A method for detecting APT attacks based on random walk and neighborhood reconstruction

Through detection methods based on random walk and neighborhood reconstruction, the problem that traditional detection methods are difficult to deal with APT network attacks is solved, and comprehensive monitoring of system behavior and accurate identification of abnormal nodes is achieved, which significantly improves the effectiveness of network security defense.

CN119788420BActive Publication Date: 2025-05-13ZHEJIANG UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510266649.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-05-13
Estimated Expiration
2045-03-07

AI Technical Summary

Technical Problem

Traditional network traffic-based detection methods are difficult to cope with the concealment and diversity of APT network attacks, and directly extracting artificial predefined features from system log data will lead to information loss.

Method used

APT attack detection method based on random walk and neighborhood reconstruction is adopted, and the traceability map is constructed by obtaining benign system log data, and the noise is removed using Laplace regularization, a breadth-first random walk strategy and an unsupervised learning algorithm based on neural networks is used to generate embedded vectors, and finally anomalies are detected using neighborhood reconstruction model.

Benefits of technology

It significantly improves the efficiency and ability of network security prevention, can effectively reduce noise, deeply mine node context semantic information and local topological characteristics, accurately identify multiple types of abnormal nodes, and deal with complex network attack scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788420B_ABST
    Figure CN119788420B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of network security and machine learning, and discloses an APT attack detection method based on random walk and neighborhood reconstruction, including obtaining benign system log data and obtaining a denoised traceability graph; adopting a breadth-first random walk strategy to obtain a walk path, adopting an unsupervised learning algorithm based on a neural network to learn the walk path, and obtaining an embedding vector of each node in the denoised traceability graph; obtaining a neighborhood reconstruction model based on an encoder and a decoder, inputting the embedding vector of the node into the neighborhood reconstruction model, and calculating the node attribute reconstruction loss, edge distribution reconstruction loss and neighbor distribution reconstruction loss of each node according to the output of the neighborhood reconstruction model; combining to obtain the total reconstruction loss of the node, and updating and optimizing the neighborhood reconstruction model according to the total reconstruction loss. The present invention effectively responds to complex network attack scenarios and significantly improves the efficiency and ability of network security prevention.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and machine learning, and in particular relates to an APT attack detection method based on random walk and neighborhood reconstruction. Background Art

[0002] Compared with traditional network attacks, APT (Advanced Persistent Threat) network attacks are highly concealed, have a long incubation period, and have a variety of attack methods, which makes it difficult for traditional detection methods based on network traffic to deal with them. Therefore, comprehensive monitoring of system behavior to discover the actual destructive behavior of APT network attacks on the system is one of the effective means to deal with the concealment and diversity of APT network attacks.

[0003] On the other hand, with the development of machine learning technology, network attack detection methods based on machine learning have received widespread attention. Machine learning technologies used for network attack detection include traditional shallow learning technology and deep learning technology. Among them, deep learning technology usually has higher accuracy and generalization ability because it can automatically learn complex nonlinear hidden features. Deep learning models commonly used for network attack detection include MLP (multi-layer perceptron), CNN (convolutional neural network), LSTM (long short-term memory network), automatic encoder, etc. However, since the system behavior contained in the system log data is very complex, the unprocessed raw data has more noise, and if the artificially predefined features are directly extracted from the system log data, it will cause great information loss due to the complexity of APT network attacks.

[0004] In response to the above problems, how to reduce the noise of data and use deep learning to automatically learn the detection model of APT network attacks is an issue that needs to be solved urgently. Summary of the invention

[0005] The purpose of the present invention is to provide an APT attack detection method based on random walk and neighborhood reconstruction, which can effectively deal with complex network attack scenarios and significantly improve the efficiency and capability of network security prevention.

[0006] To achieve the above object, the technical solution adopted by the present invention is:

[0007] A method for detecting an APT attack based on random walk and neighborhood reconstruction, the method comprising:

[0008] Obtain benign system log data and construct a traceability graph. Based on the traceability graph, construct a Laplace matrix and use Laplace regularization to remove neighbor noise of nodes in the traceability graph to obtain a denoised traceability graph.

