Adaptive Traceability Graph Real-Time Attack Detection Method and System Based on Tags and Gradient Backpropagation

By adopting an adaptive traceability diagram method based on label and gradient backpropagation in the detection system, the problems of high false alarm rate and alarm fatigue in the prior art are solved, and higher detection accuracy and efficiency are achieved.

CN119583117BActive Publication Date: 2025-05-27ZHEJIANG UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411626829.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-14
Publication Date
2025-05-27
Estimated Expiration
2044-11-14

AI Technical Summary

Technical Problem

The existing technology has high false alarm rates and alarm fatigue problems when detecting advanced persistent threats (APTs), which makes it difficult for security personnel to effectively deal with a large number of false alarms, affecting detection accuracy and efficiency.

Method used

Adaptive traceability map real-time attack detection method based on label and gradient backpropagation is adopted. By constructing a traceability map containing behavioral tags and entity tags, combining gradient strategies and backpropagation optimization, the detection model is automatically adjusted to reduce false positive rates and improve detection accuracy.

Benefits of technology

It effectively reduces the false positive rate, improves the response ability to complex attack scenarios, reduces the complexity of system maintenance and manual intervention needs, and ensures that the system maintains efficient response capabilities in the face of changing security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583117B_ABST
    Figure CN119583117B_ABST
Patent Text Reader

Abstract

The present invention discloses an adaptive traceability graph real-time attack detection method and system based on tags and gradient backpropagation, belonging to the field of attack detection. The present invention introduces an anomaly detection mechanism, adds behavior tags to nodes, and sets corresponding rules, taking anomalies into account additionally during detection, while expanding the types of detection events and rules. The present invention uses all benign data for training the detection module. For the false alarm situations generated during the training process, the backpropagation method and the Adam optimization algorithm are used to optimize and adjust the propagation rate, anomaly threshold, alarm threshold, as well as the behavior tag score and entity tag score. Finally, the optimized and trained detection module is used for detection. The present invention overcomes the problem in the prior art that the optimization scope is too limited to the nodes and edges corresponding to alarm events and cannot comprehensively improve the overall detection accuracy of the system, thereby reducing the false alarm rate and significantly improving the system's response ability to complex attack scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of attack detection, and particularly relates to an adaptive traceability graph real-time attack detection method and system based on tags and gradient backpropagation. Background Art

[0002] In recent years, with the increasing complexity and concealment of cyber attacks, advanced persistent threats (APTs) have become a severe challenge faced by governments and industrial sectors, causing significant social impacts. Detecting intrusions in normal behaviors has become increasingly important and challenging. [1] The source-based intrusion detection system (PIDS) has received extensive attention in the academic community due to its causal analysis ability. [2] Regarding the overhead problem, there is also a rule-based PIDS. [3] It has the advantage of being lightweight, greatly reducing the storage requirements and allowing for fast response with minimal latency. However, in terms of actual deployment, due to the environmental complexity and variability, it has a high false alarm rate, and the widespread problem of alarm fatigue has long troubled security personnel. Statistics from QiAnXin show that for a digital enterprise with about 3,000 people, an average of about 100,000 alarm messages are generated every day. However, a security expert with rich practical experience can only handle less than 500 alarm messages per day on average. And for a 5-person security operation team, the upper limit of alarm handling per day is only 2,500, which is far from the total of 100,000 alarm messages. The contradiction between the massive false alarm information and the limited number of analysts has greatly hindered the popularization of this technology.

[0003] To improve accuracy, in the SOC, analysts must manually configure the model, which is a time-consuming process and requires extremely high professional capabilities. Therefore, there is an urgent need for an automated configuration method to improve the accuracy of rule-based PIDS.

[0004] Rule-based PIDS uses rules designed by humans to map system entities and events to predefined semantic units (such as tags TTP, etc.) and propagates these units along the information flow to obtain detection results. Due to its real-time processing ability and lightweight characteristics, it has become popular. Rule-based PIDS has solved the problem of large-scale burden in traceability analysis to a certain extent. However, due to the complex environment, when threat reports are generated, a large amount of false alarm information is accompanied, bringing a great burden to reviewers and causing the widespread existence of alarm fatigue, which has become the biggest hidden danger and vulnerability in security operations.

