An analysis method and system for real battle attack and defense confrontation
By combining multi-source heterogeneous dataset fusion technology and knowledge graphs with machine learning algorithms, the problems of unclear assets, unknown risks, and missing processes in enterprise digital systems have been solved, enabling automated analysis and rapid response in real-world offensive and defensive confrontations.
Patent Information
- Application Number
- CN202411465599.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-21
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-10-21
AI Technical Summary
Existing technologies are unable to effectively address the systemic confrontations and systemic risks in enterprise digital systems, especially in real-world offensive and defensive confrontations, where there are problems such as unclear assets, unknown risks, and missing processes.
By employing multi-source heterogeneous dataset fusion technology and utilizing knowledge graphs and machine learning algorithms, a trustworthy dataset is constructed to achieve structured and visual representation of protected objects and their related elements. Combined with structured processing of alarm information and conflict game models, automated analysis and judgment are performed.
It enables precise and rapid handling of known threats, enhances the automation capabilities of security analysis and judgment, solves the problems of insufficient data content richness and single type, and provides accurate security incident analysis and rapid response capabilities.
Smart Images

Figure CN119363419B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to an analysis method and system for practical offensive and defensive confrontation. Background Technology
[0002] With the rapid advancement of digital transformation, the industry is gradually moving from fragmentation to consolidation, and from decentralized to integrated approaches. Business operations and information technology are becoming increasingly intertwined, forming a top-down digital system that extends from headquarters to branches. However, this system is characterized by wide exposure, long attack chains, and complex interconnections. The scope of protection has become ubiquitous, extending to cloud, network, data applications, endpoints, and the supply chain, reaching the entire industry. Users face long-term systemic challenges and systemic risks, making security a practical necessity.
[0003] Therefore, there is an urgent need for a targeted analytical method and system for practical offensive and defensive confrontation. Summary of the Invention
[0004] The purpose of this invention is to provide an analysis method and system for practical offensive and defensive confrontation, which provides multiple capabilities such as asset sorting, exposure surface convergence, and security situation awareness, realizes business asset analysis and identification and basic correlation, realizes risk data aggregation covering dozens of security capabilities, builds an integrated closed loop of monitoring and early warning, rapid response, analysis and judgment and automated defense, and solves the problems of unclear assets, unknown risks and missing processes to complete basic structured defense.
[0005] Firstly, this application provides an analysis method for practical offensive and defensive confrontation, the method comprising:
[0006] Step 1: Organize the trusted dataset, including:
[0007] Based on raw traffic, hosts, and applications, obtain raw, massive amounts of data.
[0008] Identify the key security data fields corresponding to each security capability;
[0009] Based on the raw massive data, extract security-related information;
[0010] Based on the key security data fields, a security data baseline is established for security-related information to obtain a trusted dataset.
[0011] Step two, build a basic library of practical scenarios, including:
[0012] Based on the aforementioned trusted dataset, a foundational library of practical scenarios is formed through key data correlation.
[0013] Step 3, Automated modeling of protected object associations, including:
[0014] Based on the results of the inventory of protected objects, a model of the association of protected objects is constructed, and information technology business, IT assets and their related elements are visualized and structured in the form of a knowledge graph.
[0015] Step four, automated assessment and modeling of known security risks through multi-source fusion, includes:
[0016] By structuring and standardizing various alarms, the source of alarms is automatically defined as a data label. While ensuring that the alarm level of the probe is reasonable, alarms of three levels (high, medium and low) are summarized, alarm categories and sub-types are sorted out, a conflict game model is established, and the impact of the learning ability of alarms as objects of conflict game on visualization and structured expression is quantitatively analyzed.
[0017] Depending on the characteristics, scale, and quality of alarm data at different stages, different other data resources can be used for correlation analysis, and noise reduction and filtering of alarm data are necessary.
[0018] By associating alarm data with behaviors, considering its impact on visualization and structured representation, and generating cybersecurity events from multiple data types and attributes, the system presents complete event content and automates the analysis and assessment of known threats.
[0019] Secondly, this application provides an analysis system for actual combat offense and defense confrontation, the system comprising: a data generation module, a scene generation module, an object association module, an automatic judgment module, and an analysis configuration module;
[0020] The data generation module is used to organize a trustworthy dataset, including:
[0021] Based on raw traffic, hosts, and applications, obtain raw, massive amounts of data.
