle periodic characteristics of attack behaviors, and can promptly detect and respond to new and highly concealed attack methods.

[0064] The covert attack behavior mining method of the present invention combines the traditional spectrum analysis process with deep learning, which improves accuracy, has high efficiency, and has strong subsequent scalability. After implementation, it also lowers the daily operation and maintenance threshold for operation and maintenance personnel.

[0065] See the instructions attached Figure 4 This embodiment also provides a device for mining covert attack behaviors, which is used to implement the above method embodiment. The device includes:

[0066] The information extraction unit 201 is used to obtain attack intelligence data, perform data normalization on the attack intelligence data to obtain a behavior event stream, and perform information extraction on the behavior event stream to obtain attack information, which includes attack patterns, TTPs, and IOCs information.

[0067] The conversion unit 202 is used to perform text vectorization processing on the attack information to obtain a corresponding spatial plane expression, perform vector projection based on the spatial plane expression to obtain a fusion vector of the attack information in the unit sphere space, and perform nonlinear transformation based on the fusion vector to obtain an intensity factor of the fusion vector.

[0068] The candidate entity selection unit 203 is used to construct an initial attack graph based on the attack intelligence data, determine related entities based on the target entity, obtain historical dependency information of the related entities from the initial attack graph, normalize the historical dependency information to obtain non-historical dependency information, calculate the attention weights of the related entities based on the historical dependency information and the non-historical dependency information, and select candidate entities from the related entities based on the attention weights.

[0069] The focused entity set determining unit 204 is configured to determine a focused entity set from candidate entities by applying a binary classifier for distinguishing similar samples from dissimilar samples of a target entity.

[0070] The prediction unit 205 is used to calculate the prediction probability of the focused entity set, adjust the prediction probability according to the classifier result and strength factor of the binary classifier to obtain the predicted entity, and obtain the attack behavior corresponding to the predicted entity to obtain the hidden attack behavior of the mined target entity.

[0071] All relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0072] In other embodiments of the present application, the present application discloses an electronic device, such as Figure 5 As shown, the electronic device 300 may include: one or more processors 301; a memory 302; a display 303; one or more applications (not shown); and one or more computer programs 304. The above components may be connected via one or more communication buses 305. The one or more computer programs 304 are stored in the above memory and configured to be executed by the one or more processors 301. The one or more computer programs 304 include instructions, which may be used to execute the following: Figure 1 、 Figure 4 and each step in the corresponding embodiment.

[0073] Through the description of the above embodiments, those skilled in the art will clearly understand that for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0074] The functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0075] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as flash memory, mobile hard disk, read-only memory, random access memory, magnetic disk or optical disk.

[0076] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A method for mining covert attack behaviors, characterized in that: include: Acquire attack intelligence data, perform data normalization on the attack intelligence data to obtain a behavior event stream, and perform information extraction on the behavior event stream to obtain attack information, wherein the attack information includes attack patterns, TTPs, and IOCs information; Performing text vectorization processing on the attack information to obtain a corresponding spatial plane expression, performing vector projection based on the spatial plane expression to obtain a fusion vector of the attack information in the unit sphere space, and performing nonlinear transformation based on the fusion vector to obtain an intensity factor of the fusion vector; Constructing an initial attack graph based on attack intelligence data, determining related entities based on target entities, obtaining historical dependency information of the related entities from the initial attack graph, normalizing the historical dependency information to obtain non-historical dependency information, calculating attention weights of the related entities based on the historical dependency information and the non-historical dependency information, and selecting candidate entities from the related entities based on the attention weights; Determine a set of entities of interest from the candidate entities by applying a binary classifier for distinguishing similar samples from dissimilar samples of the target entity; Calculate the predicted probability of the entity set of interest, adjust the predicted probability according to the classifier result of the binary classifier and the strength factor to obtain the predicted entity, obtain the attack behavior corresponding to the predicted entity to obtain the hidden attack behavior of the mined target entity.

2. The method according to claim 1, characterized in that Determining related entities according to the target entity, obtaining historical dependency information of the related entities from the initial attack graph, normalizing the historical dependency information to obtain non-historical dependency information, calculating attention weights of the related entities according to the historical dependency information and the non-historical dependency information, and selecting candidate entities from the related entities according to the attention weights, including: determining related entities related to the entity information of the target entity; Acquiring historical dependency information of the relevant entities from the initial attack graph, and normalizing the historical dependency information to obtain non-historical dependency information; The attention weight of each of the related entities is calculated according to the historical dependency information and the non-historical dependency information, and the related entities whose attention weight is greater than the candidate threshold are selected as candidate entities.

