Methods, devices, servers, media, and products for processing network attack data
By constructing a heterogeneous network graph and obtaining its embedding vectors for classification, the problem of network attackers hiding malicious code features is solved, the accuracy of homology analysis is improved, and precise identification of network attacks is achieved.
Patent Information
- Application Number
- CN202411813407.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-10
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2044-12-10
AI Technical Summary
In existing technologies for analyzing the origins of cyberattacks, attackers use code obfuscation techniques to hide the true characteristics of malicious code, which reduces the accuracy of the analysis.
By receiving target network attack paths, historical domain name system data, and network traffic data, a network heterogeneous graph of a preset order is constructed for each node. The embedding vector of the heterogeneous graph is obtained, and the heterogeneous graph type is obtained based on the vector of the heterogeneous graph for homology analysis.
It improves the accuracy of network attack homology analysis, and can comprehensively consider all nodes and their relationships in the target network attack path to achieve more accurate attack source identification.
Smart Images

Figure CN119544366B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, server, medium and product for processing network attack data. Background Technology
[0002] Cyberattacks are complex and diverse, and their methods are constantly evolving with technological advancements. Cyberattack organizations employ strategies to target specific individuals or groups. These targeted attacks not only cause losses to the victims but also threaten cybersecurity. Analyzing the origins of cyberattacks is a crucial method for identifying cyberattack organizations.
[0003] Currently, existing technologies perform homology analysis on network attacks by analyzing samples of malicious code used in the attacks.
[0004] However, cyber attackers often use techniques such as code obfuscation to hide the true characteristics of malicious code, which increases the difficulty of conducting homology analysis on cyber attacks and reduces the accuracy of homology analysis. Summary of the Invention
[0005] This application provides methods, apparatus, servers, media, and products for processing network attack data, in order to improve the accuracy of network attack homology analysis.
[0006] In a first aspect, embodiments of this application provide a data processing method for network attacks, comprising: receiving a target network attack path, historical domain name system data, and network traffic data sent by a data acquisition device; acquiring all nodes in the target network attack path; acquiring a network heterogeneous graph of a preset order for each node based on the historical domain name system data, network traffic data, and a predefined heterogeneous graph network pattern; merging the network heterogeneous graphs of the preset order for all nodes according to the target network attack path to obtain a heterogeneous graph corresponding to the target network attack path; acquiring the embedding vector of each node in the heterogeneous graph to obtain a heterogeneous graph with node embedding vectors; obtaining a vector of the heterogeneous graph based on the heterogeneous graph with node embedding vectors; classifying the heterogeneous graph based on the vector of the heterogeneous graph to obtain a heterogeneous graph type; outputting the heterogeneous graph type; the heterogeneous graph type is used for homogeneity analysis of network attacks.
[0007] In one possible implementation, a network heterogeneous graph of a preset order is obtained for each node based on historical domain name system data, network traffic data, and a predefined heterogeneous graph network pattern. This includes: obtaining historical domain name system data related to each node from the historical domain name system data; obtaining network traffic data related to each node from the network traffic data; and obtaining a network heterogeneous graph of a preset order for each node, centered on each node, based on the historical domain name system and network traffic data related to each node, and the predefined heterogeneous graph network pattern.
[0008] In one possible implementation, obtaining the embedding vector of each node in the heterogeneous graph includes: sampling the heterogeneous neighbor nodes of each node in the heterogeneous graph to obtain multiple heterogeneous neighbor nodes; extracting features from each heterogeneous neighbor node according to the type of each heterogeneous neighbor node to obtain the features of each heterogeneous neighbor node; encoding the features of each heterogeneous neighbor node to obtain the encoded features of each heterogeneous neighbor node; and aggregating the encoded features of multiple heterogeneous neighbor nodes to obtain the embedding vector of each node.
[0009] In one possible implementation, the encoded features of multiple heterogeneous neighbor nodes are aggregated to obtain the embedding vector of each node, including: obtaining the type of each heterogeneous neighbor node; aggregating heterogeneous neighbor nodes of the same type among multiple heterogeneous neighbor nodes to obtain initial embedding vectors of different types among multiple heterogeneous neighbor nodes; and aggregating the initial embedding vectors of different types among multiple heterogeneous neighbor nodes to obtain the embedding vector of each node.
