Attack attribution methods, devices, and electronic equipment based on attack digests

By converting the summary data values ​​of network streams into the color values ​​of image pixels, generating a summary representation map, and performing image matching, the problem of low accuracy in network stream data matching in existing technologies is solved, enabling precise tracing of the initial attacking host.

CN119449403BActive Publication Date: 2025-10-31BEIJING UNIV OF POSTS & TELECOMM +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411543799.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2025-10-31
Estimated Expiration
2044-10-31

AI Technical Summary

Technical Problem

Existing attack attribution methods do not have high accuracy in matching network flow data, especially after attackers add interference information, making it difficult to accurately locate the initial attacking host.

Method used

The summary data values ​​of the network stream to be matched are converted into the color values ​​of the pixels corresponding to the summary data values ​​in the image, generating a summary representation map. This map is then matched with the current attack link representation map using image matching technology to determine the initial attacking host.

Benefits of technology

The attack attribution method has improved its ability to resist interference information in the network flow, and has improved the accuracy and comprehensiveness of network attack attribution. It can accurately locate the initial attacking host even when there is interference information and some jump host is not monitored.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449403B_ABST
    Figure CN119449403B_ABST
Patent Text Reader

Abstract

This invention provides an attack attribution method, apparatus, and electronic device based on attack digests. The method includes: acquiring digest data values ​​of a network flow to be matched; converting the digest data values ​​into color values ​​of pixels corresponding to the digest data values ​​in an image to obtain a digest representation map of the network flow to be matched; performing image matching based on the digest representation map and a current attack link representation map to obtain a current image matching result; and determining the initial attack host based on the image matching result. The method and apparatus provided by this invention improve the anti-interference capability of the attack attribution method for interference information in the network flow to be matched by converting the digest data values ​​of the network flow to be matched into color values ​​of pixels corresponding to the digest data values ​​in an image to obtain a digest representation map of the network flow to be matched, and performing image matching based on the digest representation map and the current attack link representation map to determine the initial attack host. This enhances the accuracy of network attack attribution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an attack attribution method, apparatus, and electronic device based on attack digests. Background Technology

[0002] The internet has rapidly become an indispensable part of people's lives. However, with the increase in internet users, cyberattacks have also become more frequent. Therefore, the proliferation of cyberattacks and the resulting cybersecurity risks make cybersecurity protection particularly important. Current attack attribution methods mainly rely on flow correlation techniques, which are divided into active flow correlation and passive flow correlation. Passive flow correlation refers to determining whether multiple network flows belong to the same attack chain by extracting and analyzing network flow characteristics, such as packet size and time intervals between packets.

[0003] However, attackers often add interference to the forwarded attack stream, such as delaying interference or adding jamming packets, to avoid being traced back to the source. Therefore, the accuracy of network flow data matching in current attack attribution methods needs further improvement. Summary of the Invention

[0004] This invention provides an attack tracing method, apparatus, and electronic device based on attack digests, which addresses the shortcomings of existing attack tracing methods in terms of the low accuracy of matching network flow data.

[0005] This invention provides an attack attribution method based on attack digests, comprising:

[0006] Obtain the summary data value of the network stream to be matched;

[0007] The summary data value is converted into the color value of the pixel in the image corresponding to the summary data value to obtain the summary representation map of the network stream to be matched;

[0008] Image matching is performed based on the digest representation graph and the current attack link representation graph to obtain the current image matching result;

[0009] Based on the current image matching results, the initial attacking host is determined.

[0010] According to the attack attribution method based on attack digests provided by the present invention, the step of converting the digest data value into the color value of the pixel corresponding to the digest data value in the image to obtain the digest representation map of the network stream to be matched includes:

[0011] The summary data values ​​of the two flows in the network stream to be matched are converted into the gray values ​​of each pixel in the grayscale image, respectively, to obtain the upstream flow grayscale image and the downstream flow grayscale image;

[0012] The grayscale values ​​corresponding to each pixel in the upstream grayscale image are converted into color values ​​of the first color channel in the RGB image, and the grayscale values ​​corresponding to each pixel in the downstream grayscale image are converted into color values ​​of the second color channel in the RGB image to obtain the summary representation image.

[0013] According to the attack attribution method based on attack digest provided by the present invention, determining the initial attacking host based on the current image matching result includes:

[0014] The host that sends the network flow with a successful current image matching result is designated as the next hop host. The summary representation graphs of all inbound flows of the next hop host are matched until all current image matching results of the next hop host fail. Based on the current image matching results of network flows in the global network region, the initial attacking host is obtained.