[0005] [1]A. Alshamrani, S. Myneni, A. Chowdhary, and D. Huang, “A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,” IEEE Communications Surveys Tutorials, vol. 21, no. 2, 2019.

[0006] [2] M. Zipperle, et al., "Provenance-based Intrusion Detection Systems: A Survey". ACM Comput. Surv. 2023.

[0007] [3] M. N. Hossain, S. Sheikhi, and R. Sekar, “Combating dependence explosion in forensic analysis using alternative tag propagation semantics,” in IEEE Symposium on Security and Privacy (SP), 2020. Summary of the Invention

[0008] To solve the problems in the prior art, the present invention proposes an adaptive provenance graph real-time attack detection method and system based on tags and gradient backpropagation.

[0009] The technical solution of the present invention is as follows:

[0010] The present invention first proposes an adaptive provenance graph real-time attack detection method based on tags and gradient backpropagation, which includes the following steps:

[0011] S1: Construct a provenance graph according to the input audit log training set; each node of the provenance graph has a behavior tag and an entity tag, and each edge of the provenance graph stores the source node ID, the destination node ID, the event type between the two nodes, the propagation rate, the anomaly threshold, and the alarm threshold;

[0012] S2: Transmit the entity tags according to the event type and the propagation rate; among them, the event type determines the transmission path, the destination node in the path stores the path information, and the source node stores the corresponding number of destination nodes;

[0013] S3: For each edge, select the nodes to be abnormally detected according to the event type stored on the edge, and perform abnormal detection on the behavior label scores of the nodes according to the abnormal threshold; when an abnormality is detected, set an alarm weight to adjust the entity label score of the node during alarm detection;

[0014] S4: For each edge, select the nodes to be alarm-detected according to the event type, and perform alarm detection on the entity label scores of the nodes according to the alarm threshold; alarm for the edges with abnormalities;

[0015] S5: According to the gradient strategy, optimize the propagation rate, abnormal threshold, alarm threshold, behavior label score, and entity label score of the edges that generate alarms;

[0016] S6: Perform backpropagation optimization according to the path information stored in the nodes, and optimize the propagation rate, abnormal threshold, alarm threshold, behavior label score, and entity label score of the edges on the path;

[0017] S7: Repeat steps S1 - S6 until the optimization ends; after the optimization ends, replace the audit log training set in step S1 with the audit log to be detected, and execute steps S1 - S4 for detection.

[0018] The present invention also provides an adaptive traceability graph real-time attack detection based on label and gradient backpropagation for implementing the above method, which includes a detection module and a learning module;

[0019] The detection module is used to perform attack detection on the input audit log to be detected, and it includes:

[0020] A traceability graph construction unit, which is used to construct a traceability graph according to the audit log; each node of the traceability graph has a behavior label and an entity label, and each edge of the traceability graph stores the source node ID, destination node ID, event type between the two nodes, propagation rate, abnormal threshold, and alarm threshold;

[0021] An entity label transfer unit, which is used to transfer the entity label according to the event type and propagation rate; among them, the event type determines the transfer path, the destination node in the transfer path stores path information, and the source node stores the number of its destination nodes;

[0022] An abnormal detection unit, which is used to, for each edge, select the nodes to be detected according to the event type stored on the edge, and perform abnormal detection on the behavior label scores of the nodes according to the abnormal threshold; when an abnormality is detected, set an alarm weight to adjust the entity label score of the node during alarm detection;

[0023] The alarm detection unit, for each edge, selects the nodes to be detected according to the event type, and performs alarm detection on the entity label scores of the nodes according to the alarm threshold; alarms the edges with anomalies.

[0024] The learning module is used to train and optimize the detection module; the learning module optimizes the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edges that generate alarms according to the gradient strategy; and further performs backpropagation optimization based on the path information stored in the nodes to optimize the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edges that generate alarms.

[0025] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0026] (1) The present invention adopts an incremental learning method. After the system is deployed and applied, the detection results are automatically divided into two categories: benign data and alarm data. By inputting the benign data into the training mode, the system can re-learn the new data, and after the learning is completed, automatically update and replace the original detection model. Therefore, the present invention effectively overcomes the problem of the decrease in detection accuracy caused by concept drift in the prior art, and at the same time reduces the complexity of long-term system maintenance and the need for manual intervention, thereby realizing the automatic update of detection parameters and ensuring the system's efficient response ability in the face of constantly changing security threats.