[0010] In one possible implementation, obtaining a vector of a heterogeneous graph from a heterogeneous graph with node embedding vectors includes performing convolution and pooling operations on the heterogeneous graph with node embedding vectors to obtain a vector of the heterogeneous graph.
[0011] Secondly, embodiments of this application provide a network attack data processing apparatus, comprising:
[0012] The receiving module is used to receive target network attack paths, historical domain name system data, and network traffic data sent by the data acquisition device;
[0013] The first acquisition module is used to acquire all nodes in the target network attack path;
[0014] The second acquisition module is used to acquire a network heterogeneous graph of a preset order for each node based on historical domain name systems, network traffic data, and predefined heterogeneous graph network patterns.
[0015] The merging module is used to merge the heterogeneous graphs of all nodes of a preset order according to the target network attack path, so as to obtain the heterogeneous graph corresponding to the target network attack path.
[0016] The third acquisition module is used to acquire the embedding vector of each node in the heterogeneous graph to obtain a heterogeneous graph with node embedding vectors.
[0017] The fourth acquisition module is used to obtain the vector of the heterogeneous graph based on the heterogeneous graph with node embedding vectors;
[0018] The classification module is used to classify heterogeneous graphs based on their vectors and obtain the type of heterogeneous graph.
[0019] The output module is used to output heterogeneous graph types; heterogeneous graph types are used for homogeneity analysis of network attacks.
[0020] In one possible implementation, the second acquisition module is specifically used to: acquire historical domain name system data related to each node from the historical domain name system data; acquire network traffic data related to each node from the network traffic data; and acquire a network heterogeneous graph of a preset order for each node, centered on each node, based on the historical domain name system data and network traffic data related to each node, as well as a predefined heterogeneous graph network pattern.
[0021] Thirdly, embodiments of this application provide a server, including: a memory and a processor;
[0022] The memory stores computer-executed instructions;
[0023] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.
[0024] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.
[0025] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0026] The network attack data processing method, apparatus, server, medium, and product provided in this application embodiment obtain a network heterogeneous graph of a preset order for each node based on historical domain name system data, network traffic data, and a predefined heterogeneous graph network pattern; merge the network heterogeneous graphs of preset orders for all nodes based on the target network attack path to obtain a heterogeneous graph of the target network attack path; obtain the embedding vector of each node in the heterogeneous graph, and obtain the vector of the heterogeneous graph based on the embedding vector of each node in the heterogeneous graph; classify the heterogeneous graph based on the vector of the heterogeneous graph to obtain the heterogeneous graph type; and perform homogeneity analysis on the network attack through the heterogeneous graph type. By combining the heterogeneous graph network pattern and all nodes in the target network attack path to obtain the heterogeneous graph, it is possible to comprehensively consider all nodes in the target network attack path and the relationships between all nodes. By obtaining the heterogeneous graph type based on the vector of the heterogeneous graph, homogeneity analysis of the network attack is realized, thereby improving the accuracy of homogeneity analysis. Attached Figure Description
[0027] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0028] Figure 1 A schematic diagram illustrating a scenario for a method of processing network attack data provided in an embodiment of this application;
[0029] Figure 2 A flowchart illustrating the method for processing network attack data provided in this application embodiment;
[0030] Figure 3 A schematic diagram of a network attack path provided for an embodiment of this application;
[0031] Figure 4 A schematic diagram of the structure of the network attack data processing device provided in the embodiments of this application;
[0032] Figure 5 This is a schematic diagram of the server structure provided in an embodiment of this application.
[0033] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0034] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0035] Figure 1 This is a schematic diagram of a scenario for a method of processing network attack data provided in an embodiment of this application, such as... Figure 1 As shown, the specific application scenarios of this application include data acquisition device 101 and server 102.
[0036] refer to Figure 1 The data acquisition device 101 sends the target network attack path, historical domain name system data, and network traffic data to the server 102. The server 102 performs a series of processes based on the target network attack path, historical domain name system data, and network traffic data to obtain the heterogeneous graph corresponding to the target network attack path, and then obtains the heterogeneous graph type. The server 102 outputs the heterogeneous graph type to the display terminal for display.