[0022] Identify the key security data fields corresponding to each security capability;
[0023] Based on the raw massive data, extract security-related information;
[0024] Based on the key security data fields, a security data baseline is established for security-related information to obtain a trusted dataset.
[0025] The scenario generation module is used to build a basic library of practical scenarios, including:
[0026] Based on the aforementioned trusted dataset, a foundational library of practical scenarios is formed through key data correlation.
[0027] The object association module is used to protect automated object association modeling, including:
[0028] Based on the results of the inventory of protected objects, a model of the association of protected objects is constructed, and information technology business, IT assets and their related elements are visualized and structured in the form of a knowledge graph.
[0029] The automatic assessment module is used for automated assessment and modeling of known security risks from multi-source fusion, including:
[0030] By structuring and standardizing various alarms, the source of alarms is automatically defined as a data label. While ensuring that the alarm level of the probe is reasonable, alarms of three levels (high, medium and low) are summarized, alarm categories and sub-types are sorted out, a conflict game model is established, and the impact of the learning ability of alarms as objects of conflict game on visualization and structured expression is quantitatively analyzed.
[0031] Depending on the characteristics, scale, and quality of alarm data at different stages, different other data resources can be used for correlation analysis, and noise reduction and filtering of alarm data are necessary.
[0032] By associating alarm data with behaviors, its impact on visualization and structured expression, and various attribute data, a network security event is generated, presenting complete event content and automating the analysis and assessment of known threats.
[0033] The analysis configuration module is used to build the analysis configuration platform.
[0034] Thirdly, this application provides an analysis system for practical offensive and defensive confrontation, the system including a processor and a memory:
[0035] The memory is used to store program code and transmit the program code to the processor;
[0036] The processor is configured to execute any one of the four possible methods of the first aspect according to the instructions in the program code.
[0037] Fourthly, this application provides a computer-readable storage medium for storing program code, which is executed by a processor to implement any one of the four possible methods of the first aspect.
[0038] Beneficial effects
[0039] This invention provides an analysis method and system for practical offensive and defensive confrontation. By constructing a multi-source heterogeneous dataset fusion technology, and through in-depth analysis of the interfaces provided by relevant security capability probes and platforms, it sorts out the interface data fields of heterogeneous probes or platforms, performs unified comparison of the field information of security capability probes and platforms, and establishes a security data baseline under the same product type. In the field of protected object association, knowledge graph technology is applied to realize the structured and visual expression of the relationship between protected objects and their related elements. Based on trusted datasets, it deeply associates technical alarm information with protected objects within the organization. The protected object-security risk-intelligence algorithm is automatically modeled, and an algorithm model is superimposed on the algorithms of protected objects, trusted data, and security risks to accurately and quickly handle known threats, achieve accurate noise reduction of massive data and automated analysis and judgment of security events, and overcome the problem that existing technologies cannot cope with systematic confrontation and systemic risks.
[0040] The method and system of the present invention have the following advantages and effects:
[0041] It abandons the traditional approach of using a single log source, eliminating the problems of insufficient data content richness and single data type. It adopts multiple methods such as API, syslog, and URL to acquire and integrate multi-source heterogeneous datasets to form a reliable dataset, providing reliable data support for accurate analysis and judgment.
[0042] In the field of protected object association, knowledge graph technology is applied to realize the structured and visual expression of the relationship between protected objects and their related elements, and to realize the automated, clear and intuitive sorting of protected objects. In the field of raw security data processing and analysis, machine learning algorithms such as random forest and unsupervised clustering are applied. At the same time, similarity comparison, deduplication, aggregation and whitelisting are used for the monitored alarm information to achieve accurate noise reduction of massive data and automated analysis and analysis of security events.
[0043] The automated modeling of the protected object, security risk, and intelligence algorithm adds another layer of algorithmic model on top of the algorithms for protected objects, trusted data, and security risks, enabling precise and rapid handling of known threats and elevating the overall security analysis and judgment capabilities to a new level of automation. Attached Figure Description
[0044] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without creative effort.