[0015] According to the attack attribution method based on attack digest provided by the present invention, the method for obtaining the initial attacking host based on the current image matching result of network flow in a global network region includes:

[0016] If the current image matching result of all network flows in the global network area fails, the last next-hop host will be used as the initial attack host.

[0017] According to the attack attribution method based on attack digest provided by the present invention, the step of performing image matching based on the digest representation graph and the current attack link representation graph to obtain the current image matching result includes:

[0018] Based on the summary representation diagram of the previous image matching result being a successful match, the current attack link representation diagram is obtained;

[0019] Image matching is performed between the summary representation graph and the current attack link representation graph to obtain image relevance;

[0020] Based on the image correlation and the preset matching threshold, the current image matching result is obtained.

[0021] According to the attack attribution method based on attack digests provided by the present invention, the step of obtaining the current attack chain representation map based on the digest representation map of the previous image matching result being a successful match includes:

[0022] In the case where only the first historical jump host exists, the attack flow summary representation graph received by the victim host is used as the current attack link representation graph;

[0023] In the presence of multiple historical jump host hosts, the current attack link representation map is obtained by combining the image matching weight of the summary representation map where the previous image matching result was a successful match and the image matching weight of the historical attack link representation map.

[0024] The present invention also provides an attack attribution device based on attack digests, the device comprising:

[0025] The acquisition unit acquires the summary data value of the network stream to be matched;

[0026] The graph representation unit converts the summary data value into the color value of the pixel in the image corresponding to the summary data value, thereby obtaining the summary representation graph of the network stream to be matched;

[0027] The matching unit performs image matching based on the digest representation graph and the current attack link representation graph to obtain the current image matching result;

[0028] The attack tracing unit determines the initial attacking host based on the current image matching results.

[0029] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the attack attribution method based on attack digest as described above.

[0030] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the attack attribution method based on attack digest as described above.

[0031] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements an attack attribution method based on attack digest as described above.

[0032] The attack tracing method, apparatus, and electronic device based on attack digests provided by this invention convert the digest data value of the network stream to be matched into the color value of the pixel corresponding to the digest data value in an image to obtain a digest representation map of the network stream to be matched. Based on the digest representation map and the current attack link representation map, image matching is performed to determine the initial attack host. This improves the anti-interference ability of the attack tracing method against interference information in the network stream to be matched, thereby improving the accuracy of network attack tracing. Attached Figure Description

[0033] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0034] Figure 1 This is a flowchart illustrating the attack attribution method based on attack digests provided by the present invention.

[0035] Figure 2 This is a schematic diagram of the process for determining the initial attacking host provided by the present invention;

[0036] Figure 3 This is a flowchart illustrating the process of determining the attack chain representation diagram provided by the present invention;

[0037] Figure 4 This is one of the schematic diagrams illustrating the accuracy of the attack attribution method based on attack digest provided by this invention;

[0038] Figure 5 This is the second schematic diagram illustrating the accuracy of the attack attribution method based on attack digests provided by this invention.

[0039] Figure 6 This is a schematic diagram of the attack tracing device based on attack digest provided by the present invention;

[0040] Figure 7 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0042] The internet has rapidly become an indispensable part of people's lives. However, with the increase in internet users, cyberattacks have also become more frequent. At the same time, the types of cyberattacks are constantly expanding, including distributed denial-of-service (DDoS) attacks, phishing attacks, and malware.

[0043] Detecting and attributing cyberattacks are two crucial methods for mitigating cyber threats. However, attackers often employ various strategies to evade attribution, such as using spoofed IP addresses or anonymous networks. A common tactic used by attackers is to utilize hop hosts to forward attack traffic, making it difficult for the victim host to directly identify the source of the attack. This type of attack is called a hop attack. In a hop attack, attackers typically use a series of hop hosts as forwarding nodes. The attacker first sends the attack traffic to a hop host, which then forwards it through multiple hop hosts until it finally reaches the victim host. At this point, the victim host can only determine that the attack traffic originated from the last hop host, but cannot identify the original attacking host.

[0044] Current attack attribution methods primarily utilize flow correlation techniques, which are categorized into active and passive flow correlation. Passive flow correlation involves extracting and analyzing network flow characteristics, such as packet size and inter-packet time intervals, to determine whether multiple network flows belong to the same attack chain. Passive flow correlation does not require modification of network traffic, thus offering better stealth and significantly reducing the chance of attackers discovering the attribution of network attacks. Therefore, this attribution method is widely used in attack attribution.