[0037] Cyberattacks are complex and diverse, and their methods are constantly evolving with technological advancements. Cyberattack organizations employ strategies to target specific individuals or groups. These targeted attacks not only cause losses to the victims but also threaten cybersecurity. Attack origination analysis is a crucial method for identifying cyberattack organizations. Currently, existing technologies analyze samples of malicious code used in cyberattacks to determine their origin. However, attackers often employ techniques such as code obfuscation to conceal the true nature of their malicious code, increasing the difficulty of origination analysis and reducing its accuracy.
[0038] To address the aforementioned technical problems, this application proposes the following technical approach: Considering that analyzing samples of malicious code used in network attacks reduces the accuracy of homology analysis, the inventors devised a method that combines the target network attack path with a predefined heterogeneous graph network pattern. This involves analyzing all nodes in the target network attack path, constructing a heterogeneous graph of a preset order for each node, and thus obtaining the heterogeneous graph corresponding to the target network attack path. The inventors then obtain the vectors of the heterogeneous graphs, classify them based on these vectors, and determine the heterogeneous graph type. Finally, they perform homology analysis on network attacks using the heterogeneous graph type, thereby improving the accuracy of homology analysis.
[0039] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0040] Figure 2 A flowchart illustrating the method for processing network attack data provided in this application embodiment is shown below. Figure 2 As shown, the method includes:
[0041] S201: Receive target network attack paths, historical domain name system data, and network traffic data sent by the data acquisition device.
[0042] In this embodiment, a network attack is the result of an attacker conducting several reconnaissance and attacks through multiple attack springboards. The network attack path is an ordered list of devices from the first springboard to the target device.
[0043] For example, Figure 3 This is a schematic diagram of a network attack path provided for an embodiment of this application. Figure 3 As shown, the attacker uses a jump server to connect through n jump server devices to launch a network attack on the target device. After completing the attack, the attacker obtains sensitive data from the target device and sends the data back to the attacker.
[0044] Among them, Domain Name System (DNS) data records the mapping relationship between domain names and IP addresses; network traffic data is generated by network devices and is used to record detailed information about network traffic, such as source IP address, destination IP address, source port, destination port, protocol type, and traffic size.
[0045] S202: Obtain all nodes in the target network attack path.
[0046] For example, there are n nodes in the target network attack path P, i.e. .
[0047] S203: Based on historical domain name system data, network traffic data, and predefined heterogeneous graph network patterns, obtain a network heterogeneous graph of a preset order for each node.
[0048] Among them, the predefined heterogeneous graph network pattern is predefined.
[0049] In this embodiment, the predefined heterogeneous graph network pattern defines three types of nodes, including IP addresses, URLs, and domain names. Table 1 shows the node definitions in the predefined heterogeneous graph network pattern.
[0050] Table 1. Node definitions in predefined heterogeneous graph network patterns
[0051]
[0052] In this embodiment, the predefined heterogeneous graph network pattern defines four types of edges, including: IP address connecting IP addresses, IP address requesting URLs, IP address hosting domain names, and URL similarity. Table 2 shows the edge definitions in the predefined heterogeneous graph network pattern.
[0053] Table 2. Edge definitions in predefined heterogeneous graph network patterns
[0054]
[0055] Specifically, historical domain name system data related to each node is obtained from historical domain name system data; network traffic data related to each node is obtained from network traffic data; and a network heterogeneous graph of a preset order is obtained for each node, centered on each node, based on the historical domain name system data and network traffic data related to each node, as well as a predefined heterogeneous graph network pattern.
[0056] For example, obtain node N C The process of obtaining a heterogeneous graph of an r-order network is as follows:
[0057] First-order heterogeneous network graph: based on N C Relevant historical domain name system data and network traffic data, obtain information related to N C Directly related nodes are added to the heterogeneous graph of the network, and corresponding edges are established.
[0058] For each order of network heterogeneity (r>1), consider N C Indirectly related nodes. These nodes may be connected through N. C Directly related nodes are connected, or N is connected via a longer path. C Connect these nodes and them to N. C Edges from other nodes are added to the heterogeneous graph of the network. When expanded to a specified order r, node N is obtained. C A heterogeneous network graph of order r.
[0059] According to the above node N C The process of obtaining the r-order heterogeneous graph of a network is to obtain the r-order heterogeneous graph of each node in the target network attack path P.
[0060] S204: Based on the target network attack path, merge the heterogeneous graphs of all nodes of a preset order to obtain the heterogeneous graph corresponding to the target network attack path.
