A Network Malicious Attack Detection Method and System with Multi-Perspective Feature Fusion
By constructing node mutual infographics and embedded graphs, and combining the K-means algorithm to extract multi-view features, the problem of insufficient security detection performance in existing network malicious attack detection methods is solved, and higher detection accuracy and reliability are achieved.
Patent Information
- Application Number
- CN202510207995.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-02-25
AI Technical Summary
The existing network malicious attack detection methods mainly rely on single feature extraction, resulting in the security detection performance not meeting the usage requirements.
By constructing node mutual infographics and embedded graphs, the existence characteristics of malicious behavior are extracted, and the transfer probability matrix is constructed in combination with the K-means algorithm, and multi-view features are fused to identify malicious behavior.
It improves the accuracy and reliability of malicious behavior detection and can accurately identify and classify malicious attacks on networks.
Smart Images

Figure CN119728295B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of network security technology. Specifically, it relates to a method and system for detecting network malicious attacks with multi-perspective feature fusion. Background Art
[0002] Currently, network security issues have attracted much attention. Detection methods for network malicious attack behaviors such as viruses and Trojans have always been hot issues in the field of network security. In the era of popularization of network applications, users need reliable network malicious attack detection technologies to combat attacks from insecure factors in the network, such as viruses, Trojans and other insecure factors. With the development of network technology, the latency, concealment and destructiveness of viruses and Trojans are becoming stronger and stronger, and the detection difficulty is increasing. The intrusion and damage of network malicious attacks such as viruses and Trojans to the network have become a key problem that needs to be solved urgently.
[0003] Currently, detection methods for network malicious attack behaviors such as viruses and Trojans mainly include static detection technologies and dynamic detection methods. Among them, the static detection method parses malicious code in the PE file format, extracts binary, strings, byte sequences, etc. as feature codes, and matches the feature codes to be tested with the feature library to detect whether there are network malicious attack behaviors. The dynamic analysis detection method realizes the detection of network malicious attack behaviors based on the call behaviors of application programming interfaces, and can be divided into sequence-based virus and Trojan detection, graph-based virus and Trojan detection, and transfer-based virus and Trojan detection according to the differences in detection means.
[0004] However, the existing detection methods for network malicious attack behaviors such as viruses and Trojans extract single features from the call sequence information of application program interfaces for security detection, and their security detection performance cannot meet the usage requirements. Summary of the Invention
[0005] The purpose of this specification is to provide a method for detecting network malicious attacks with multi-perspective feature fusion, which can solve the problem of poor security detection performance existing in the existing network malicious attack behavior detection methods.
[0006] The embodiments of this specification are implemented as follows:
[0007] On the one hand, this specification provides a method for detecting network malicious attacks with multi-perspective feature fusion, mainly including:
[0008] According to the obtained network operation records of key network communication facilities, determine possible malicious behaviors and the interfaces and interface call sequences involved;
[0009] According to the interfaces and interface call sequences involved in the possible malicious behavior, by constructing a node mutual information graph and an embedded graph, extract the existence features of the malicious behavior. The nodes of the node mutual information graph and the embedded graph are the interfaces involved in the possible malicious behavior, including:
[0010] Use the interfaces involved in the possible malicious behavior as nodes, and use the degree of association between two nodes as the associated edge;
[0011] According to the call order and call distance of each node in the interface call sequence, determine the call matrix of the system interface set; the call distance represents the number of nodes separated between two nodes in the interface call sequence;
[0012] According to the call matrix, determine the call vector of the calling node and the weight of the first associated edge;
[0013] According to the weight of the first associated edge, construct the node mutual information graph;
[0014] Group the interfaces through 2-gram of the interface call sequence, and determine the node function similarity threshold through the L2 norm between the node embedding vectors ;
[0015] If there is a second associated edge between nodes with a function similarity greater than , otherwise there is no second associated edge;
[0016] Determine the neighbor nodes with functions similar to each node through the L2 norm between the node embedding vectors;
[0017] Calculate the function similarity between each node and its neighbor nodes with similar functions;
[0018] Add a second associated edge between each node and its neighbor nodes with similar functions and determine the weight of the second associated edge;
[0019] According to the weight of the second associated edge, determine the embedded graph;
[0020] According to the node mutual information graph, determine the first adjacency matrix;
[0021] According to the embedded graph, determine the second adjacency matrix;
[0022] According to the first adjacency matrix and the second adjacency matrix, through a multi-layer Transformer network, extract the first behavior feature and the second behavior feature respectively. The first behavior feature and the second behavior feature correspond to the node mutual information graph and the embedded graph respectively;
[0023] According to the first behavior feature and the second behavior feature, determine the existence features of the possible malicious behavior;
[0024] Construct a transition probability matrix through the K-means algorithm according to the interfaces and interface call sequences involved in the possible malicious behavior, and extract the transfer characteristics of the possible malicious behavior;
[0025] Determine whether the possible malicious behavior is a malicious behavior according to the extracted existence characteristics and transfer characteristics.