[0045] However, attackers often add interference information to forwarded attack streams, such as delay interference or adding jamming packets, which reduces the accuracy of network stream data matching and increases the difficulty of attribution. To address this problem, this invention provides an attack attribution method based on attack digests to achieve highly effective and accurate network attack attribution. Figure 1 This is a flowchart illustrating the attack attribution method based on attack digests provided by this invention, as shown below. Figure 1 As shown, the method includes:

[0046] Step 110: Obtain the summary data value of the network stream to be matched;

[0047] Here, the network flow to be matched can refer to the network flow received by the host that sent the attack network flow received by the victim host. This host can be used as the current jump host, and the ingress network flow of the current jump host can be used as the network flow to be matched to determine the network flow containing the attack information in the ingress network flow of the current jump host, and then trace back to the next jump host, until the original attack host is traced back.

[0048] Additionally, the summary data values ​​here refer to data values ​​used to reflect the characteristics of network flows. These summary data values ​​can be packet length and packet interval time.

[0049] Specifically, network flow analysis tools can be used to capture the ingress flow of the jump host, and the packet length and packet interval in the network flow can be used as the digest data value of the network flow to be matched. It can be understood that this digest data value can be used as a basis for determining whether the network flow to be matched contains attack information.

[0050] Step 120: Convert the summary data value into the color value of the pixel in the image corresponding to the summary data value to obtain the summary representation map of the network stream to be matched;

[0051] Specifically, firstly, the image can be divided into multiple pixels; for example, the image region can be discretized into... Each pixel is represented by a vertical coordinate of the grayscale image, with 0 at the top and 1 at the bottom; the horizontal coordinate represents the time interval between data packets, with 0 at the leftmost and 1 at the rightmost. The grayscale value of each pixel in the image is set to 0. Thus, the entire range from 0 to 1 is discretized into 64 intervals, each interval having a width of [missing value]. This is to facilitate mapping the summary data values ​​to specific regions of the image. Therefore, the 1st to 64th intervals are respectively... , , ..., .

[0052] Then, the summary data values ​​of the two flows in the network stream to be matched can be converted into the grayscale values ​​of each pixel in a grayscale image, respectively, to obtain the grayscale images of the upstream flow and the downstream flow. For example, the normalized length value of data packet A in the network stream to be matched is... The data packet time interval is Then data packet A can be mapped to coordinate point A in the image ( , The pixel containing the upstream and downstream grayscale images is then identified. Finally, a summary representation of the network stream to be matched can be obtained by combining the upstream and downstream grayscale images.

[0053] It should be noted that by converting the summary data values ​​into pixels in the image corresponding to the summary data values, the summary data values ​​are discretely processed. This allows summary data with certain perturbations to still be mapped to the same pixel, reducing the impact of interference information in the attack flow on the generation of the summary representation graph. In turn, this reduces the impact of interference information in the attack flow on network flow data matching, greatly improving the accuracy of network flow summary data matching.

[0054] Step 130: Perform image matching based on the digest representation graph and the current attack link representation graph to obtain the current image matching result;

[0055] Here, the color value features of the current attack link representation graph can be used to reflect the characteristics of network flow summary data in the known attack link of the network attack suffered by the victim host.

[0056] Specifically, during the matching of network flows on the first hop host, the attack flow summary representation graph of the victim host is used as the current attack link representation graph. The generation steps for this attack flow summary representation graph are the same as the generation method for the summary representation graph of the network flows to be matched. During the matching of network flows on non-first hop hosts, the current attack link representation graph can be obtained by combining historical attack link representation graphs and successfully matched summary representation graphs.

[0057] Then, the summary representation map and the current attack link representation map can be input into the image matching model. The image matching model outputs the matching relevance between the two images, and the matching relevance between the summary representation map and the current attack link representation map can be used as the current image matching result. This current image matching result reflects the correlation between the network flow corresponding to the summary representation map and the current attack link. Finally, the matching relevance of the summary representation maps of all network flows to be matched can be compared with a preset matching threshold, and the current image matching result of the network flow with the highest matching degree can be recorded as a successful match.

[0058] Step 140: Based on the current image matching results, determine the initial attacking host.

[0059] Specifically, the host that sends a network flow with a successful current image matching result is designated as the next-hop host. Image matching of the summary representation graph of all inbound flows on the next-hop host is repeatedly performed until all current image matching results on the next-hop host fail, and the current image matching results of network flows within the global network area also fail. Then, the last next-hop host can be designated as the initial attacking host. Here, the initial attacking host refers to the host that initially launched the network attack.