[0027] (2) The present invention adopts a backpropagation method, which is not limited to calculating the gradient backpropagation to optimize parameters according to the system generation results, but expands the scope of optimization. Through the path stored in the nodes for backpropagation, the parameters of relevant nodes and edges are optimized. Therefore, it overcomes the problem in the prior art that the scope of optimization is too limited to the nodes and edges corresponding to alarm events and cannot comprehensively improve the overall detection accuracy of the system, thereby reducing the false alarm rate and significantly improving the system's response ability to complex attack scenarios, and further improving the system efficiency.

[0028] (3) The present invention adopts the Adam optimization algorithm to further optimize the calculated initial gradient, thus overcoming the problem that the original Batch gradient descent is difficult to perfectly correspond to the number of events due to the fixed batch size. If the batch size is too small, optimization may be performed before the detection is completed, resulting in inconsistent labels of individual traceability graphs. At the same time, it can reach the optimal value faster and more accurately, rather than directly updating the parameters according to the gradient.

[0029] (4) The present invention introduces an anomaly detection mechanism, adds behavior tags, and sets corresponding rules for them, taking into account abnormal situations additionally during detection. At the same time, the types of detection events and rules are extended. It overcomes the problem in the prior art that the false negative rate increases due to the pursuit of reducing false positives. Thus, a more reasonable detection result and higher detection accuracy are achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 is a flowchart of the real-time attack detection method for adaptive traceability graph based on tags and gradient backpropagation of the present invention;

[0031] Figure 2 is a working schematic diagram of the detection module of the present invention;

[0032] Figure 3 is a working schematic diagram of the learning module of the present invention;

[0033] Figure 4 is a flowchart of the backpropagation of the present invention;

[0034] Figure 5 is a schematic diagram of the incremental learning process after deploying the system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] The present invention will be further described and explained below in conjunction with the detailed embodiments. The embodiments are only examples of the present disclosure content and do not delimit the scope of limitation. The technical features of each embodiment of the present invention can be combined correspondingly without conflict.

[0036] As Figure 1 shown, the present invention proposes a real-time attack detection method and system for adaptive traceability graph based on tags and gradient backpropagation. The system includes a detection module and a learning module; the detection module ( Figure 2 shown) is used to perform attack detection on the input audit logs to be detected: the learning module ( Figure 3 shown) is used to train and optimize the detection module. In the training process, the present invention uses all-benign audit logs as training samples. Therefore, if an alarm is generated during the training process, it means that a false positive has occurred during the training process. Based on the false positive situation, the learning module optimizes the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edge that generates the alarm according to the gradient strategy; and further optimizes the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edge that generates the alarm according to the path information stored in the node through backpropagation. Finally, the detection module after training can be deployed in the actual application scenario to perform attack detection on the audit logs to be detected.

[0037] The detection module can be specifically divided into a traceability graph construction unit, an entity label transmission unit, an anomaly detection unit, and an alarm detection unit. The following will elaborate on each module in combination with the specific detection method of the present invention. The adaptive traceability graph real-time attack detection method based on labels and gradient backpropagation of the present invention includes the following steps:

[0038] S1: Construct a traceability graph based on the input audit log training set; each node of the traceability graph has a behavior label and an entity label, and each edge of the traceability graph stores the source node ID, the destination node ID, the event type between the two nodes, the propagation rate, the anomaly threshold, and the alarm threshold;

[0039] S2: Transmit the entity label according to the event type and the propagation rate; among them, the event type determines the transmission path, the destination node in the path stores the path information, and the source node stores the corresponding number of destination nodes;

[0040] S3: For each edge, select the nodes to be anomalously detected according to the event type stored on the edge, and perform anomaly detection on the behavior label score of the nodes according to the anomaly threshold; when an anomaly is detected, set an alarm weight to adjust the entity label score of the node during alarm detection;

[0041] S4: For each edge, select the nodes to be alarm-detected according to the event type, and perform alarm detection on the entity label score of the nodes according to the alarm threshold; alarm for the edges with anomalies;

[0042] S5: Optimize the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edges that generate alarms according to the gradient strategy;

[0043] S6: Perform backpropagation optimization according to the path information stored in the nodes, and optimize the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edges on the path;

[0044] S7: Repeat steps S1 - S6 until the optimization is completed; after the optimization is completed, replace the audit log training set in step S1 with the audit log to be detected, and execute steps S1 - S4 for detection.