[0009] A breadth-first random walk strategy is adopted to traverse the walk path starting from each node in the denoised traceability graph, and an unsupervised learning algorithm based on a neural network is used to learn the walk path to obtain the embedding vector of each node in the denoised traceability graph.

[0010] Obtain a neighborhood reconstruction model based on an encoder and a decoder, input the node's embedding vector into the neighborhood reconstruction model, and calculate the node attribute reconstruction loss, edge distribution reconstruction loss, and neighbor distribution reconstruction loss of each node according to the output of the neighborhood reconstruction model;

[0011] Combine the node attribute reconstruction loss, edge distribution reconstruction loss and neighbor distribution reconstruction loss to get the total reconstruction loss of the node, and update the optimized neighborhood reconstruction model based on the total reconstruction loss;

[0012] The acquired system log data to be detected is input into the updated and optimized neighborhood reconstruction model, and the total reconstruction loss corresponding to the system log data to be detected is calculated according to the output of the neighborhood reconstruction model. If the total reconstruction loss corresponding to the system log data to be detected exceeds the abnormal threshold, it is judged that the system log data to be detected has an APT network attack; otherwise, the system log data to be detected has no APT network attack.

[0013] Several optional methods are also provided below, but they are not intended to be additional limitations on the above-mentioned overall solution, but are merely further supplements or preferences. Under the premise that there are no technical or logical contradictions, each optional method can be combined with the above-mentioned overall solution separately, and multiple optional methods can also be combined.

[0014] Preferably, the step of constructing a Laplace matrix based on the source tracing graph includes:

[0015] The Word2Vec model is used to generate corresponding feature vectors for each node in the traceability graph;

[0016] Determine edge weights based on the similarity of node attribute features and topological structure association similarity in the traceability graph;

[0017] Construct a weight matrix based on the edge connection relationship between any two nodes in the traceability graph;

[0018] Calculate the node degree matrix based on the weight matrix;

[0019] The Laplacian matrix is ​​obtained by subtracting the node degree matrix from the weight matrix.

[0020] Preferably, the determining of edge weights based on the similarity of node attribute features and topological structure association similarity in the provenance graph includes:

[0021]

[0022]

[0023]

[0024] In the formula, Representation Node and nodes The similarity of node attribute features between Representation Node The characteristic vector of Representation Node The characteristic vector of Representation Node The magnitude of the eigenvector of Representation Node The magnitude of the eigenvector of Representation Node and nodes The topological structure association similarity between is the maximum number of hops in the time window, Indicates The weight of the hopping neighbor, Representation Node and nodes No. The sum of the number of hop neighbors, is the first The sum of the number of hop neighbors, Representation Node and nodes The edge weights between is the first weight adjustment parameter, is the second weight adjustment parameter, and .

[0025] Preferably, constructing a weight matrix according to the edge connection relationship between any two nodes in the traceability graph includes:

[0026] For any two nodes in the traceability graph, if the edge connection relationship between the two nodes is edge-connected, the weight between the two nodes in the weight matrix is ​​taken as the edge weight; if the edge connection relationship between the two nodes is disconnected, the weight between the two nodes in the weight matrix is ​​taken as 0.

[0027] Preferably, the method of removing neighbor noise of nodes in the provenance graph by using Laplace regularization to obtain a denoised provenance graph includes:

[0028] The convex quadratic optimization problem is constructed as follows:

[0029]

[0030] Solve the convex quadratic optimization problem and obtain the node after removing the neighbor noise:

[0031]

[0032]

[0033] In the formula, is the feature vector of the node in the denoised traceability graph after removing the neighbor noise, represents the feature vector of a node in the provenance graph, is the regularization parameter, Represents the feature vector of the node after removing neighbor noise The transpose of is the Laplace matrix, is the identity matrix.

[0034] Preferably, in the breadth-first random walk strategy, the transition probability is calculated as follows:

[0035]

[0036] In the formula, Represents a slave node Transfer to Node The probability of For Node The number of outgoing edges, Representation Node With Node The edge between Represents the edge set in the provenance graph.