[0060] The method provided in this invention converts the summary data value of the network stream to be matched into the color value of the pixel corresponding to the summary data value in the image to obtain a summary representation map of the network stream to be matched. Based on the summary representation map and the current attack link representation map, image matching is performed to determine the initial attack host. This improves the anti-interference ability of the attack tracing method for interference information in the network stream to be matched, thereby improving the accuracy of attack tracing.

[0061] Based on any of the above embodiments, step 120 includes:

[0062] The summary data values ​​of the two flows in the network stream to be matched are converted into the gray values ​​of each pixel in the grayscale image, respectively, to obtain the upstream flow grayscale image and the downstream flow grayscale image;

[0063] The grayscale values ​​corresponding to each pixel in the upstream grayscale image are converted into color values ​​of the first color channel in the RGB image, and the grayscale values ​​corresponding to each pixel in the downstream grayscale image are converted into color values ​​of the second color channel in the RGB image to obtain the summary representation image.

[0064] Here, the upstream and downstream grayscale images can respectively reflect the summary data features of the upstream and downstream flows in the network flow to be matched.

[0065] Specifically, the network stream to be matched can be viewed as a bidirectional stream. Then, by converting the summary data values ​​of the two streams in the network stream to be matched into grayscale values ​​of each pixel region in the grayscale image, the upstream stream grayscale image and the downstream stream grayscale image can be obtained.

[0066] In detail, for each initial grayscale image, it can be divided into: A pixel region, i.e. Each pixel has an initial grayscale value of 0. The normalized length and time interval of each packet can be extracted by iterating through the summary data values ​​of each packet in the single-flow network stream. Based on this data, the corresponding pixel in the grayscale image is located, and the grayscale value of that pixel is incremented by 1. It should be noted that the normalization of the summary data values ​​can be achieved using the following formula, as shown below:

[0067]

[0068] In the formula, This represents the normalized summary data value; This represents a summary data value of the network stream to be matched that is being processed; This represents the smallest summary data value in the network stream being processed for matching; This represents the largest summary data value in the network stream being processed for matching. It should be noted that all summary data values ​​in the network stream to be matched will be normalized to between 0 and 1.

[0069] Next, the grayscale values ​​of each pixel in the upstream grayscale image can be converted to the color values ​​of the first color channel in the RGB image, and the grayscale values ​​of each pixel in the downstream grayscale image can be converted to the color values ​​of the second color channel in the RGB image. For example, the grayscale values ​​of each pixel in the upstream grayscale image can be converted to the color values ​​of the blue channel in the RGB image; the grayscale values ​​of each pixel in the downstream grayscale image can be converted to the color values ​​of the green channel in the RGB image, and the color values ​​of the red channel can be set to 0, thus obtaining the summary representation map. It is understood that compared with grayscale images, RGB multi-channel images can more clearly and accurately reflect the bidirectional flow data characteristics of the network stream to be matched, thereby improving the matching accuracy and reliability of the summary representation map obtained based on the summary data values.

[0070] Based on any of the above embodiments, step 140 includes:

[0071] The host that sends the network flow with a successful current image matching result is designated as the next hop host. The summary representation graphs of all inbound flows of the next hop host are matched until all current image matching results of the next hop host fail. Based on the current image matching results of network flows in the global network region, the initial attacking host is obtained.

[0072] Specifically, the host that sends a network flow with a successful current image matching result can be designated as the next-hop host. Then, all inbound flows of the next-hop host are designated as the network flows to be matched by the next-hop host. Matching is performed on the network flows to be matched by the next-hop host to obtain the current image matching results for all network flows to be matched by the next-hop host. It can be understood that if there is a case where the current image matching result is successful, the host to which the successfully matched network flow belongs can continue to be designated as the next-hop host, and the network flow matching for the next-hop host can be performed in the next round until all current image matching results for the next-hop host fail. Then, based on the current image matching results of the network flows in the global network region, the initial attacking host can be obtained.

[0073] Compared to existing technologies that directly analyze network flow data characteristics to determine the initial attacking host, the method provided in this invention uses the host to which the network flow with a successful current image matching result belongs as the next hop host. It then matches the summary representation graph of the network flows to be matched on the next hop host until all current image matching results on the next hop host fail. Based on the current image matching results of network flows in the global network region, the initial attacking host is obtained, thus progressively determining the hop hosts in the network attack process and further improving the accuracy of network attack attribution.

[0074] It should be noted that, since not all host servers forwarding attack flows are within the monitoring range of internet service providers, the attribution process may be interrupted at these hosts. Based on any of the above embodiments, the initial attacking host is obtained based on the current image matching results of network flows in the global network area, including:

[0075] If the current image matching result of all network flows in the global network area fails, the last next-hop host will be used as the initial attack host.