[0045] As Figure 2 shown, steps S1, S2, S3, and S4 in the method of the present invention are respectively executed by the traceability graph construction unit, the entity label transmission unit, the anomaly detection unit, and the alarm detection unit of the detection module. As Figure 3 shown, S5 and S6 in the method of the present invention are executed by the learning module. The actual detection work of S7 is executed by the trained detection module.

[0046] To improve the training efficiency, in a specific embodiment of the present invention, S1 of the present invention uses fully benign audit logs as training samples, and adjusts the parameters in the detection module using the learning module according to the false alarm situations generated during the training process, and repeats this process until the training is completed.

[0047] In step S1, after the audit log is input, first identify the object in the audit log. If a new entity is identified, add it as a new node to the traceability graph; if it is an existing object (i.e., an existing node), then reduce the frequency score in the behavior label of the corresponding node according to the frequency at which the object has appeared.

[0048] Each node of the traceability graph has a behavior label and an entity label. The behavior label B of the node includes a frequency score b 0 (a low frequency score represents an abnormal call frequency) and a time score b 1 (a low time score represents an abnormal usage time). The scores in the behavior label B are used for anomaly detection, and the alarm threshold in the alarm detection link is adjusted according to the detection result. The entity label A is related to the node type. For data type nodes, the entity label A includes a confidentiality score c (a low confidentiality score represents highly sensitive data) and an integrity score i (a low integrity score represents a high likelihood of being victimized); for code type nodes, the entity label A only includes the integrity score i (a low integrity score represents a high likelihood of being victimized). The entity label A is used for final alarm detection.

[0049] Each edge of the traceability graph stores the source node ID, destination node ID, event type between the two nodes, propagation rate, anomaly threshold, and alarm threshold. Among them, the event type is a well-known concept in the art, and the event type can be extended as needed. In the embodiments of the present invention, the event types of concern mainly include create, read, load, open, write, remove, rename, execute, inject, set user identifier, modify permission, create new process, and bind. Among them, create(s,o) means that node s creates a node o, read(s,o) means that node s reads node o, load(s,o) means that node s loads node o, open(s,o) means that node s opens node o, write(s,o) means that node s writes to node o, remove(s,o) means that node s removes node o, rename(s,o) means that node s renames node o, execve(s,o) means that node s executes node o, inject(s,o) means that node s injects node o, set_uid(s,o) means that node s sets the user identifier of node o, chmod(s,o) means that node s modifies the permission of node o, fork(s,o) means that node s creates node o (new process), and bind(s,o) means that node s binds node o. In the symbols of each event type, s represents the source node and o represents the destination node. In the present invention, enent_type is used to represent the event type. Therefore, an event can be recorded as (s, enent_type, o). If min(s.tag, o.tag) appears, the specific label scores are both taken as the minimum value, and itag represents the integrity score.

[0050] In S2, the event type determines the transfer path, and the transfer path represents the transfer direction of the data flow; during the transfer, the source node only transfers the entity label to the destination node. The destination node in the path will store the information of the path where the sound is transmitted, and the source node will store the number of its corresponding destination nodes. At the same time, the propagation rate is controlled by the parameter G; specifically, for any edge e in the traceability graph, a g is stored e , according to the rules corresponding to the event type, given the entity label tag of the target node that needs to be updated dest and the entity label tag of the source node rule , the tag is updated as follows during the label propagation dest :

[0051] tag dest (new) = g e × tag rule + (1 – g e ) × tag dest ;

[0052] The specific rules for entity label passing are as shown in Table 1 below:

[0053] Table 1 Design of Entity Label Passing Rules

[0054]

[0055]

[0056] Store the path in the updated node. The source node regards it as a child node and records the number of child nodes.