[0026] In this specification, the determination of possible malicious behaviors and the interfaces and interface call sequences involved therein according to the network operation records of key network communication facilities includes:
[0027] Determine whether the network operation behavior conforms to the network security protection policy according to the network operation records of the key network communication facilities obtained;
[0028] If not, determine the network operation behavior that does not conform to the network security protection policy as the possible malicious behavior.
[0029] In this specification, the determination of possible malicious behaviors and the interfaces and interface call sequences involved therein according to the network operation records of key network communication facilities includes:
[0030] Construct a malicious behavior threat association graph through the KeyGraph algorithm according to the network operation records of the key network communication facilities obtained;
[0031] Determine the key threat association strength according to the malicious behavior threat association graph;
[0032] Determine the malicious behavior interface path call model according to the key threat association strength;
[0033] Determine the interfaces and interface call sequences involved in the possible malicious behavior according to the possible malicious behavior and the malicious behavior interface path call model.
[0034] In this specification, before determining the existence characteristics of the possible malicious behavior according to the first behavior characteristic and the second behavior characteristic, it includes:
[0035] Iteratively update the graph convolutional neural network through the graph convolutional neural network loss function until the accuracy of the first behavior characteristic and the second behavior characteristic output by the updated graph convolutional neural network meets the extraction conditions.
[0036] In this specification, the construction of a transition probability matrix through the K-means algorithm according to the interfaces and interface call sequences involved in the possible malicious behavior, and the extraction of the transfer characteristics of the possible malicious behavior, includes:
[0037] By using the K-means algorithm, cluster division is performed on the interfaces involved in the possible malicious behaviors to determine each cluster and the center of each cluster;
[0038] According to the interface call sequence involved in the possible malicious behaviors and the clusters to which the interfaces belong, an interface call cluster sequence is constructed;
[0039] Taking the interface call cluster sequence as a Markov chain and using each cluster as the state of the interface, a transition probability matrix is generated through state transition statistical probability;
[0040] Taking the transition probability matrix as the input, through a convolutional neural network, the transfer characteristics of the possible malicious behaviors are extracted.
[0041] In this specification, determining whether the possible malicious behavior is a malicious behavior according to the extracted existence characteristics and transfer characteristics includes:
[0042] Fusing the existence characteristics and the transfer characteristics to obtain a fused feature;
[0043] Taking the fused feature as the input, through a one-dimensional convolutional neural network, the possible malicious behavior is identified to determine whether the possible malicious behavior is a malicious behavior.
[0044] On the other hand, this specification provides a network malicious attack detection system with multi-perspective feature fusion, mainly including:
[0045] A determination module, configured to determine possible malicious behaviors and the interfaces and interface call sequences involved therein according to the network operation records of key network communication facilities obtained;
[0046] An existence feature extraction module, configured to extract the existence features of the malicious behavior according to the interfaces and interface call sequences involved in the possible malicious behavior by constructing a node mutual information graph and an embedded graph, and the nodes of the node mutual information graph and the embedded graph are the interfaces involved in the possible malicious behavior;
[0047] A transfer feature extraction module, configured to construct a transition probability matrix through the K-means algorithm according to the interfaces and interface call sequences involved in the possible malicious behavior, and extract the transfer features of the possible malicious behavior;
[0048] An identification module, configured to determine whether the possible malicious behavior is a malicious behavior according to the extracted existence features and transfer features.
[0049] The embodiments of this specification at least have the following advantages or beneficial effects:
[0050] The network malicious behavior detection method can accurately obtain the correlation relationship and functional similarity between interfaces, and use the node mutual information graph and embedded graph to represent the call relationship and similarity of the above interfaces. Then, by extracting transfer features to represent the call association relationship between different interfaces of possible malicious behaviors, and identifying the above two fused features, the accuracy of the malicious behavior detection result can be effectively improved, so as to realize the identification and classification of network malicious attack behaviors. Brief Description of the Drawings
[0051] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this specification, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other relevant drawings can also be obtained based on these drawings.
[0052] Figure 1 It is a schematic flowchart of the network malicious attack detection method with multi-perspective feature fusion provided by this specification;
[0053] Figure 2 It is another schematic flowchart of the network malicious attack detection method with multi-perspective feature fusion provided by this specification;
[0054] Figure 3 It is a schematic diagram of the network malicious attack detection system with multi-perspective feature fusion provided by this specification. Detailed Embodiment
[0055] To make the objectives, technical solutions, and advantages of the embodiments of this specification clearer, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are some, but not all, of the embodiments of this specification. Generally, the components of the embodiments of this specification described and shown in the drawings here can be arranged and designed in various different configurations.