[0037] Preferably, the calculating of the node attribute reconstruction loss, the edge distribution reconstruction loss and the neighbor distribution reconstruction loss according to the output of the neighborhood reconstruction model comprises:

[0038] The node attribute reconstruction loss is calculated as follows:

[0039]

[0040] In the formula, For Node The node attribute reconstruction loss is is the distance function, For Node The embedding vector of Nodes output by the neighborhood reconstruction model The reconstructed embedding vector;

[0041] The edge distribution reconstruction loss is calculated as follows:

[0042]

[0043]

[0044]

[0045] In the formula, For Node The feature mean of all original edges, Representation Node The total number of edges, Representation Node With Node The feature vectors of the edges between For Node The set of neighbor nodes of For Node The feature covariance matrix of all original edges, express The transpose of For Node The edge distribution reconstruction loss, represents the KL divergence, Refers to satisfying the mean The variance is The normal distribution of Refers to satisfying the mean The variance is The normal distribution of Nodes output by the neighborhood reconstruction model The feature mean of all original edges after reconstruction, Nodes output by the neighborhood reconstruction model The feature covariance matrix after reconstruction of all original edges;

[0046] The neighbor distribution reconstruction loss is calculated as follows:

[0047]

[0048]

[0049]

[0050] In the formula, For Node The feature mean of the neighbor nodes, Representation Node The total number of neighbor nodes, For Node The embedding vector of For Node The feature covariance matrix of the neighbor nodes of for The transpose of Nodes output by the neighborhood reconstruction model The feature mean of the reconstructed neighbor nodes, Nodes output by the neighborhood reconstruction model The feature covariance matrix of the reconstructed neighbor nodes, Refers to satisfying the mean The variance is The normal distribution of Refers to satisfying the mean The variance is The normal distribution of For Node The neighbor distribution reconstruction loss.

[0051] Preferably, the node attribute reconstruction loss, the edge distribution reconstruction loss and the neighbor distribution reconstruction loss are combined to obtain the total reconstruction loss, including:

[0052]

[0053] In the formula, For Node The total reconstruction loss is is the first weight hyperparameter, is the second weight hyperparameter, is the third weight hyperparameter.

[0054] The APT attack detection method based on random walk and neighborhood reconstruction provided by the present invention has the following beneficial effects compared with the prior art:

[0055] 1. Construct a weight matrix based on the similarity of node attribute features and the similarity of topological structure association. On this basis, the Laplace regularization denoising method can reduce neighbor noise while retaining the graph structure features. At the same time, this method has high computational efficiency. 2. Use random walks and unsupervised learning algorithms based on neural networks (such as the Skip-gram algorithm) to generate embedding vectors, which can avoid changes in graph structure caused by imitation attacks, and can deeply mine node context semantic information and local topological features to enhance the accuracy and richness of node feature expression. 3. Use the neighborhood reconstruction method to detect abnormal nodes, and use node attributes, edge distribution, and neighbor distribution as reconstruction indicators to fully capture system behavior information, accurately identify various types of abnormal nodes, effectively respond to complex network attack scenarios, and significantly improve network security defense effectiveness. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 A flowchart of an APT attack detection method based on random walk and neighborhood reconstruction of the present invention;

[0057] Figure 2 It is a structural schematic diagram of the neighborhood reconstruction model of the present invention. DETAILED DESCRIPTION

[0058] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0059] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used in the specification of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention.

[0060] like Figure 1 As shown, this embodiment provides an APT attack detection method based on random walk and neighborhood reconstruction, comprising the following steps:

[0061] (1) Graph construction and Laplace regularization denoising: Obtain benign system log data and construct a traceability graph. Based on the traceability graph, build a Laplace matrix and use Laplace regularization to remove the neighbor noise of the nodes in the traceability graph to obtain a denoised traceability graph.

[0062] (1-1) Tracing graph construction: Collect benign system log data from multiple system audit log sources, define node types according to the system behaviors involved, including processes, files, networks, node attributes, etc., abstract the interactions between entities as edges, and construct a tracing graph ,in is the node set of the provenance graph, is the edge set of the provenance graph.