[0057] In the present invention, for the event types stored on the edges, the selection of detection nodes is performed. Among them, the nodes selected for anomaly detection and alarm detection are the same. The specific rules for anomaly detection and alarm detection may need to be adjusted, and the present invention does not limit this. The detection content corresponding to each event type is also well-known. Taking the file creation event create(s,o) as an example, it means that the source node s creates a destination node o. The content of its alarm detection is: if the destination node is a file and the integrity score of the source node < threshold, it is determined as malicious file creation, and the node to be detected for the create(s,o) event is the source node. In a specific embodiment of the present invention, the specific rules for alarm detection are as shown in Table 2 below:

[0058] Table 2 Design of Alarm Detection Rules

[0059]

[0060]

[0061] The rules for anomaly detection are relatively simple and are the same as those for alarm detection in terms of the selection of nodes to be detected. Anomaly detection is to detect the relationship between the behavior label and the corresponding threshold. For the edges of the traceability graph, set the anomaly detection threshold T b , if the edge already stores the anomaly detection threshold, directly read and use it. Otherwise, initialize and set the anomaly detection threshold T b = {0.5, 0.5, 0.5, 0.5}, and each item in T b corresponds to the source node frequency threshold, source node time threshold, destination node frequency threshold, and destination node time threshold respectively; in S3 anomaly detection, according to the corresponding rules of the event type, select the frequency score and time score of the corresponding node and compare them with the anomaly detection threshold respectively.

[0062] In a specific embodiment of the present invention, the behavior label score is obtained in the following manner: the frequency score b of the behavior label of the node newly added to the traceability graph 0It is assigned a value of 1. As the number of times the node appears increases, the frequency score is gradually decreased according to a preset decreasing rate, and the specific decreasing rate can be determined according to the actual situation. The time score depends on the user's setting of the normal usage time within a day (setting the normal usage time range within 24 hours of a day). Within the normal time range, the initial assignment is 1, otherwise, the time score Among them, T 0 represents the difference between the current usage time and the closest normal usage time, and T 1 represents the magnitude of the abnormal usage time within a day.

[0063] During S3 anomaly detection, both the frequency score and the time score are compared with the anomaly threshold. As long as the frequency score is less than the corresponding threshold or the time score is less than the corresponding threshold, it is regarded as detecting an anomaly. If there is no anomaly, the alarm weight K is set to 1. If there is an anomaly, the alarm weight Among them, b is the sum of the frequency scores or time scores of the selected nodes that are less than the corresponding thresholds, and t is the sum of the corresponding thresholds that are greater than the frequency scores or time scores of the selected nodes among the thresholds.

[0064] In a specific embodiment of the present invention, the entity label score is obtained in the following manner: If the node already exists, it directly inherits the previous entity label score. If the node joins the traceability graph for the first time, its entity label score is initialized. Specifically, for any node n ∈ N in the traceability origin graph, A stores its initial data label relative to its node characteristics. The node characteristics depend on the information granularity of the audit log, such as file path, process name, command line, IP address, port, etc. During training, the initialization is carried out with a conservative strategy. For example, we assign an initial integrity of 0 to all IP addresses so that we do not miss any attackers entering through network communication.

[0065] During S4 alarm detection, the entity label score of the detected node is multiplied by the alarm weight and then compared with the alarm threshold. The rules for alarm detection are shown in Table 2.

[0066] The present invention uses the above steps S1 - S4 for attack detection. For the training process, the audit log training set consists of entirely benign audit logs. If an alarm is generated during the training process, it indicates a false alarm occurred during the training process. After a false alarm occurs, optimization learning is initiated. The optimization learning specifically includes the gradient strategy optimization in step S5 and the backpropagation optimization in step S6. The present invention adopts the method of backpropagation, which is not limited to calculating the gradient backpropagation optimization parameters based on the system-generated results, but expands the scope of optimization. Backpropagation is performed through the paths stored in the nodes to optimize the parameters of the relevant nodes and edges. Therefore, it overcomes the problem in the prior art that the scope of optimization is too limited to the nodes and edges corresponding to the alarm events, and cannot comprehensively improve the overall detection accuracy of the system. Thus, the false alarm rate is reduced, and the system's response ability to complex attack scenarios is significantly improved, further enhancing the system efficiency. The present invention adopts the Adam optimization algorithm to further optimize the initially calculated gradients, thereby overcoming the problem that the original Batch gradient descent is difficult to perfectly correspond to the number of events due to the fixed batch size. If the batch size is too small, optimization may occur before the detection is completed, resulting in inconsistent single traceability graph labels. At the same time, it can reach the optimal value faster and more accurately, rather than directly updating the parameters according to the gradient.