[0056] Please refer to Figure 1 and Figure 2 , an embodiment of this specification provides a network malicious attack detection method with multi-perspective feature fusion, which mainly includes:
[0057] Step 102: Determine possible malicious behaviors, the interfaces involved, and the interface call sequences according to the obtained network operation records of key network communication facilities;
[0058] Step 104: According to the interfaces and interface call sequences involved in the possible malicious behavior, by constructing a node mutual information graph and an embedded graph, extract the existence features of the malicious behavior. The nodes of the node mutual information graph and the embedded graph are the interfaces involved in the possible malicious behavior.
[0059] Step 106: According to the interfaces and interface call sequences involved in the possible malicious behavior, construct a transition probability matrix through the K-means algorithm, and extract the transfer features of the possible malicious behavior.
[0060] Step 108: According to the extracted existence features and transfer features, determine whether the possible malicious behavior is a malicious behavior.
[0061] In this embodiment, the above-mentioned key network communication facilities refer to facilities vulnerable to threats, such as servers, routers, and computer terminals.
[0062] In this embodiment, through the above method, the correlation relationship and functional similarity between interfaces can be accurately obtained, and the call relationship and similarity of the above interfaces are characterized by a node mutual information graph and an embedded graph. Then, the call association relationship between different interfaces of the possible malicious behavior is characterized by extracting transfer features, and the above two features after fusion are identified, which can effectively improve the accuracy of the malicious behavior detection result, so as to realize the identification and classification of network malicious attack behaviors.
[0063] In this embodiment, by optimizing the existence features and fully mining the transfer features of malicious behaviors in the above way, the reliability of network malicious attack behavior detection can be effectively improved.
[0064] In this embodiment, one implementation manner of Step 102 is specifically as follows:
[0065] Step 112: According to the network operation records of the key network communication facilities obtained, determine whether the network operation behavior conforms to the network security protection strategy.
[0066] Step 114: If not, determine the network operation behavior that does not conform to the network security protection strategy as the possible malicious behavior.
[0067] In this embodiment, if so, it is considered that the current network operation behavior is a normal network behavior and not a malicious behavior.
[0068] In this embodiment, using the above-mentioned key network communication facilities as security ontology instances, determine whether some or all of the network operation behaviors of the security ontology instances violate the security protection strategy. If so, determine the current network operation behavior as a possible malicious behavior.
[0069] In this embodiment, the above-mentioned network operation records can be network operation logs.
[0070] In this embodiment, through the above method, network malicious behaviors can be formally described in a specific manner, so as to extract relevant features of network malicious behaviors for analysis.
[0071] In this embodiment, one implementation manner of step 102 is specifically as follows:
[0072] Step 122: According to the network operation records of the obtained key network communication facilities, construct a malicious behavior threat association graph through the KeyGraph algorithm;
[0073] Step 124: Determine the key threat association strength according to the malicious behavior threat association graph;
[0074] Step 126: Determine a malicious behavior interface path call model according to the key threat association strength;
[0075] Step 128: Determine the interfaces involved in the possible malicious behavior and the interface call sequence according to the possible malicious behavior and the malicious behavior interface path call model.
[0076] In this embodiment, by constructing a malicious behavior threat degree association graph, the implicit threat of network malicious attacks can be quantitatively evaluated.
[0077] In this embodiment, the above malicious behavior threat association graph extracts the key threat association strength according to malicious behavior correlation and probability theory, that is, determines the threat behavior implicit in the network malicious attack behavior through the above method.
[0078] In this embodiment, according to the above malicious behavior threat association graph, through the initial interface call model (the initial parameters are determined according to prior knowledge), the key threat association strength is determined, and the initial parameters are iteratively adjusted according to the key threat association strength to determine the accurate malicious behavior interface path call model corresponding to the current malicious behavior threat association graph.
[0079] In this embodiment, the parameter setting range or parameter setting of the above initial interface call model has the characteristic of being broad.
[0080] In this embodiment, the above malicious behavior interface path call model Specifically:
[0081]
[0082] Wherein, is the malicious behavior threat association graph, is a key cluster in the malicious behavior threat association graph. are respectively the security metric index set, security metric index, threat association digraph, threat association vertex set, and threat association vertex. Indicates the number of arrows pointing to a vertex in the threat correlation directed graph .