[0045] Figure 1 This is a flowchart illustrating the security data baseline analysis process of the present invention.
[0046] Figure 2 This is a system architecture diagram of the present invention. Detailed Implementation
[0047] The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby providing a clearer and more explicit definition of the scope of protection of the present invention.
[0048] The analytical method for practical offensive and defensive confrontation provided in this application includes:
[0049] Step 1: Organize the trusted dataset, specifically including:
[0050] Based on raw traffic, hosts, and applications, obtain raw, massive amounts of data.
[0051] Identify the key security data fields corresponding to each security capability;
[0052] Based on the raw massive data, extract security-related information;
[0053] Based on the key security data fields, a security data baseline is established for security-related information to obtain a trusted dataset.
[0054] In some preferred embodiments, the security-related information includes one or more of the following: security capability alarms, system and traffic error logs, authentication behavior records, and access records.
[0055] Based on the key security data fields, a security data baseline is established for security-related information to ensure that it covers at least five key event analysis elements: event occurrence time, assets affected by the event, event behavior process, personnel involved in the event, and the impact of the event on disk.
[0056] In some preferred embodiments, the security data baseline includes one or more of the following: security capability alarm baseline, system and traffic error log baseline, and authentication behavior record baseline.
[0057] The secure data baseline is enriched with data content to obtain a trusted dataset.
[0058] Step two involves building a foundational library of practical scenarios, which specifically includes:
[0059] Based on the aforementioned trusted dataset, a foundational library of practical scenarios is formed through key data correlation.
[0060] The practical scenario library includes a variety of basic analysis methods.
[0061] Step 3, Automated modeling of protected object associations, specifically includes:
[0062] Based on the results of the inventory of protected objects, a model of the association of protected objects is constructed, and information technology business, IT assets and their related elements are visualized and structured in the form of a knowledge graph.
[0063] It can clarify business operations, open ports and component information, and asset ownership, helping to clarify the relationships between protected objects. In the event of a security incident, it can quickly locate the affected IT assets based on a certain influencing factor, reducing the pressure on analysts to disassemble and sort out the protected objects.
[0064] Step four, automated assessment and modeling of known security risks through multi-source fusion, specifically includes:
[0065] By structuring and standardizing various alarms, the source of alarms is automatically defined as a data label. While ensuring that the alarm level of the probe is reasonable, alarms of three levels (high, medium and low) are summarized, alarm categories and sub-types are sorted out, a conflict game model is established, and the impact of the learning ability of alarms as objects of conflict game on visualization and structured expression is quantitatively analyzed.
[0066] In practical applications, two alarms choosing to cooperate represent considering the influence of neighboring object control schemes, while choosing to betray represent not considering the influence of neighboring object control schemes. Each alarm is a pure strategist and has only two strategies to choose from: cooperation, which aims for global optimization, and betrayal, which aims for individual optimization.
[0067] In a game, the total payoff for a given alarm is the sum of all interacting neighboring objects after an iteration.
[0068] For alarms, the total revenue can be adjusted by adjusting the revenue matrix.
[0069] Depending on the characteristics, scale, and quality of alarm data at different stages, different other data resources can be used for correlation analysis, and noise reduction and filtering of alarm data are necessary.
[0070] By associating alarm data with behaviors, its impact on visualization and structured expression, and various attribute data, a network security event is generated, presenting complete event content and automating the analysis and assessment of known threats.
[0071] This application does not employ a massive data lake model to construct a trusted dataset. Instead, it utilizes a multi-source heterogeneous dataset fusion technology. Through in-depth analysis of the interfaces provided by relevant security capability probes and platforms, it sorts out the interface data fields of heterogeneous probes or platforms, and performs a unified comparison of the field information of security capability probes and platforms from different vendors, brands, types, and versions. This results in a dataset list, and based on security business requirements, it establishes a security data baseline for the same product type.
[0072] It abandons the traditional approach of using a single log source, eliminating the problems of insufficient data content richness and single data type. It adopts multiple methods such as API, syslog, and URL to acquire and integrate multi-source heterogeneous datasets to form a reliable dataset, providing reliable data support for accurate analysis and judgment.