[0067] Among them, in a specific embodiment of the present invention, according to the gradient strategy in S5, the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edge that generates an alarm are optimized, which specifically includes the following steps:

[0068] 1) The audit log training set consists of entirely benign audit logs. If an alarm is generated during the training process, it indicates a false alarm occurred during the training process;

[0069] At this time, record f(e) = tag rule -thr i representing the difference between the entity label score Tag selected by the event detection rule of edge e rule and the alarm detection threshold thr i stored by the edge,

[0070] Record L(e) = max(0, (1 - f(e)) 2 - 1). If L(e) is not 0, it indicates that this edge generates a false alarm;

[0071] 2) Calculate the loss function:

[0072] Loss = ∑ e∈E L(e) + α||A - A 0 || 2 + μ||B - B 0 || 2 + γ||G - G 0 || 2+τ||T b -T b0 || 2 +r||T - T 0 || 2

[0073] Among them, α, μ, γ, τ, r are regularization coefficients, E represents the set of edges, the A parameter represents the label entity score, the B parameter represents the behavior label behavior score, the G parameter represents the label propagation rate, T b represents the behavior anomaly detection threshold, T represents the alarm detection threshold, A 0 , B 0 , G 0 , T b0 , T 0 represents the initial default value;

[0074] 3) For the parameter θ ∈ {A, B, G, T b , T}, the gradient is calculated as follows,

[0075] where f represents f(e), a represents a specific parameter in θ, a 0 represents the initial default value corresponding to the parameter a;

[0076] 4) Adam gradient optimization, for the gradient of the parameter θ

[0077] First moment:

[0078] Second moment:

[0079]

[0080] The final modification of the parameter θ:

[0081]

[0082] where, t represents the number of times, β 1 , β 2 are hyperparameters, represents the correction value, η represents the learning rate, and ε is a very small value added to prevent division by zero. In a specific embodiment of the present invention, β 1 = 0.9,, β 2 = 0.999, and ε takes the value of 10 -8 .

[0083] Such as Figure 4As shown, in a specific embodiment of the present invention, the basis node of S6 stores path information for backpropagation optimization, optimizing the propagation rate, anomaly threshold, alarm threshold, and entity label score on the path. The specific steps are as follows:

[0084] 1) When an alarm is generated on a certain edge and gradient optimization is completed, the path information is stored in the nodes connected by the edge, and backpropagation is performed through the path information;

[0085] 2) For the parameter θ involved in the path, according to the final gradient when optimizing the edge where the alarm is generated perform attenuation. According to the path, for each additional propagation, the optimized gradient is attenuated That is, the gradient

[0086] 3) For a node containing multiple sub-paths, according to the number of sub-nodes n of the node, the propagated gradient is further attenuated That is, the gradient

[0087] 4) Update the parameter η represents the learning rate.

[0088] The detection module and the learning module repeat steps S1 - S6 to continuously perform optimization learning until the entire training optimization process ends; after the optimization ends, the obtained detection module can execute the detection task. The detection module is deployed in the actual detection scenario, and the audit log to be detected replaces the audit log training set in step S1, and the detection module can execute steps S1 - S4 for detection. Further, as Figure 5 shown, after the system is deployed and applied, the present invention can automatically divide the detection results into two categories: benign data and alarm data. Subsequently, by putting the benign data into the training mode, the system can re-learn the new data, and after the learning is completed, automatically update and replace the original detection module. Therefore, the present invention can effectively overcome the problem of decreased detection accuracy caused by concept drift in the prior art, while reducing the complexity of long-term system maintenance and the need for manual intervention, thereby realizing the automatic update of detection parameters and ensuring the system's efficient response ability in the face of constantly changing security threats.