[0083] In this embodiment, one implementation of step 104 is as follows:
[0084] Step 132: Use the interfaces involved in the possible malicious behavior as nodes, and use the correlation degree between two nodes as the correlation edge;
[0085] Step 134: Determine the call matrix of the system interface set according to the call order and call distance of each node in the interface call sequence; the call distance represents the number of nodes separated between two nodes in the interface call sequence;
[0086] Step 136: Determine the call vector of the calling node and the weight of the first correlation edge according to the call matrix;
[0087] Step 138: Construct the node mutual information graph according to the weight of the first correlation edge.
[0088] In this embodiment, the system interface set represents the complete set of interfaces possessed by the operating system, which can be expressed as . Taking to represent the call relationship between nodes and , to represent the call vector of node , PMI represents the correlation between interfaces. If PMI is positive, it indicates a high correlation between interfaces, while if PMI is negative, it indicates no correlation between interfaces, that is, there is no first correlation edge between two nodes.
[0089] In this embodiment, and are calculated as follows:
[0090]
[0091]
[0092] The weight of the first correlation edge is calculated as follows:
[0093]
[0094]
[0095]
[0096] Among them, are any two different nodes respectively, represents node The th element of the call vector, represents any node call vector mean, is the call frequency of any node in the interface call sequence, the frequency of occurrence of any node in the interface call sequence, represents the total length of the interface call sequence.
[0097] In this embodiment, the above interface refers to the call interface of the application program.
[0098] In this embodiment, one implementation manner of step 104 is specifically as follows:
[0099] Step 142: Group the interfaces through the 2-gram of the interface call sequence, and determine the node function similarity threshold through the L2 norm between the node embedding vectors . Nodes with a function similarity greater than have a second associated edge, otherwise there is no second associated edge;
[0100] Step 144: Determine the neighbor nodes with similar functions to each node through the L2 norm between the node embedding vectors;
[0101] Step 146: Calculate the function similarity between each node and its neighbor nodes with similar functions;
[0102] Step 146: Add a second associated edge between each node and its neighbor nodes with similar functions and determine the weight of the second associated edge;
[0103] Step 148: Determine the embedded graph according to the weight of the second associated edge.
[0104] In this embodiment, the interface call sequence can be embedded and encoded specifically according to its context, and the neighbor nodes with similar functions to each node are determined through the L2 norm between the node embedding vectors.
[0105] In this embodiment, two adjacent interfaces in the interface call sequence form an interface group, and the set of interface groups is denoted as U. The node function similarity threshold is calculated as follows:
[0106]
[0107]
[0108] The weight of the above second associated edge is specifically calculated as:
[0109]
[0110]
[0111] Among them, represents the length of the interface grouping set, represents the node L2 norm distance of the word embedding, represents the node node embedding vector obtained based on word2vec.
[0112] In this embodiment, one implementation manner of step 104 is specifically as follows:
[0113] Step 152: Determine the first adjacency matrix according to the node mutual information graph;
[0114] Step 154: Determine the second adjacency matrix according to the embedded graph;
[0115] Step 156: According to the first adjacency matrix and the second adjacency matrix, respectively extract the first behavior feature and the second behavior feature through a multi-layer Transformer network, and the first behavior feature and the second behavior feature respectively correspond to the node mutual information graph and the embedded graph;
[0116] Step 158: Determine the existence feature of the possible malicious behavior according to the first behavior feature and the second behavior feature.
[0117] In this embodiment, through the above method, the call relationship between the software and the interface can be incorporated into the constructed node mutual information graph and the embedded graph, thereby effectively enhancing the semantic information of the network malicious attack behavior.
[0118] In this embodiment, represents the node mutual information graph in the node, then the adjacency matrix constructed based on the node mutual information graph is denoted as :
[0119]
[0120] represents the node based on the embedded graph in the node, then the adjacency matrix constructed based on the embedded graph is denoted as :
[0121]
[0122] In this embodiment, the first behavior feature and the second behavior feature Respectively:
[0123]
[0124]
[0125]
[0126]
[0127]
[0128]
[0129]
[0130]
[0131] Among them, represents the -th layer Transformer block. The Transformer block fuses through the multi-head attention mechanism to obtain the first-row feature and the second-row feature . represents the learnable weight of the -th layer Transformer block. represents the query feature, key feature, and value feature of the -rd attention head. represents the learnable weight of the query feature, key feature, and value feature of the -th attention head. * represents or .
[0132] In this embodiment, the above first-row feature and second-row feature are compressed by a one-dimensional convolutional neural network, that is:
[0133]
[0134]
[0135] Among them, represents the dimensionality reduction convolutional network. represents the concatenation operation.
[0136] In this embodiment, through the above method, the existence feature can represent the correlation call relationship and similarity call relationship between the software and the interface.