[0076] Specifically, if the matching results of all current images of the next jump host fail, it means that the correlation between all network flows in the ingress flow of this jump host and the current attack link representation graph is less than a preset threshold. Therefore, the matching results of network flows in the global network region can be obtained. This involves taking the network flows within the entire network monitoring scope as the network flows to be matched, and matching the summary representation graph of the network flows in the global network region with the current attack link representation graph to obtain the current image matching results of the network flows in the global network region.

[0077] Understandably, if the current image matching result is successful when matching the summary representation graph of network flows within the global network area, the next hop host can be successfully identified. This next hop host may have multiple hop hosts that were not traced to the previous hop host, but this does not affect the ability to trace back to the initial attacking host. Therefore, by matching the summary representation graph of network flows within the global network area, "multi-hop iteration" is achieved to obtain the final initial attacking host. This overcomes the problem that some hop hosts outside the monitoring range of Internet service providers cannot be traced, improving the comprehensiveness and accuracy of attack attribution methods.

[0078] It should be noted that when performing image matching on the summary representation graph of network flow in the global network region, the preset threshold for comparing the degree of image matching can be appropriately lower than the preset threshold during single-hop iteration. For example, if the preset threshold during single-hop iteration is usually 80%, then the preset threshold here can be 60%.

[0079] If any network flow has a successful image matching result in the current image, the network flow with the highest matching degree is selected, and the sending host of that network flow can be used as the next hop host. Then, the image matching of the network flow summary representation graph is repeated, i.e., single-hop iteration is performed. If the single-hop iteration is interrupted again, the image matching of all network flows in the global network region is performed.

[0080] If the current image matching result of the network flow in the global network area fails, it means that there is no network flow in the global network area that matches the current attack link representation graph. In this case, the last next-hop host can be considered to be the original attack host.

[0081] For example, in one embodiment, Figure 2 This is a schematic diagram of the process for determining the initial attacking host provided by the present invention, as shown below. Figure 2 As shown, the process includes: First, a single-hop iteration is performed, that is, the attack link representation graph is matched with each ingress flow of the current jump host to determine if a matching ingress flow is found. If a match is found, the next jump host is successfully determined, i.e., the host that sent the successfully matched ingress flow. Then, the attack link representation graph is updated based on the digest representation graph of the successfully matched ingress flow, and step 1: single-hop iteration is repeated. If no matching ingress flow is found, step 2: multi-hop iteration is performed, that is, a matching network flow is searched for across the entire monitoring range to determine if a matching network flow is found. If a match is found, the next jump host is successfully determined, and the attack link representation graph is updated based on the digest representation graph of the successfully matched network flow, and step 1: single-hop iteration is repeated. In multi-hop iteration, if no matching network flow is found, the last jump host is taken as the initial attack host.

[0082] The method provided in this invention addresses the issue of hop hosts in network attacks and the problem of a hop host being outside the monitoring range of an Internet service provider. It uses single-hop iteration and multi-hop iteration methods to determine the initial attacking host of the entire attack chain, achieving comprehensive and accurate network attack tracing.

[0083] Based on any of the above embodiments, step 130 includes:

[0084] Based on the summary representation diagram of the previous image matching result being a successful match, the current attack link representation diagram is obtained;

[0085] Image matching is performed between the summary representation graph and the current attack link representation graph to obtain image relevance;

[0086] Based on the image relevance and the preset matching threshold, the current image matching result is obtained.

[0087] Specifically, firstly, the historical attack link representation map can be updated based on the summary representation map of the previous image matching result, which is a successful match, to obtain the current attack link representation map.

[0088] Then, the summary representation map to be matched and the current attack link representation map can be input into the image matching model built on a convolutional neural network (CNN). The image matching model outputs the image relevance of the summary representation map. Here, the CNN consists of three convolutional layers and three fully connected layers. After each convolutional layer, there is a max pooling layer. To facilitate the subsequent update of the attack link representation map, an attention layer is added after the last fully connected layer to obtain the attention weights of the CNN for different parts of the input image, i.e., the image matching weights for image sub-regions. That is, the attention layer in the CNN is needed during the update process. The attention layer in the CNN-based matching algorithm can generate a heatmap using the attention mechanism, showing the image regions that the CNN pays special attention to during the matching process. Thus, by leveraging the advantages of CNNs in image matching, network attack attribution can be traced with high accuracy.

[0089] Furthermore, the image relevance of the entire summary representation graph can be compared with a preset matching threshold. When the image relevance is greater than or equal to the preset matching threshold, the current image matching result of the network stream with the highest matching degree is recorded as a successful match. When the matching degree is less than the preset matching threshold, the current image matching result is considered a failed match.