[0061] For example, the heterogeneous graphs of the network of order r for each node are merged according to the target attack path to obtain the heterogeneous graph of the target network attack path.
[0062] In this embodiment, the heterogeneous graph of the target network attack path reflects the node characteristics and topological structure characteristics of the attack path.
[0063] S205: Obtain the embedding vector of each node in the heterogeneous graph to obtain a heterogeneous graph with node embedding vectors.
[0064] In this embodiment, the embedding vector of each node in the heterogeneous graph is obtained based on the heterogeneous graph neural network.
[0065] Specifically, step S205 includes S2051 to S2054:
[0066] S2051: Sample the heterogeneous neighbor nodes of each node in the heterogeneous graph to obtain multiple heterogeneous neighbor nodes.
[0067] Specifically, a random walk method based on a restart strategy is used to sample a fixed number of heterogeneous neighbor nodes for each node.
[0068] S2052: Based on the type of each heterogeneous neighbor node, perform feature extraction on each heterogeneous neighbor node to obtain the features of each heterogeneous neighbor node.
[0069] Optionally, feature extraction can be performed on different types of neighbor nodes, such as extracting traffic statistics features from IP address nodes; and extracting resolution features and text features from domain name nodes.
[0070] S2053: Encode the features of each heterogeneous neighbor node to obtain the encoded features of each heterogeneous neighbor node.
[0071] In this embodiment, a neural network is used to encode the features of each heterogeneous neighbor node.
[0072] S2054: Aggregate the encoded features of multiple heterogeneous neighbor nodes to obtain the embedding vector of each node.
[0073] Specifically, step S2054 includes Sa~Sc:
[0074] Sa: Get the type of each heterogeneous neighbor node.
[0075] For example, types include domain names, URLs, and IP addresses.
[0076] Sb: Aggregate heterogeneous neighbor nodes of the same type among multiple heterogeneous neighbor nodes to obtain initial embedding vectors of different types of multiple heterogeneous neighbor nodes.
[0077] Optionally, for heterogeneous neighbor nodes of the same type, a bidirectional long short-term memory network is used to aggregate their encoded features, and then a pooling layer, such as max pooling or average pooling, is used to reduce the dimensionality of the output of the bidirectional long short-term memory network to obtain the initial embedding vector of the heterogeneous neighbor nodes of that type.
[0078] Sc: Aggregate the initial embedding vectors of different types from multiple heterogeneous neighbor nodes to obtain the embedding vector of each node.
[0079] Optionally, an attention mechanism can be used to perform a weighted summation of the initial embedding vectors of heterogeneous neighbor nodes of different types to obtain the embedding vector of each node.
[0080] S206: Obtain the vector of the heterogeneous graph from the heterogeneous graph with node embedding vectors.
[0081] S207: Based on the vectors of the heterogeneous graph, classify the heterogeneous graph and obtain the heterogeneous graph type.
[0082] Optionally, based on the vectors of the heterogeneous graph, an unsupervised or semi-supervised learning algorithm can be used to classify the heterogeneous graph.
[0083] S208: Output heterogeneous graph type; heterogeneous graph type is used for homogeneity analysis of network attacks.
[0084] Among them, heterogeneous graphs of the same type have similarities, and the corresponding network attacks come from the same or related attackers.
[0085] In summary, based on historical domain name system data, network traffic data, and predefined heterogeneous graph network patterns, a network heterogeneous graph of a preset order is obtained for each node. Based on the target network attack path, the network heterogeneous graphs of all nodes of the preset order are merged to obtain the heterogeneous graph of the target network attack path. The embedding vector of each node in the heterogeneous graph is obtained, and the vector of the heterogeneous graph is obtained based on the embedding vector of each node. Based on the vector of the heterogeneous graph, the heterogeneous graph is classified to obtain the heterogeneous graph type. Homology analysis of network attacks is performed through the heterogeneous graph type. By combining the heterogeneous graph network pattern and all nodes in the target network attack path to obtain the heterogeneous graph, it is possible to comprehensively consider all nodes in the target network attack path and the relationships between all nodes. Obtaining the heterogeneous graph type based on the vector of the heterogeneous graph enables homogeneity analysis of network attacks, thereby improving the accuracy of homogeneity analysis.