[0063] (1-2) Laplace matrix construction:

[0064] (1-2-1) Use the Word2Vec model to generate corresponding feature vectors for each node in the traceability graph: Based on the node attributes (such as process name, file path, network IP address, etc.), use the Word2Vec model to generate low-dimensional, dense feature vectors for the nodes. .

[0065] (1-2-2) Determine the edge weight based on the similarity of node attribute features and topological structure association similarity in the traceability graph: as shown in formula (1)-formula (3), where Representation Node and nodes The similarity of node attribute features between and The nodes are and nodes The characteristic vector of Representation Node The magnitude of the eigenvector of Representation Node The magnitude of the eigenvector of Representation Node and nodes The topological structure association similarity between is the maximum number of hops in the time window, Indicates The weight of the hop neighbor (customized, for example, the weight of the 1st hop neighbor is 0.5, the weight of the 2nd hop neighbor is 0.3, the weight of the 3rd hop neighbor is 0.2, etc.), Representation Node and nodes No. The sum of the number of hop neighbors, is the first The sum of the number of hop neighbors, Representation Node and nodes The edge weights between is the first weight adjustment parameter, is the second weight adjustment parameter and satisfies .

[0066] (1)

[0067] (2)

[0068] (3)

[0069] (1-2-3) Construct a weight matrix based on the edge connection relationship between any two nodes in the traceability graph: For any two nodes in the traceability graph, if the edge connection relationship between the two nodes is edge-connected, then the weight between the two nodes in the weight matrix is ​​taken as the edge weight ; If the edge connection relationship between two nodes is disconnected, the weight between the two nodes in the weight matrix is ​​taken as 0.

[0070] (1-2-4) Calculate the node degree matrix based on the weight matrix, and take the node degree matrix minus the weight matrix as the Laplace matrix, that is, Since the traceability graph is a directed graph, the out-degree of the directed graph is considered when calculating the node degree matrix in this embodiment: just add the weight value of each row in the weight matrix to the diagonal elements of this row, that is, .

[0071] (1-3) Solve the eigenvector of the denoised node: When using Laplace regularization for denoising, construct a convex quadratic optimization problem as shown in formula (4), and then obtain the node after removing the neighbor noise by solving the linear system. The solution calculation method is formula (5) and formula (6). After removing the neighbor noise, the topological structure of the traceability graph is retained.

[0072] (4)

[0073] (5)

[0074] (6)

[0075] In the formula, is the feature vector of the node after removing the neighbor noise in the denoised traceability graph (i.e. the feature vector of the node after denoising), Represents the feature vector of the node in the traceability graph (i.e., the feature vector of the node before denoising), is the regularization parameter, Represents the feature vector of the node after removing neighbor noise The transpose of is the Laplace matrix, is the identity matrix.

[0076] (2) A breadth-first random walk strategy is adopted to traverse the walk path starting from each node in the denoised traceability graph. An unsupervised learning algorithm based on a neural network is used to learn the walk path and obtain the embedding vector of each node in the denoised traceability graph.

[0077] (2-1) Generate random walk sequence: For the denoised traceability graph, a breadth-first random walk strategy is adopted, such as the breadth-first random walk strategy mentioned in the document LTRDetector: Exploring Long-Term Relationship for Advanced PersistentThreats Detection. Starting from each node in the denoised traceability graph, a fixed-length path is traversed along the edges (if the length is not enough, the actual traversal length shall prevail). The walk path is determined according to the transition probability calculation method shown in formula (7), the local topological equivalent features of the network are captured, the node context information is mined, the walk path is obtained, and the nodes in the walk path are taken in order to form a node sequence.

[0078] (7)

[0079] in, Represents a slave node Transfer to Node The probability of For Node The number of outgoing edges, Representation Node With Node The edge between represents the edge set in the provenance graph, represents the first nodes, represents the first nodes.

[0080] (2-2) Generate node embedding vector: After random walk, each node in the denoised traceability graph obtains a corresponding walk path, and the feature vectors of the nodes after removing the neighbor noise in the walk path are combined in order to form a node sequence. Then, the Skip-Gram algorithm is used to learn the sampled node sequence to obtain the node embedding vector .