[0137] In this embodiment, it further includes:
[0138] Step 162: Iteratively update the Transformer network through the loss function until the accuracies of the first line feature and the second line feature output by the updated Transformer network meet the extraction conditions.
[0139] Specifically, in this embodiment, in order to optimize and obtain the first line feature and the second line feature that meet the detection accuracy, it can be specifically achieved through the following methods:
[0140] Map the behavior features based on the node mutual information graph and the embedded graph to the feature loss space:
[0141]
[0142]
[0143] where represents a multi-layer perceptron.
[0144] The loss function is used to update the model parameters through backpropagation and supervise the model to learn more important behavior features, denoted as :
[0145]
[0146] where represents the set of software samples in the training batch, represents the temperature coefficient, is the set of positive samples and negative samples constructed based on the cosine similarity of the interface call sequence (i.e., the set of similar software samples and the set of different software samples).
[0147] In this embodiment, by determining the loss function of the above Transformer network, the Transformer network can be iteratively optimized, so that the accuracies of the output first line feature and second line feature are stronger.
[0148] In this embodiment, the existence feature is enhanced and fused through the channel attention mechanism of the first line feature and the second line feature. The fusion method of the existence feature is:
[0149]
[0150]
[0151] where represents a multi-layer perceptron, represents the average pooling operation in the channel direction, Max pooling operation indicating the channel direction, * indicates or .
[0152] In this embodiment, one implementation manner of step 106 is as follows:
[0153] Step 172: Through the K-means algorithm, cluster the interfaces involved in the possible malicious behavior to determine each cluster and the center of each cluster;
[0154] Step 174: According to the interface call sequence involved in the possible malicious behavior and the cluster to which the interface belongs, construct an interface call cluster sequence;
[0155] Step 176: Using the interface call cluster sequence as a Markov chain, with each cluster as the state of the interface, generate a transition probability matrix through state transition statistical probability;
[0156] Step 178: Using the transition probability matrix as the input, extract the transfer characteristics of the possible malicious behavior through a convolutional neural network.
[0157] In this embodiment, taking the interface set as , through the above K-means algorithm, cluster the interface set, that is:
[0158] Set the cluster center of the above interface set as , and the cluster label corresponding to each cluster center is , then:
[0159]
[0160]
[0161] Update the cluster center word embedding:
[0162]
[0163] Through the above steps of iteration until the clustering center no longer changes.
[0164] For the application program interface call sequence , according to the cluster to which the interface belongs, construct an application program interface call cluster sequence :
[0165]
[0166] Among them. is the length of the application program interface call sequence.
[0167] In this embodiment, taking the interface call cluster sequence Regarded as a Markov chain, each of the above clusters represents the state of the interface. According to the statistical probability of interface state transition, a transition probability matrix is generated :
[0168]
[0169] Among them, represents the state to state transition probability, , .
[0170] In this embodiment, according to the above transition probability matrix generate order transition probability matrix .
[0171] In this embodiment, the interface call sequence is divided into clusters in two rounds. During the second round of cluster division, the cluster with the highest frequency of occurrence in the first round of cluster division is deleted from the cluster set, so as to obtain two different groups of interface call cluster sequences. These two different groups of interface call cluster sequences are used as two different views to construct two groups of order transition probability matrix .
[0172] Then, metastatic features are extracted through a convolutional neural network:
[0173]
[0174]
[0175] Among them, represents the weight parameter of the fully connected layer, represents that the weight parameter is convolutional network of
[0176] It can be seen that the metastatic features extracted by the above method can fully characterize the correlation relationship between different interfaces. Moreover, the reliability of trojan and virus detection can be effectively improved through the above two perspectives (i.e., two different views).
[0177] In this embodiment, in order to make the extraction accuracy of the above metastatic features meet the detection and recognition requirements, a loss function corresponding to the above convolutional neural network is constructed, and the above convolutional neural network model is optimized, that is:
[0178] Map the transfer features of the two different views to the feature loss space:
[0179]
[0180]
[0181] The loss function of the convolutional neural network is used for backpropagation to update the model parameters and supervise the model to learn more important transfer features, denoted as :
[0182]
[0183] Among them, represents the set of software samples in the training batch, represents the temperature coefficient.
[0184] In this embodiment, the transfer feature is concatenated to obtain the transfer feature of the possible malicious behavior :
[0185]
[0186] In this embodiment, the interface call sequence can be converted into an interface call cluster sequence in the above manner, so as to mine the interface call subsequence.
[0187] In this embodiment, the above interface call sequence can be the interface call sequence of the software, so as to mine the interface call subsequence of the software.