[0086] Based on the above embodiments, this embodiment describes the process of obtaining the vector of the heterogeneous graph from the heterogeneous graph with node embedding vectors in step S206 of the previous embodiment, as detailed below:
[0087] Perform convolution and pooling operations on a heterogeneous graph with node embedding vectors to obtain vectors of the heterogeneous graph.
[0088] Specifically, a heterogeneous graph with node embedding vectors is used as input to a graph convolutional neural network pair. The node representations are updated through the convolution operation of the graph convolutional neural network. The updated nodes are then pooled to form a single vector, namely the heterogeneous graph vector.
[0089] Optionally, pooling operations include global average pooling, global max pooling, and attention pooling.
[0090] In summary, convolution and pooling operations yield vectors of heterogeneous graphs. Convolution reduces the number of times nodes and edges are processed, improving efficiency; while pooling operations typically produce vectors with fixed dimensions and formats, facilitating subsequent classification and analysis of the heterogeneous graphs.
[0091] Figure 4 This is a schematic diagram of the structure of the network attack data processing device provided in the embodiments of this application, as shown below. Figure 4 As shown, the network attack data processing device provided in this embodiment includes: a receiving module 401, a first acquisition module 402, a second acquisition module 403, a merging module 404, a third acquisition module 405, a fourth acquisition module 406, a classification module 407, and an output module 408.
[0092] The receiving module 401 is used to receive the target network attack path, historical domain name system data and network traffic data sent by the data acquisition device;
[0093] The first acquisition module 402 is used to acquire all nodes in the target network attack path;
[0094] The second acquisition module 403 is used to acquire a network heterogeneous graph of a preset order for each node based on historical domain name system data, network traffic data and a predefined heterogeneous graph network pattern.
[0095] The merging module 404 is used to merge the heterogeneous graphs of all nodes of a preset order according to the target network attack path to obtain the heterogeneous graph corresponding to the target network attack path.
[0096] The third acquisition module 405 is used to acquire the embedding vector of each node in the heterogeneous graph to obtain a heterogeneous graph with node embedding vectors.
[0097] The fourth acquisition module 406 is used to obtain the vector of the heterogeneous graph based on the heterogeneous graph with node embedding vectors;
[0098] The classification module 407 is used to classify heterogeneous graphs based on their vectors and obtain the type of heterogeneous graph.
[0099] Output module 408 is used to output heterogeneous graph types; heterogeneous graph types are used for homogeneity analysis of network attacks.
[0100] In one possible implementation, the second acquisition module 403 is specifically used to: acquire historical domain name system data related to each node from historical domain name system data; acquire network traffic data related to each node from network traffic data; and acquire a network heterogeneous graph of a preset order for each node, centered on each node, based on the historical domain name system data and network traffic data related to each node, as well as a predefined heterogeneous graph network pattern.
[0101] In one possible implementation, the third acquisition module 405 is specifically used for: sampling the heterogeneous neighbor nodes of each node in the heterogeneous graph to obtain multiple heterogeneous neighbor nodes; extracting features from each heterogeneous neighbor node according to the type of each heterogeneous neighbor node to obtain the features of each heterogeneous neighbor node; encoding the features of each heterogeneous neighbor node to obtain the encoded features of each heterogeneous neighbor node; and aggregating the encoded features of multiple heterogeneous neighbor nodes to obtain the embedding vector of each node.
[0102] In one possible implementation, the third acquisition module 405 is further configured to acquire the type of each heterogeneous neighbor node; aggregate heterogeneous neighbor nodes of the same type among multiple heterogeneous neighbor nodes to obtain initial embedding vectors of different types of multiple heterogeneous neighbor nodes; and aggregate the initial embedding vectors of different types of multiple heterogeneous neighbor nodes to obtain the embedding vector of each node.
[0103] In one possible implementation, the fourth acquisition module 406 is specifically used to: perform convolution and pooling operations on the heterogeneous graph with node embedding vectors to obtain vectors of the heterogeneous graph.
[0104] The network attack data processing device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0105] Figure 5 This is a schematic diagram of the server structure provided in an embodiment of this application. Figure 5 As shown, the server provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the server further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus 504.
[0106] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.