[0089] In summary, the present invention introduces an anomaly detection mechanism, adds behavior labels, and sets corresponding rules for them, considering abnormal situations additionally during detection. At the same time, it expands the detection event types and rules. It overcomes the problem in the prior art that the false negative rate increases due to the pursuit of reducing false positives. Thus, it achieves the effects of more reasonable detection results and higher detection accuracy.

[0090] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of the patent of the present invention. For those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention.

Claims

1. A real-time attack detection method based on adaptive traceability graphs and gradient back propagation, characterized in that: The steps include: S1: Construct a traceability graph based on the input audit log training set; each node of the traceability graph has a behavior label and an entity label, and each edge of the traceability graph stores a source node ID, a destination node ID, an event type between two nodes, a propagation rate, an anomaly threshold, and an alarm threshold; S2: Entity tags are transferred based on event type and propagation rate. The event type determines the transfer path, the destination node in the path stores the path information, and the source node stores the number of its corresponding destination nodes. S3: For each edge, select the node to be detected for anomaly based on the event type stored on the edge, and perform anomaly detection on the behavior label score of the node based on the anomaly threshold; when an anomaly is detected, set an alarm weight to adjust the entity label score of the node during alarm detection; S4: For each edge, select the node to be detected based on the event type, and perform alarm detection on the entity label score of the node according to the alarm threshold; and issue an alarm for the edge with abnormalities; S5: Based on the gradient strategy, optimize the propagation rate of the edge that generates the alarm, the anomaly threshold, the alarm threshold, the behavior label score, and the entity label score; Step S5 specifically includes the following steps: 1) The audit log training set is a completely benign audit log. If an alarm is generated during the training process, it means that a false alarm has occurred during the training process; At this time, let f(e) = tag rule -thr i Represents the entity tag score Tag selected by the event detection rule of edge e rule The alarm detection threshold thr stored by the edge i The difference, Let L(e) = max(0,(1-f(e)) 2 -1), if L(e) is not 0, it means that the edge generates a false positive; 2) Calculate the loss function: Loss=∑ e∈E L(e)+α||A-A0||2+μ||B-B0||2+γ||G-G0||2+τ||T b -T b0 ||2+r||T-T0||2 Among them, α, μ, γ, τ, r are regularization coefficients, E represents the set of edges, A parameter represents the label entity score, B parameter represents the behavior label behavior score, G parameter represents the label propagation rate, T b represents the abnormal behavior detection threshold, T represents the alarm detection threshold, A0, B0, G0, T b0 , T0 represents the initial default value; 3) For the parameters θ∈{A, B, G, T b , T}, the gradient is calculated as follows, Where f represents f(e), a represents a specific parameter in θ, and a0 represents the initial default value of parameter a. 4) Adam gradient optimization, the gradient of parameter θ Recorded as First moment: Second moment: The parameter θ is finally modified: Among them, t represents the number of times, β1 and β2 are hyperparameters, represents the correction value, η represents the learning rate, and ε is the value added to prevent division by zero; S6: Perform back propagation optimization based on the path information stored in the node to optimize the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edges on the path; Step S6 specifically includes the following steps: 1) When an edge generates an alarm and completes gradient optimization, the path information is stored in the nodes connected by the edge, and the path information is propagated backwards; 2) For the parameters θ involved in the path, according to the final gradient when the alarm edge is optimized Attenuation is performed according to the path, and each additional propagation is performed to optimize the gradient attenuation Gradient 3) For a node with multiple sub-paths, the propagated gradient is additionally attenuated according to the number of sub-nodes n of the node Gradient 4) Update parameters η represents the learning rate; S7: Repeat steps S1-S6 until the optimization is completed; after the optimization is completed, replace the audit log training set in step S1 with the audit log to be tested, and execute steps S1-S4 for testing.

2. The attack detection method according to claim 1, characterized in that: The audit log training set described in S1 is a completely benign audit log.

3. The attack detection method according to claim 1, characterized in that: In S1, the objects in the audit log are first identified, and if a new entity is identified, it is added to the provenance graph as a new node; The behavior label B of the node includes the frequency score b0 and the time score b1; for the data type node, the entity label A includes the confidentiality score c and the integrity score i; for the code type node, the entity label A only includes the integrity score i.