[0188] In this embodiment, a specific implementation manner of step 108 is as follows:
[0189] Step 182, fuse the existence feature and the transfer feature to obtain a fused feature;
[0190] Step 184, use the fused feature as an input, and through a one-dimensional convolutional neural network, identify the possible malicious behavior and determine whether the possible malicious behavior is a malicious behavior.
[0191] In this embodiment, the malicious attack behavior feature can be activated through a feature fusion activation network.
[0192] In this embodiment, the above fused feature can be identified by a network malicious attack detector, that is:
[0193]
[0194] represents the recognition result, that is, the attack type of the possible malicious behavior, represents the weight matrix and bias vector of the network malicious attack detector.
[0195] Please refer to Figure 3 , Another embodiment of this specification provides a network malicious attack detection system with multi-perspective feature fusion, mainly including:
[0196] A determination module 202, configured to determine possible malicious behaviors and the interfaces and interface call sequences involved therein according to the obtained network operation records of key network communication facilities;
[0197] An existence feature extraction module 204, configured to extract the existence features of the malicious behavior by constructing a node mutual information graph and an embedded graph according to the interfaces and interface call sequences involved in the possible malicious behavior, wherein the nodes of the node mutual information graph and the embedded graph are the interfaces involved in the possible malicious behavior;
[0198] A transfer feature extraction module 206, configured to extract the transfer features of the possible malicious behavior by constructing a transfer probability matrix through the K-means algorithm according to the interfaces and interface call sequences involved in the possible malicious behavior;
[0199] An identification module 208, configured to determine whether the possible malicious behavior is a malicious behavior according to the extracted existence features and transfer features.
[0200] Specifically, through the above method, the correlation relationship and functional similarity between interfaces can be accurately obtained, and the call relationship and similarity of the above interfaces are characterized by a node mutual information graph and an embedded graph. Then, the call association relationship between different interfaces of the possible malicious behavior is characterized by extracting transfer features, and the two fused features are identified, which can effectively improve the accuracy of the malicious behavior detection result, so as to realize the identification and classification of network malicious attack behaviors.
[0201] In this embodiment, the above determination module 202 is configured to determine whether the network operation behavior conforms to the network security protection policy according to the obtained network operation records of key network communication facilities; if not, the network operation behavior that does not conform to the network security protection policy is determined as the possible malicious behavior. According to the obtained network operation records of key network communication facilities, a malicious behavior threat association graph is constructed through the KeyGraph algorithm; according to the malicious behavior threat association graph, the key threat association intensity is determined; according to the key threat association intensity, a malicious behavior interface path call model is determined; according to the possible malicious behavior and the malicious behavior interface path call model, the interfaces and interface call sequences involved in the possible malicious behavior are determined. Through the above method, network malicious behaviors can be formally described in detail, so as to facilitate the extraction of relevant features of network malicious behaviors for analysis. Moreover, by constructing a malicious behavior threat degree association graph, the implicit threat of network malicious attacks can be quantitatively evaluated.
[0202] In this embodiment, the existence feature extraction module 204 uses the interfaces involved in the possible malicious behavior as nodes, and the Pearson frequency coefficient between two nodes as the associated edge; determines the correlation between nodes according to the Pearson coefficient of the call vector of each node and the frequency coefficient of the call sequence; determines the weight of the first associated edge according to the correlation between the nodes; constructs the node mutual information graph according to the weight of the first associated edge. Group the interfaces through the 2-gram of the interface call sequence, and determine the node function similarity threshold through the L2 norm between the node embedding vectors . Nodes with a function similarity greater than have a second associated edge, otherwise there is no second associated edge; determine the neighbor nodes similar to the function of each node through the L2 norm between the node embedding vectors; calculate the function similarity between each node and its neighbor nodes with similar functions; add a second associated edge between each node and its neighbor nodes with similar functions and determine the weight of the second associated edge; determine the embedded graph according to the weight of the second associated edge. Determine the first adjacency matrix according to the node mutual information graph; determine the second adjacency matrix according to the embedded graph; respectively extract the first behavior feature and the second behavior feature through the Transformer network according to the first adjacency matrix and the second adjacency matrix, and the first behavior feature and the second behavior feature respectively correspond to the node mutual information graph and the embedded graph; determine the existence feature of the possible malicious behavior according to the first behavior feature and the second behavior feature. Iteratively update the Transformer network through the Transformer network loss function until the accuracies of the first behavior feature and the second behavior feature output by the updated Transformer network meet the extraction conditions. Through the above method, the associated call relationship and the similar call relationship between the software and the interfaces can be characterized by the existence feature, and through the above method, the call relationship between the software and the interfaces can be incorporated into the constructed node mutual information graph and the embedded graph, thereby effectively enhancing the semantic information of the network malicious attack behavior.