[0081] (3) Obtain a neighborhood reconstruction model based on an encoder and a decoder, input the node's embedding vector into the neighborhood reconstruction model, calculate the node attribute reconstruction loss, edge distribution reconstruction loss, and neighbor distribution reconstruction loss of each node based on the output of the neighborhood reconstruction model; combine the node attribute reconstruction loss, edge distribution reconstruction loss, and neighbor distribution reconstruction loss to obtain the total reconstruction loss of the node, and update and optimize the neighborhood reconstruction model based on the total reconstruction loss. This embodiment uses benign system log data to train the parameters in the neighborhood reconstruction model, and uses the trained neighborhood reconstruction model for attack detection.

[0082] (3-1) Obtain the output of the neighborhood reconstruction model: Figure 2 As shown, the encoder embeds the node’s vector Random Linear Projection Encoding into Dense Low-Dimensional Representation The decoder reconstructs the 1-hop neighborhood information of the node, including its own attributes, the distribution of edges, and the distribution of neighbor features. The decoder uses three multilayer perceptrons (MLPs) to process the dense low-dimensional representation of the encoder output. , including node attribute multilayer perceptron, edge distribution multilayer perceptron and neighbor distribution multilayer perceptron, among which the node attribute multilayer perceptron processes dense low-dimensional representation , get the embedding vector of the reconstructed node ; Edge-distributed multilayer perceptrons for dense low-dimensional representation , get the node The mean of the features after reconstruction of all original edges and nodes The covariance matrix of all original edges after reconstruction ; Neighborhood distribution multilayer perceptron for dense low-dimensional representation , get the node The feature mean of the reconstructed neighbor nodes and nodes The reconstructed eigenvector covariance matrix of neighboring nodes .

[0083] (3-2) Calculate the node attribute reconstruction loss, edge distribution reconstruction loss and neighbor distribution reconstruction loss for each node.

[0084] (3-2-1) Calculate the node attribute reconstruction loss as shown in formula (8):

[0085] (8)

[0086] In the formula, For Node The node attribute reconstruction loss is is a distance function (such as L2 distance function), For Node The embedding vector of For Node The reconstructed embedding vector.

[0087] (3-2-2) The distribution of edges is considered to satisfy the normal distribution. The mean and variance are estimated first, and then after mapping and sampling, the KL divergence is used to calculate the edge type distribution. The edge distribution reconstruction loss is calculated as shown in formula (9)-formula (11):

[0088] (9)

[0089] (10)

[0090] (11)

[0091] In the formula, For Node The feature mean of all original edges, Representation Node The total number of edges, Representation Node With Node The feature vectors of the edges between For Node The set of neighbor nodes of For Node The covariance matrix of all original edges, express The transpose of For Node The edge distribution reconstruction loss, represents the KL divergence, Refers to satisfying the mean The variance is The normal distribution of Refers to satisfying the mean The variance is The normal distribution of For Node The feature mean of all original edges after reconstruction, For Node The covariance matrix of all original edges after reconstruction. The edge feature vector is obtained by one-hot encoding according to the edge type.

[0092] (3-2-3) The neighbor features are regarded as samples that satisfy the normal distribution. The mean and covariance matrix are estimated first, and then after mapping and sampling, the KL divergence is used to calculate the neighbor feature distribution. The neighbor distribution reconstruction loss (12)-formula (14) is shown as:

[0093] (12)

[0094] (13)

[0095] (14)

[0096] In the formula, For Node The feature mean of the neighbor nodes, Representation Node The total number of neighbor nodes, For Node The embedding vector of For Node The eigenvector covariance matrix of the neighbor nodes, for The transpose of For Node The feature mean of the reconstructed neighbor nodes, For Node The reconstructed eigenvector covariance matrix of neighboring nodes, Refers to satisfying the mean The variance is The normal distribution of Refers to satisfying the mean The variance is The normal distribution of For Node The neighbor distribution reconstruction loss.