[0073] This application relates to automated modeling of protected objects, security risks, and intelligence algorithms. In the domain of protected object association, knowledge graph technology is applied to achieve a structured and visual representation of the relationships between protected objects and their associated elements, enabling automated, clear, and intuitive organization of protected objects.
[0074] The automated modeling of the protected object, security risk, and intelligence algorithm adds another layer of algorithmic model on top of the algorithms for protected objects, trusted data, and security risks, enabling precise and rapid handling of known threats and elevating the overall security analysis and judgment capabilities to a new level of automation.
[0075] Figure 2 The architecture diagram of the analysis system for practical offensive and defensive confrontation provided in this application includes: a data generation module, a scenario generation module, an object association module, an automatic judgment module, and an analysis configuration module;
[0076] The data generation module is used to organize a trustworthy dataset, including:
[0077] Based on raw traffic, hosts, and applications, obtain raw, massive amounts of data.
[0078] Identify the key security data fields corresponding to each security capability;
[0079] Based on the raw massive data, extract security-related information;
[0080] Based on the key security data fields, a security data baseline is established for security-related information to obtain a trusted dataset.
[0081] The scenario generation module is used to build a basic library of practical scenarios, including:
[0082] Based on the aforementioned trusted dataset, a foundational library of practical scenarios is formed through key data correlation.
[0083] The object association module is used to protect automated object association modeling, including:
[0084] Based on the results of the inventory of protected objects, a model of the association of protected objects is constructed, and information technology business, IT assets and their related elements are visualized and structured in the form of a knowledge graph.
[0085] The automatic assessment module is used for automated assessment and modeling of known security risks from multi-source fusion, including:
[0086] By structuring and standardizing various alarms, the source of alarms is automatically defined as a data label. While ensuring that the alarm level of the probe is reasonable, alarms of three levels (high, medium and low) are summarized, alarm categories and sub-types are sorted out, a conflict game model is established, and the impact of the learning ability of alarms as objects of conflict game on visualization and structured expression is quantitatively analyzed.
[0087] Depending on the characteristics, scale, and quality of alarm data at different stages, different other data resources can be used for correlation analysis, and noise reduction and filtering of alarm data are necessary.
[0088] By associating alarm data with behaviors, its impact on visualization and structured expression, and various attribute data, a network security event is generated, presenting complete event content and automating the analysis and assessment of known threats.
[0089] The analysis configuration module is used to build the analysis configuration platform.
[0090] In some preferred embodiments, the security-related information includes one or more of the following: security capability alarms, system and traffic error logs, authentication behavior records, and access records.
[0091] In some preferred embodiments, the security data baseline includes one or more of the following: security capability alarm baseline, system and traffic error log baseline, and authentication behavior record baseline.
[0092] It abandons the traditional approach of using a single log source, eliminating the problems of insufficient data content richness and single data type. It adopts multiple methods such as API, syslog, and URL to acquire and integrate multi-source heterogeneous datasets to form a reliable dataset, providing reliable data support for accurate analysis and judgment.
[0093] This application provides an analysis system for practical offensive and defensive confrontation, the system comprising: a processor and a memory.
[0094] The memory is used to store program code and transmit the program code to the processor;
[0095] The processor is configured to execute the method described in any one of the embodiments of the first aspect according to the instructions in the program code.
[0096] This application provides a computer-readable storage medium for storing program code, which is executed by a processor to implement the method described in any one of the embodiments of the first aspect.
[0097] In a specific implementation, the present invention also provides a computer storage medium, wherein the computer storage medium may store a program, and the program, when executed, may include some or all of the steps in the various embodiments of the present invention. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0098] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions in the embodiments of the present invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or certain parts of the embodiments of the present invention.
[0099] The same or similar parts between the various embodiments in this specification can be referred to mutually. In particular, the embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.
[0100] The embodiments of the present invention described above do not constitute a limitation on the scope of protection of the present invention.