3. The method according to claim 1, characterized in that Applying a binary classifier for distinguishing similar samples and dissimilar samples of the target entity to determine a set of entities of interest from the candidate entities includes: dividing the candidate entities into a historical entity set and a non-historical entity set according to a timestamp associated with the target entity; Applying a binary classifier for distinguishing similar samples from dissimilar samples of the target entity, and determining whether the correct prediction result exists in the historical entity set or the non-historical entity set; When it is determined that the correct prediction result exists in the historical entity set, the historical entity set is determined to be the focus entity set; when it is determined that the correct prediction result exists in the non-historical entity set, the non-historical entity set is determined to be the focus entity set.

4. The method according to claim 1, wherein Calculate the predicted probability of the entity set of interest, including: Generate historical dependency vectors and non-historical dependency vectors for the set of entities of interest; An activation function is applied to integrate the historical dependency vector and the non-historical dependency vector to obtain the predicted probability of the focused entity set, which satisfies the following formula: },in, represents the predicted probability, T represents the timestamp, s represents the target entity, and p represents the relationship type. represents the historical dependency vector, represents the non-historical dependency vector, Represents the activation function.

5. The method according to claim 1, wherein Applying the binary classifier to distinguish similar samples and dissimilar samples of the target entity, the output classifier result includes a classification value; Adjusting the predicted probability according to the classifier result of the binary classifier and the strength factor to obtain a predicted entity includes: Multiplying the classification value by the predicted probability to obtain an intermediate result; Normalizing the intensity factor, and multiplying the normalized intensity factor by the intermediate result to obtain a control product; Adding the control product to the set bias term to complete the control of the predicted probability to obtain the control probability; The control probabilities corresponding to the entities in the focused entity set are compared, and the entity with the largest control probability is selected as the predicted entity.

6. The method according to claim 1, characterized in that After obtaining the hidden attack behavior of the target entity, it also includes: Comparing the covert attack behavior of the target entity with the initial attack graph to determine whether there is new data different from the behavior event stream in the covert attack behavior of the target entity; When it is determined that new data exists in the covert attack behavior of the target entity, the new data is stored in a preset incremental database.

7. A device for mining covert attack behaviors, characterized in that: The device comprises: An information extraction unit is configured to obtain attack intelligence data, perform data normalization on the attack intelligence data to obtain a behavior event stream, and perform information extraction on the behavior event stream to obtain attack information, wherein the attack information includes attack patterns, TTPs, and IOCs information; a conversion unit, configured to perform text vectorization processing on the attack information to obtain a corresponding spatial plane expression, perform vector projection based on the spatial plane expression to obtain a fusion vector of the attack information in the unit sphere space, and perform nonlinear transformation based on the fusion vector to obtain an intensity factor of the fusion vector; a candidate entity selection unit, configured to construct an initial attack graph based on the attack intelligence data, determine related entities based on the target entity, obtain historical dependency information of the related entities from the initial attack graph, normalize the historical dependency information to obtain non-historical dependency information, calculate attention weights of the related entities based on the historical dependency information and the non-historical dependency information, and select candidate entities from the related entities based on the attention weights; a focus entity set determining unit, configured to determine a focus entity set from the candidate entities by applying a binary classifier for distinguishing similar samples and dissimilar samples of the target entity; A prediction unit is used to calculate the prediction probability of the set of entities of interest, adjust the prediction probability according to the classifier result of the binary classifier and the strength factor to obtain the predicted entity, and obtain the attack behavior corresponding to the predicted entity to obtain the hidden attack behavior of the mined target entity.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for mining covert attack behaviors according to any one of claims 1 to 6 is implemented.

9. An electronic device, characterized in that: include: processor and memory; The memory is used to store computer programs; The processor is configured to execute the computer program stored in the memory, so as to enable the electronic device to execute the covert attack behavior mining method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network attack behavior prediction method based on attack mode

    CN115333778A

  • TTP information mining method and device based on threat intelligence, medium and electronic equipment

    CN118427636A