[0097] (3-3) The total reconstruction loss of the calculation node is shown in formula (15):

[0098] (15)

[0099] In the formula, For Node The total reconstruction loss is is the first weight hyperparameter, is the second weight hyperparameter, is the third weight hyperparameter. This embodiment supports focusing on adjusting hyperparameters according to different abnormal types. , , , if you focus on context anomaly detection, increase the first weight hyperparameter ; Focus on context anomaly detection, then increase the second weight hyperparameter ; Focus on joint anomaly detection, then increase the third weight hyperparameter .

[0100] (3-4) Model training: Based on the calculated total reconstruction loss , by minimizing the loss value , optimize the parameters in the neighborhood reconstruction model, and the parameter updating method, such as back propagation updating, etc., is not limited in this embodiment.

[0101] (4) Attack detection: The acquired system log data to be detected is input into the updated and optimized neighborhood reconstruction model. The total reconstruction loss corresponding to the system log data to be detected is calculated according to the output of the neighborhood reconstruction model, as shown in Formula (8) to Formula (15). It will not be elaborated here. If the total reconstruction loss corresponding to the system log data to be detected exceeds the abnormal threshold, it is judged that the system log data to be detected has an APT network attack; otherwise, the system log data to be detected has no APT network attack.

[0102] It should be noted that in the inference application, after the neighborhood reconstruction model training is completed, step (4) can be repeated for detection without executing steps (1) to (4) in sequence.

[0103] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0104] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the invention. It should be pointed out that, for ordinary technicians in this field, several modifications and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the attached claims.

Claims

1. A method for detecting APT attacks based on random walk and neighborhood reconstruction, characterized in that: The APT attack detection method based on random walk and neighborhood reconstruction includes: Obtain benign system log data and construct a traceability graph. Based on the traceability graph, construct a Laplace matrix and use Laplace regularization to remove neighbor noise of nodes in the traceability graph to obtain a denoised traceability graph. A breadth-first random walk strategy is adopted to traverse the walk path starting from each node in the denoised traceability graph, and an unsupervised learning algorithm based on a neural network is used to learn the walk path to obtain the embedding vector of each node in the denoised traceability graph. Obtain a neighborhood reconstruction model based on an encoder and a decoder, input the node's embedding vector into the neighborhood reconstruction model, and calculate the node attribute reconstruction loss, edge distribution reconstruction loss, and neighbor distribution reconstruction loss of each node according to the output of the neighborhood reconstruction model; Combine the node attribute reconstruction loss, edge distribution reconstruction loss and neighbor distribution reconstruction loss to get the total reconstruction loss of the node, and update the optimized neighborhood reconstruction model based on the total reconstruction loss; Input the acquired system log data to be detected into the updated and optimized neighborhood reconstruction model, and calculate the total reconstruction loss corresponding to the system log data to be detected according to the output of the neighborhood reconstruction model. If the total reconstruction loss corresponding to the system log data to be detected exceeds the abnormal threshold, it is judged that the system log data to be detected has an APT network attack; otherwise, the system log data to be detected does not have an APT network attack; The step of calculating the node attribute reconstruction loss, the edge distribution reconstruction loss and the neighbor distribution reconstruction loss according to the output of the neighborhood reconstruction model includes: The node attribute reconstruction loss is calculated as follows: ; In the formula, For Node The node attribute reconstruction loss is is the distance function, For Node The embedding vector of Nodes output by the neighborhood reconstruction model The reconstructed embedding vector; The edge distribution reconstruction loss is calculated as follows: ; ; ; In the formula, For Node The feature mean of all original edges, Representation Node The total number of edges, Representation Node With Node The feature vector of the edge between For Node The set of neighbor nodes of For Node The feature covariance matrix of all original edges, express The transpose of For Node The edge distribution reconstruction loss, represents the KL divergence, Refers to satisfying the mean The variance is The normal distribution of Refers to satisfying the mean The variance is The normal distribution of Nodes output by the neighborhood reconstruction model The feature mean of all original edges after reconstruction, Nodes output by the neighborhood reconstruction model The feature covariance matrix after reconstruction of all original edges; The neighbor distribution reconstruction loss is calculated as follows: ; ; ; In the formula, For Node The feature mean of the neighbor nodes, Representation Node The total number of neighbor nodes, For Node The embedding vector of For Node The feature covariance matrix of the neighbor nodes of for The transpose of Nodes output by the neighborhood reconstruction model The feature mean of the reconstructed neighbor nodes, Nodes output by the neighborhood reconstruction model The feature covariance matrix of the reconstructed neighbor nodes, Refers to satisfying the mean The variance is The normal distribution of Refers to satisfying the mean The variance is The normal distribution of For Node The neighbor distribution reconstruction loss.