[0107] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0108] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0109] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0110] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0111] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0112] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0113] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0114] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0115] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0116] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0117] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0118] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0119] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0120] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A method for processing network attack data, characterized in that, Applied to servers, including: Receive target network attack paths, historical domain name system data, and network traffic data sent by data acquisition devices; Obtain all nodes in the target network attack path; Based on the historical domain name system data, the network traffic data, and the predefined heterogeneous graph network pattern, obtain a network heterogeneous graph of a preset order for each node; Based on the target network attack path, the heterogeneous graphs of all nodes of a preset order are merged to obtain the heterogeneous graph corresponding to the target network attack path. Obtain the embedding vector of each node in the heterogeneous graph to obtain a heterogeneous graph with node embedding vectors; Based on the heterogeneous graph with node embedding vectors, the vectors of the heterogeneous graph are obtained; Based on the vectors of the heterogeneous graph, the heterogeneous graph is classified to obtain the heterogeneous graph type; Output the heterogeneous graph type; the heterogeneous graph type is used for homogeneity analysis of network attacks.
2. The method according to claim 1, characterized in that, The step of obtaining a network heterogeneous graph of a preset order for each node based on the historical domain name system, the network traffic data, and a predefined heterogeneous graph network pattern includes: From the historical domain name system data, obtain the historical domain name system data related to each node; From the network traffic data, obtain the network traffic data related to each node; Centered on each node, based on the historical domain name system data and network traffic data associated with each node, as well as the predefined heterogeneous graph network pattern, a network heterogeneous graph of a preset order is obtained for each node.
3. The method according to claim 1, characterized in that, The step of obtaining the embedding vector of each node in the heterogeneous graph includes: Sampling is performed on the heterogeneous neighbor nodes of each node in the heterogeneous graph to obtain multiple heterogeneous neighbor nodes; Based on the type of each heterogeneous neighbor node, feature extraction is performed on each heterogeneous neighbor node to obtain the features of each heterogeneous neighbor node; The features of each heterogeneous neighbor node are encoded to obtain the encoded features of each heterogeneous neighbor node; The encoded features of the multiple heterogeneous neighbor nodes are aggregated to obtain the embedding vector of each node.
4. The method according to claim 3, characterized in that, The aggregation of the encoded features of the multiple heterogeneous neighbor nodes to obtain the embedding vector of each node includes: Get the type of each heterogeneous neighbor node; Aggregate heterogeneous neighbor nodes of the same type among the multiple heterogeneous neighbor nodes to obtain initial embedding vectors of different types of the multiple heterogeneous neighbor nodes; The different types of initial embedding vectors of the multiple heterogeneous neighbor nodes are aggregated to obtain the embedding vector of each node.
5. The method according to any one of claims 1-4, characterized in that, The step of obtaining the vector of the heterogeneous graph based on the heterogeneous graph with node embedding vectors includes: Perform convolution and pooling operations on the heterogeneous graph with node embedding vectors to obtain the vectors of the heterogeneous graph.
6. A device for processing network attack data, characterized in that, Applied to servers, including: The receiving module is used to receive target network attack paths, historical domain name system data, and network traffic data sent by the data acquisition device; The first acquisition module is used to acquire all nodes in the target network attack path; The second acquisition module is used to acquire a network heterogeneous graph of a preset order for each node based on the historical domain name system data, the network traffic data, and the predefined heterogeneous graph network pattern. The merging module is used to merge the heterogeneous graphs of all nodes of a preset order according to the target network attack path to obtain the heterogeneous graph corresponding to the target network attack path. The third acquisition module is used to acquire the embedding vector of each node in the heterogeneous graph to obtain a heterogeneous graph with node embedding vectors. The fourth acquisition module is used to obtain the vector of the heterogeneous graph based on the heterogeneous graph with node embedding vectors; The classification module is used to classify the heterogeneous graph based on its vectors and obtain the heterogeneous graph type. The output module is used to output the heterogeneous graph type; the heterogeneous graph type is used for homogeneity analysis of network attacks.
7. The apparatus according to claim 6, characterized in that, The second acquisition module is specifically used for: acquiring historical domain name system data related to each node from the historical domain name system data; and acquiring network traffic data related to each node from the network traffic data. Centered on each node, based on the historical domain name system data and network traffic data associated with each node, as well as the predefined heterogeneous graph network pattern, a network heterogeneous graph of a preset order is obtained for each node.
8. A server, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-5.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-5.
Citation Information
Patent Citations
Network attack detection method and device and storage medium
CN117134964A
Heterogeneous graph-based traffic lateral movement attack detection method and system
CN118449790A