[0203] In this embodiment, the transfer feature extraction module 206 uses the K-means algorithm to perform cluster division on the interfaces involved in the possible malicious behavior to determine each cluster and the center of each cluster; constructs an interface call cluster sequence according to the interface call sequence involved in the possible malicious behavior and the cluster to which the interface belongs; uses the interface call cluster sequence as a Markov chain, and each cluster as the state of the interface, and generates a transition probability matrix through the state transition statistical probability; uses the transition probability matrix as the input and extracts the transfer feature of the possible malicious behavior through a convolutional neural network. Through the above method, the interface call sequence can be converted into an interface call cluster sequence, so as to achieve the excavation of the interface call subsequence. And the associated relationship between the interfaces can be accurately characterized by the transfer feature.
[0204] In this embodiment, the recognition module 208 is configured to fuse the existence feature and the metastasis feature to obtain a fused feature; using the fused feature as an input, through a one-dimensional convolutional neural network, recognize the possible malicious behavior and determine whether the possible malicious behavior is a malicious behavior.
[0205] Based on the same inventive concept, another embodiment of this specification further provides a computer-readable storage medium. The above computer-readable storage medium stores one or more programs. When the above one or more programs are executed by an electronic device including multiple application programs, the above electronic device is caused to execute Figure 1 the multi-perspective feature fusion network malicious attack detection method provided by the corresponding embodiment.
[0206] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.
[0207] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, this specification can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this specification can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0208] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of this specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 the blocks.
[0209] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the function specified in one process Figure 1 or process(es) and / or block(s) Figure 1 or block(s) specified in one or more processes and / or blocks.
[0210] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the function specified in one process Figure 1 or process(es) and / or block(s) Figure 1 or block(s) specified in one or more processes and / or blocks.
[0211] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0212] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0213] The above are only examples of the embodiments of this application and are not used to limit this specification. For those skilled in the art, various changes and modifications can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.
Claims
1. A network malicious attack detection method based on multi-view feature fusion, characterized in that Including: Based on the network operation records of the obtained network communication key facilities, determine the possible malicious behaviors and the interfaces and interface call sequences involved; Based on the interfaces and interface call sequences involved in the possible malicious behaviors, by constructing a node mutual information graph and an embedded graph, extract the existence features of the malicious behaviors. The nodes of the node mutual information graph and the embedded graph are the interfaces involved in the possible malicious behaviors, including: Use the interfaces involved in the possible malicious behaviors as nodes and the correlation degree between two nodes as the correlation edge; According to the call order and call distance of each node in the interface call sequence, determine the call matrix of the system interface set; the call distance represents the number of nodes separated between two nodes in the interface call sequence; According to the call matrix, determine the call vector of the call node and the weight of the first correlation edge; According to the weight of the first correlation edge, construct the node mutual information graph; Group the interfaces by 2-gram of the interface call sequence, and determine the node function similarity threshold by the L2 norm between the node embedding vectors ; If the functional similarity between nodes is greater than there is a second associated edge for the nodes, otherwise there is no second associated edge; Determine the neighbor nodes with similar functions to each node through the L2 norm between node embedding vectors; Calculate the function similarity between each node and its neighbor nodes with similar functions; Add a second correlation edge between each node and its neighbor nodes with similar functions and determine the weight of the second correlation edge; According to the weight of the second correlation edge, determine the embedded graph; According to the node mutual information graph, determine the first adjacency matrix; According to the embedded graph, determine the second adjacency matrix; According to the first adjacency matrix and the second adjacency matrix, through a multi-layer Transformer network, extract the first behavior feature and the second behavior feature respectively. The first behavior feature and the second behavior feature correspond to the node mutual information graph and the embedded graph respectively; According to the first behavior feature and the second behavior feature, determine the existence feature of the possible malicious behavior; Based on the interfaces and interface call sequences involved in the possible malicious behaviors, construct a transition probability matrix through the K-means algorithm and extract the transfer features of the possible malicious behaviors; According to the extracted existence feature and transfer feature, determine whether the possible malicious behavior is a malicious behavior.
2. The network malicious attack detection method with multi-view feature fusion according to claim 1, wherein The step of based on the network operation records of the obtained network communication key facilities, determining the possible malicious behaviors and the interfaces and interface call sequences involved, includes: Based on the network operation records of the obtained network communication key facilities, determine whether the network operation behavior conforms to the network security protection strategy; If not, determine the network operation behavior that does not conform to the network security protection strategy as the possible malicious behavior.