4. The attack detection method according to claim 1, characterized in that: The event type determines the transmission path, which represents the transmission direction of the data flow. During the transmission, the source node only transmits the entity label to the destination node, and the propagation rate is controlled by the parameter G. Specifically, for any edge e in the traceability graph, a g is stored. e , according to the rules corresponding to the event type, the entity tag tag of the target node to be updated is given dest and the entity tag of the source node rule , during tag propagation, tagd is updated as follows est : tag dest (new)=g e ×tag rule +(1–g e )×tag dest ; The path is stored in the updated node, the source node regards it as a child node, and the number of child nodes is recorded.

5. The attack detection method according to claim 3, characterized in that: The behavior label score is obtained in the following way: the frequency score b0 of the behavior label of the node added to the traceability graph for the first time is assigned to 1. As the number of node appearances increases, the frequency score is gradually reduced according to the preset reduction rate; the time score depends on the user's setting of the normal usage time of the day. Within the normal time range, the initial value is 1, otherwise, the time score is Among them, T0 represents the difference between the current usage time and the closest normal usage time, and T1 represents the abnormal usage time in a day; During S3 anomaly detection, both the frequency score and the time score are compared with the anomaly threshold. As long as the frequency score is less than the corresponding threshold or the time score is less than the corresponding threshold, the detection is considered to be abnormal.

6. The attack detection method according to claim 5, characterized in that: The alarm weight is set in the following way: First, for the edge of the traceability graph, set the anomaly detection threshold T b If the edge already has an anomaly detection threshold stored, it is directly read and used; otherwise, the anomaly detection threshold T is initialized and set b ={0.5,0.5,0.5,0.5}, T b The items in correspond to the source node frequency threshold, the source node time threshold, the destination node frequency threshold and the destination node time threshold respectively; When S3 detects anomalies, according to the event type corresponding rules, the frequency score and time score of the corresponding node are selected and compared with the anomaly detection threshold. If there is no anomaly, the alarm weight K=1 is set; if there is an anomaly, the alarm weight is set. Among them, b is the sum of the frequency scores or time scores of the selected nodes that are less than the corresponding threshold, and t is the sum of the corresponding thresholds of the frequency scores or time scores of the selected nodes that are greater than the selected nodes.

7. The attack detection method according to claim 3, characterized in that: The entity label score is obtained in the following way: if the node already exists, the previous entity label score is directly inherited; if the node is added to the traceability graph for the first time, its entity label score is initialized; During S4 alarm detection, the entity label score of the detected node is multiplied by the alarm weight and then compared with the alarm threshold.

8. A real-time attack detection system based on adaptive traceability graph of labels and gradient back propagation for implementing the method of claim 1, characterized in that: Includes detection module and learning module; The detection module is used to perform attack detection on the input audit log to be detected, which includes: A traceability graph construction unit is used to construct a traceability graph according to the audit log; each node of the traceability graph has a behavior label and an entity label, and each edge of the traceability graph stores a source node ID, a destination node ID, an event type between two nodes, a propagation rate, an abnormal threshold, and an alarm threshold; An entity label transmission unit is used to transmit the entity label according to the event type and the propagation rate; wherein the event type determines the transmission path, the destination node in the transmission path stores the path information, and the source node stores the number of its destination nodes; The anomaly detection unit is used to select the node to be detected according to the event type stored on each edge, and perform anomaly detection on the behavior label score of the node according to the anomaly threshold; when an anomaly is detected, an alarm weight is set to adjust the entity label score of the node during alarm detection; The alarm detection unit selects the node to be detected according to the event type for each edge, and performs alarm detection on the entity label score of the node according to the alarm threshold; and issues an alarm for the edge with abnormality; The learning module is used to train and optimize the detection module; the learning module optimizes the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edge that generates the alarm based on the gradient strategy; and further performs back propagation optimization based on the path information stored in the node to optimize the propagation rate, anomaly threshold, alarm threshold, behavior label score, and entity label score of the edge that generates the alarm.

Citation Information

Patent Citations

  • Off-ground attack detection method and system based on time sequence analysis and memory forensics

    CN117150488A

  • Heterogeneous graph embedding attack detection method and device based on multi-relation perception

    CN117811763A