[0090] The method provided in this invention transforms the parameter data of the network stream to be matched into color value data of the summary representation graph, and reflects the correlation of attack features between two network streams through the correlation of image matching, which greatly improves the accuracy of network attack tracing.

[0091] Based on any of the above embodiments, obtaining the current attack link representation graph based on the summary representation graph of the previous image matching result being a successful match includes:

[0092] In the case where only the first historical jump host exists, the attack flow summary representation graph received by the victim host is used as the current attack link representation graph;

[0093] In the presence of multiple historical jump host hosts, the current attack link representation map is obtained by combining the image matching weight of the summary representation map where the previous image matching result was a successful match and the image matching weight of the historical attack link representation map.

[0094] Specifically, when only one historical hop host exists (i.e., during the initial matching of the hop host's ingress flow), the attack flow summary representation graph received by the victim host can be used as the current attack link representation graph. This graph is then used for image matching with the summary representation graphs of the network flows to be matched, thus determining the next hop host. When multiple historical hop hosts exist, indicating that a successfully matched network flow contains attack information, the image matching weights of the previously successfully matched summary representation graph and the historical attack link representation graphs can be used to combine the previously successfully matched summary representation graph and the historical attack link representation graphs to obtain the current attack link representation graph.

[0095] For example, when only the first historical jump host exists, the current attack chain representation graph can be obtained by combining the successfully matched digest representation graph with the attack flow digest representation graph. Here, the combination of the current attack chain representation graphs can be achieved using the following formula, as shown below:

[0096]

[0097] In the formula, This represents the current attack chain diagram obtained after a successful match when only the first historical jump host exists. This represents a summary graph of the attack flow. This represents the image matching weights of the attack flow summary representation graph after the heatmap of the attack flow at the victim host is normalized during the matching process of the convolutional neural network. This represents the summary diagram of a successful match when only the first historical jump host exists. The summary indicating a successful match represents the image matching weight of the graph.

[0098] When multiple historical jump host hosts exist, i.e., when the image matching result is successful before the first attempt, the current attack link representation map can be obtained by combining the summary representation map of the previous successful match and the historical attack link representation map obtained from the previous update. For example, this can be achieved using the following formula, as shown below:

[0099]

[0100] In the formula, This represents the updated current attack chain diagram; This represents the attack chain diagram obtained from the last update; This represents a summary diagram of the last successful match; This represents the image matching weights. Wherein, Each pixel in the newly determined summary representation is assigned a weight. Then, the weighted network flow image is added to the attack link representation obtained from the previous update. The result is normalized and distributed to the maximum color value range. The resulting image is the attack link representation.

[0101] It should be noted that the above process is performed to update the current attack link representation map after each network flow located on the attack link is confirmed. After multiple iterations, the color values ​​of certain areas in the attack link representation map will be significantly higher than those of other parts, thus reflecting the characteristics of the entire attack link. When tracing back to the initial attacking host, the image shows the characteristics of the entire attack link from the initial attacking host to the victim host.

[0102] The method provided in this invention uses image matching weights generated by a convolutional neural network to emphasize more important parts of the attack flow representation graph and add them to the current attack link representation graph, which more clearly reflects the characteristics of the attack link, making the matching of the network flow summary representation graph more accurate and reliable.

[0103] Figure 3 This is a flowchart illustrating the determination of the attack chain representation provided by the present invention, as shown below. Figure 3 As shown, the process includes: First, inputting the attack link representation graph and the summary representation graph of the network flow to be matched into a convolutional neural network, and outputting the matching result through the convolutional neural network. It should be noted that for the attack link representation graph, when only the first historical jump host exists, the summary representation graph of the attack flow at the victim host is used instead. Then, it is determined whether the match is successful. If the match fails, a new network flow that may be located on the attack link is selected for matching; for example, it could be other ingress flows of the host, or other network flows within the entire monitoring range. If the match is successful, the attack link representation graph is updated (generated) using an attack link representation graph update (generation) algorithm, and then matched with the next network flow.