3. The network malicious attack detection method with multi - perspective feature fusion according to claim 1, characterized in that, The step of based on the network operation records of the obtained network communication key facilities, determining the possible malicious behaviors and the interfaces and interface call sequences involved, includes: Based on the network operation records of the obtained network communication key facilities, construct a malicious behavior threat association graph through the KeyGraph algorithm; According to the malicious behavior threat association graph, determine the key threat association intensity; Determine a malicious behavior interface path call model according to the key threat association intensity, and the malicious behavior interface path call model Specifically: ; Among them, is a malicious behavior threat association graph, which is a key cluster in the malicious behavior threat association graph, respectively representing a security metric index set, a security metric index, a threat association directed graph, a threat association vertex set, and a threat association vertex, indicating the number of arrows pointing to vertex in the threat association directed graph; Based on the possible malicious behavior and the malicious behavior interface path call model, determine the interfaces and interface call sequences involved in the possible malicious behavior.
4. The network malicious attack detection method with multi-view feature fusion according to claim 1, characterized in that, Before determining the existence feature of the possible malicious behavior based on the first behavior feature and the second behavior feature, it includes: Iteratively update the graph convolutional neural network through the graph convolutional neural network loss function until the accuracies of the first behavior feature and the second behavior feature output by the updated graph convolutional neural network meet the extraction conditions.
5. The method for detecting network malicious attacks with multi - perspective feature fusion according to claim 1, wherein The step of constructing a transition probability matrix through the K-means algorithm according to the interfaces and interface call sequences involved in the possible malicious behavior, and extracting the transferability feature of the possible malicious behavior includes: Using the K-means algorithm to perform cluster partitioning on the interfaces involved in the possible malicious behavior to determine each cluster and the center of each cluster; Construct an interface call cluster sequence according to the interface call sequence involved in the possible malicious behavior and the cluster to which the interface belongs; Taking the interface call cluster sequence as a Markov chain, and taking each cluster as the state of the interface, generate a transition probability matrix through state transition statistical probability; Taking the transition probability matrix as input, extract the transferability feature of the possible malicious behavior through a convolutional neural network.
6. The network malicious attack detection method with multi-view feature fusion according to claim 1, wherein The step of determining whether the possible malicious behavior is a malicious behavior according to the extracted existence feature and transferability feature includes: Fuse the existence feature and the transferability feature to obtain a fused feature; Taking the fused feature as input, identify the possible malicious behavior through a one-dimensional convolutional neural network to determine whether the possible malicious behavior is a malicious behavior.
7. A network malicious attack detection system with multi-view feature fusion, characterized in that, It includes: A determination module for determining possible malicious behaviors and their involved interfaces and interface call sequences according to the network operation records of key network communication facilities obtained; An existence feature extraction module for extracting the existence feature of the malicious behavior by constructing a node mutual information graph and an embedded graph according to the interfaces and interface call sequences involved in the possible malicious behavior, where the nodes of the node mutual information graph and the embedded graph are the interfaces involved in the possible malicious behavior, and it includes: Taking the interfaces involved in the possible malicious behavior as nodes and the correlation degree between two nodes as the correlation edge; Determine the call matrix of the system interface set according to the call order and call distance of each node in the interface call sequence; the call distance represents the number of nodes separated between two nodes in the interface call sequence; Determine the call vector of the calling node and the weight of the first correlation edge according to the call matrix; Construct the node mutual information graph according to the weight of the first correlation edge; Group the interfaces by 2-grams of the interface call sequence, and determine the node function similarity threshold by the L2 norm between the node embedding vectors ; If the functional similarity between nodes is greater than There is a second associated edge for the nodes, and vice versa if there is no second associated edge; Determine neighbor nodes with similar functions to each node through the L2 norm between node embedding vectors; Calculate the function similarity between each node and its neighbor nodes with similar functions; Add a second correlation edge between each node and its neighbor nodes with similar functions and determine the weight of the second correlation edge; Determine the embedded graph according to the weight of the second correlation edge; Determine the first adjacency matrix according to the node mutual information graph; Determine the second adjacency matrix according to the embedded graph; According to the first adjacency matrix and the second adjacency matrix, the first row features and the second row features are respectively extracted through a multi-layer Transformer network, and the first row features and the second row features respectively correspond to the node mutual information graph and the embedded graph; According to the first row features and the second row features, determine the existence features of the possible malicious behavior; The transfer feature extraction module is used to construct a transfer probability matrix through the K-means algorithm according to the interfaces and interface call sequences involved in the possible malicious behavior, and extract the transfer features of the possible malicious behavior; The recognition module is used to determine whether the possible malicious behavior is a malicious behavior according to the extracted existence features and transfer features.
Citation Information
Patent Citations
Proactively detecting malicious domains using graph representation learning
US20240333749A1
Method and apparatus for anomaly detection on graph
WO2023010502A1