2. The APT attack detection method based on random walk and neighborhood reconstruction according to claim 1 is characterized in that: The constructing of the Laplace matrix based on the traceability graph includes: The Word2Vec model is used to generate corresponding feature vectors for each node in the traceability graph; Determine edge weights based on the similarity of node attribute features and topological structure association similarity in the traceability graph; Construct a weight matrix based on the edge connection relationship between any two nodes in the traceability graph; Calculate the node degree matrix based on the weight matrix; The Laplacian matrix is ​​obtained by subtracting the node degree matrix from the weight matrix.

3. The APT attack detection method based on random walk and neighborhood reconstruction according to claim 2 is characterized in that: The determining of edge weights based on the similarity of node attribute features and topological structure association similarity in the traceability graph includes: ; ; ; In the formula, Representation Node and nodes The similarity of node attribute features between Representation Node The characteristic vector of Representation Node The characteristic vector of Representation Node The magnitude of the eigenvector of Representation Node The magnitude of the eigenvector of Representation Node and nodes The topological structure association similarity between is the maximum number of hops in the time window, Indicates The weight of the hopping neighbor, Representation Node and nodes No. The sum of the number of hop neighbors, is the first The sum of the number of hop neighbors, Representation Node and nodes The edge weights between is the first weight adjustment parameter, is the second weight adjustment parameter, and .

4. The APT attack detection method based on random walk and neighborhood reconstruction according to claim 2 is characterized in that: The weight matrix is ​​constructed according to the edge connection relationship between any two nodes in the traceability graph, including: For any two nodes in the traceability graph, if the edge connection relationship between the two nodes is edge-connected, the weight between the two nodes in the weight matrix is ​​taken as the edge weight; if the edge connection relationship between the two nodes is disconnected, the weight between the two nodes in the weight matrix is ​​taken as 0.

5. The APT attack detection method based on random walk and neighborhood reconstruction according to claim 1 is characterized in that: The method of using Laplace regularization to remove neighbor noise of nodes in the provenance graph to obtain a denoised provenance graph includes: The convex quadratic optimization problem is constructed as follows: ; Solve the convex quadratic optimization problem and obtain the node after removing the neighbor noise: ; ; In the formula, is the feature vector of the node in the denoised traceability graph after removing the neighbor noise, represents the feature vector of a node in the provenance graph, is the regularization parameter, Represents the feature vector of the node after removing neighbor noise The transpose of is the Laplace matrix, is the identity matrix.

6. The APT attack detection method based on random walk and neighborhood reconstruction according to claim 1 is characterized in that: The transition probability of the breadth-first random walk strategy is calculated as follows: ; In the formula, Represents a slave node Transfer to Node The probability of For Node The number of outgoing edges, Representation Node With Node The edge between Represents the edge set in the provenance graph.

7. The APT attack detection method based on random walk and neighborhood reconstruction according to claim 1 is characterized in that: The combined node attribute reconstruction loss, edge distribution reconstruction loss and neighbor distribution reconstruction loss are used to obtain the total reconstruction loss, including: ; In the formula, For Node The total reconstruction loss is is the first weight hyperparameter, is the second weight hyperparameter, is the third weight hyperparameter.

Citation Information

Patent Citations

  • Threat detection method and system based on traceability graph and self-supervised learning

    CN118094122A

  • APT attack detection method fusing traceability graph node semantics and neighborhood features

    CN118264474A