[0104] Based on any of the above embodiments, simulation experiments show that the attack tracing method based on attack digest proposed in this invention can still complete the attack chain tracing and the initial attack host tracing with high accuracy even when there is interference information in the attack flow and some jump host is outside the monitoring range of Internet service providers, and has a very good network attack tracing effect. Figure 4 This is one of the schematic diagrams illustrating the accuracy of the attack attribution method based on attack digests provided by this invention, such as... Figure 4The diagram shows the accuracy of attack host tracing and attack link tracing when the number of all hosts within the global monitoring scope is 20, and the number of jump host hosts varies from 1 to 10. It can be observed that when the number of hosts globally is 20 and the number of jump host hosts is less than 6, attack host tracing and attack link tracing can be completed with high accuracy. Figure 5 This is the second schematic diagram illustrating the accuracy of the attack attribution method based on attack digests provided by this invention. Figure 5 The diagram illustrates the accuracy of attack host tracing and attack chain tracing when the number of jump hosts in the attack chain is 5, and the number of all hosts in the global scope varies from 5 to 50. It can be observed that when the number of jump hosts is 5 and the number of all hosts in the monitoring range is less than 25, attack host tracing and attack chain tracing can be completed with high accuracy.

[0105] Based on any of the above embodiments Figure 6 This is a schematic diagram of the attack tracing device based on attack digests provided by the present invention, as shown below. Figure 6 As shown, the device includes:

[0106] The acquisition unit 610 acquires the summary data value of the network stream to be matched;

[0107] The image representation unit 620 converts the summary data value into the color value of the pixel corresponding to the summary data value in the image to obtain the summary representation image of the network stream to be matched;

[0108] Matching unit 630 performs image matching based on the digest representation graph and the current attack link representation graph to obtain the current image matching result;

[0109] The attack tracing unit 640 determines the initial attacking host based on the current image matching result.

[0110] The apparatus provided in this embodiment of the invention converts the summary data value of the network stream to be matched into the color value of the pixel corresponding to the summary data value in the image to obtain a summary representation map of the network stream to be matched. Based on the summary representation map and the current attack link representation map, image matching is performed to determine the initial attack host. This improves the anti-interference ability of the attack tracing method for interference information in the network stream to be matched, thereby improving the accuracy of network attack tracing.

[0111] Based on any of the above embodiments, the diagram representation unit is specifically used for:

[0112] The summary data values ​​of the two flows in the network stream to be matched are converted into the gray values ​​of each pixel in the grayscale image, respectively, to obtain the upstream flow grayscale image and the downstream flow grayscale image;

[0113] The grayscale values ​​corresponding to each pixel in the upstream grayscale image are converted into color values ​​of the first color channel in the RGB image, and the grayscale values ​​corresponding to each pixel in the downstream grayscale image are converted into color values ​​of the second color channel in the RGB image to obtain the summary representation image.

[0114] Based on any of the above embodiments, the attack tracing unit is specifically used for:

[0115] The host that sends the network flow with a successful current image matching result is designated as the next hop host. The summary representation graphs of all inbound flows of the next hop host are matched until all current image matching results of the next hop host fail. Based on the current image matching results of network flows in the global network region, the initial attacking host is obtained.

[0116] Based on any of the above embodiments, the attack tracing unit is further specifically used for:

[0117] If the current image matching result of all network flows in the global network area fails, the last next-hop host will be used as the initial attack host.

[0118] Based on any of the above embodiments, the matching unit is specifically used for:

[0119] Based on the summary representation diagram of the previous image matching result being a successful match, the current attack link representation diagram is obtained;

[0120] Image matching is performed between the summary representation graph and the current attack link representation graph to obtain image relevance;

[0121] Based on the image relevance and the preset matching threshold, the current image matching result is obtained.

[0122] Based on any of the above embodiments, the matching unit is further specifically used for:

[0123] In the case where only the first historical jump host exists, the attack flow summary representation graph received by the victim host is used as the current attack link representation graph;

[0124] In the presence of multiple historical jump host hosts, the current attack link representation map is obtained by combining the image matching weight of the summary representation map where the previous image matching result was a successful match and the image matching weight of the historical attack link representation map.

[0125] Figure 7 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 7As shown, the electronic device may include a processor 710, a communications interface 720, a memory 730, and a communication bus 740, wherein the processor 710, communications interface 720, and memory 730 communicate with each other via the communication bus 740. The processor 710 can invoke logical instructions in the memory 730 to execute an attack attribution method based on attack digests. This method includes: acquiring digest data values ​​of a network flow to be matched; converting the digest data values ​​into color values ​​of pixels corresponding to the digest data values ​​in an image to obtain a digest representation map of the network flow to be matched; performing image matching based on the digest representation map and the current attack link representation map to obtain a current image matching result; and determining the initial attacking host based on the current image matching result.

[0126] Furthermore, the logical instructions in the aforementioned memory 730 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0127] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the attack tracing method based on attack digests provided by the above methods. The method includes: obtaining a digest data value of a network flow to be matched; converting the digest data value into the color value of a pixel in an image corresponding to the digest data value to obtain a digest representation map of the network flow to be matched; performing image matching based on the digest representation map and the current attack link representation map to obtain a current image matching result; and determining the initial attacking host based on the current image matching result.