Claims
1. An analytical method for practical offensive and defensive confrontation, characterized in that, The method includes: Step 1: Organize the trusted dataset, including: Based on raw traffic, hosts, and applications, obtain raw, massive amounts of data. Identify the key security data fields corresponding to each security capability; Based on the raw massive data, extract security-related information; Based on the key security data fields, a security data baseline is established for security-related information to obtain a trusted dataset. Step two, build a basic library of practical scenarios, including: Based on the aforementioned trusted dataset, a foundational library of practical scenarios is formed through key data correlation. Step 3, Automated modeling of protected object associations, including: Based on the results of the inventory of protected objects, a model of the association of protected objects is constructed, and information technology business, IT assets and their related elements are visualized and structured in the form of a knowledge graph. Step four, automated assessment and modeling of known security risks through multi-source fusion, includes: By structuring and standardizing various alarms, the source of alarms is automatically defined as a data label. While ensuring that the alarm level of the probe is reasonable, alarms of three levels (high, medium and low) are summarized, alarm categories and sub-types are sorted out, a conflict game model is established, and the impact of the learning ability of alarms as objects of conflict game on visualization and structured expression is quantitatively analyzed. Depending on the characteristics, scale, and quality of alarm data at different stages, different other data resources can be used for correlation analysis, and noise reduction and filtering of alarm data are necessary. By associating alarm data with behaviors, considering its impact on visualization and structured representation, and generating cybersecurity events from multiple data types and attributes, the system presents complete event content and automates the analysis and assessment of known threats.
2. The method according to claim 1, characterized in that: The security-related information includes one or more of the following: security capability alerts, system and traffic error logs, authentication behavior records, and access records.
3. The method according to claim 1, characterized in that: The security data baseline includes one or more of the following: security capability alarm baseline, system and traffic error log baseline, and authentication behavior record baseline.
4. The method according to claim 1, characterized in that: Multiple methods, including API, syslog, and URL, are used to acquire and merge heterogeneous datasets from multiple sources to form a trusted dataset.
5. An analysis system for practical offensive and defensive combat, characterized in that, The system includes: a data generation module, a scene generation module, an object association module, an automatic judgment module, and an analysis configuration module; The data generation module is used to organize a trustworthy dataset, including: Based on raw traffic, hosts, and applications, obtain raw, massive amounts of data. Identify the key security data fields corresponding to each security capability; Based on the raw massive data, extract security-related information; Based on the key security data fields, a security data baseline is established for security-related information to obtain a trusted dataset. The scenario generation module is used to build a basic library of practical scenarios, including: Based on the aforementioned trusted dataset, a foundational library of practical scenarios is formed through key data correlation. The object association module is used to protect automated object association modeling, including: Based on the results of the inventory of protected objects, a model of the association of protected objects is constructed, and information technology business, IT assets and their related elements are visualized and structured in the form of a knowledge graph. The automatic assessment module is used for automated assessment and modeling of known security risks from multi-source fusion, including: By structuring and standardizing various alarms, the source of alarms is automatically defined as a data label. While ensuring that the alarm level of the probe is reasonable, alarms of three levels (high, medium and low) are summarized, alarm categories and sub-types are sorted out, a conflict game model is established, and the impact of the learning ability of alarms as objects of conflict game on visualization and structured expression is quantitatively analyzed. Depending on the characteristics, scale, and quality of alarm data at different stages, different other data resources can be used for correlation analysis, and noise reduction and filtering of alarm data are necessary. By associating alarm data with behaviors, its impact on visualization and structured expression, and various attribute data, a network security event is generated, presenting complete event content and automating the analysis and assessment of known threats. The analysis configuration module is used to build the analysis configuration platform.
6. The system according to claim 4, characterized in that: The security-related information includes one or more of the following: security capability alerts, system and traffic error logs, authentication behavior records, and access records.
7. The system according to claim 4, characterized in that: The security data baseline includes one or more of the following: security capability alarm baseline, system and traffic error log baseline, and authentication behavior record baseline.
8. The method according to claim 4, characterized in that: Multiple methods, including API, syslog, and URL, are used to acquire and merge heterogeneous datasets from multiple sources to form a trusted dataset.
9. An analysis system for practical offensive and defensive confrontation, characterized in that, The system includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to execute instructions in the program code to implement the method according to any one of claims 1-4.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store program code, which is executed by a processor to implement the method of any one of claims 1-4.
Citation Information
Patent Citations
Attack intention recognition method and device based on knowledge graph
CN116451230A
Strategic game modeling and state deduction device and system
CN116720746A