[0128] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements an attack tracing method based on attack digests provided by the methods described above. This method includes: acquiring a digest data value of a network flow to be matched; converting the digest data value into the color value of a pixel in an image corresponding to the digest data value, to obtain a digest representation map of the network flow to be matched; performing image matching based on the digest representation map and a current attack link representation map to obtain a current image matching result; and determining the initial attacking host based on the current image matching result.

[0129] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0130] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An attack attribution method based on attack digests, characterized in that, include: Obtain the summary data value of the network stream to be matched; The summary data value is converted into the color value of the pixel in the image corresponding to the summary data value to obtain the summary representation map of the network stream to be matched; Image matching is performed based on the digest representation graph and the current attack link representation graph to obtain the current image matching result; Based on the current image matching results, the initial attacking host is determined; The step of converting the summary data value into the color value of the pixel corresponding to the summary data value in the image to obtain the summary representation map of the network stream to be matched includes: The summary data values ​​of the two flows in the network stream to be matched are converted into the gray values ​​of each pixel in the grayscale image, respectively, to obtain the upstream flow grayscale image and the downstream flow grayscale image; The grayscale values ​​corresponding to each pixel in the upstream grayscale image are converted into color values ​​of the first color channel in the RGB image, and the grayscale values ​​corresponding to each pixel in the downstream grayscale image are converted into color values ​​of the second color channel in the RGB image to obtain the summary representation image. The step of determining the initial attacking host based on the current image matching result includes: The host that sends the network flow with a successful current image matching result is designated as the next hop host. The summary representation graphs of all inbound flows of the next hop host are matched until all current image matching results of the next hop host fail. Based on the current image matching results of network flows in the global network region, the initial attacking host is obtained.

2. The attack attribution method based on attack digests according to claim 1, characterized in that, The initial attacking host is obtained by matching the current image results of network flows under the global network region, including: If the current image matching result of all network flows in the global network area fails, the last next-hop host will be used as the initial attack host.

3. The attack attribution method based on attack digests according to any one of claims 1 to 2, characterized in that, The step of performing image matching based on the digest representation graph and the current attack link representation graph to obtain the current image matching result includes: Based on the summary representation diagram of the previous image matching result being a successful match, the current attack link representation diagram is obtained; Image matching is performed between the summary representation graph and the current attack link representation graph to obtain image relevance; Based on the image relevance and the preset matching threshold, the current image matching result is obtained.

4. The attack attribution method based on attack digests according to claim 3, characterized in that, The current attack chain representation graph is obtained based on the summary representation graph of the previous image matching result being a successful match, including: In the case where only the first historical jump host exists, the attack flow summary representation graph received by the victim host is used as the current attack link representation graph; In the presence of multiple historical jump host hosts, the current attack link representation map is obtained by combining the image matching weight of the summary representation map where the previous image matching result was a successful match and the image matching weight of the historical attack link representation map.

5. An attack tracing device based on attack digests, characterized in that, include: The acquisition unit acquires the summary data value of the network stream to be matched; The graph representation unit converts the summary data value into the color value of the pixel in the image corresponding to the summary data value, thereby obtaining the summary representation graph of the network stream to be matched; The matching unit performs image matching based on the digest representation graph and the current attack link representation graph to obtain the current image matching result; The attack tracing unit determines the initial attacking host based on the current image matching result; The graphic representation unit is specifically used for: The summary data values ​​of the two flows in the network stream to be matched are converted into the gray values ​​of each pixel in the grayscale image, respectively, to obtain the upstream flow grayscale image and the downstream flow grayscale image; The grayscale values ​​corresponding to each pixel in the upstream grayscale image are converted into color values ​​of the first color channel in the RGB image, and the grayscale values ​​corresponding to each pixel in the downstream grayscale image are converted into color values ​​of the second color channel in the RGB image to obtain the summary representation image. The attack tracing unit is specifically used for: The host that sends the network flow with a successful current image matching result is designated as the next hop host. The summary representation graphs of all inbound flows of the next hop host are matched until all current image matching results of the next hop host fail. Based on the current image matching results of network flows in the global network region, the initial attacking host is obtained.

6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the attack tracing method based on attack digest as described in any one of claims 1 to 4.

7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the attack tracing method based on attack digest as described in any one of claims 1 to 4.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the attack tracing method based on attack digest as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Attack tracing method, related data processing method and device, and associated display method and device

    CN115412274A

  • Data information security protection method

    CN116684181A