A General Complex Network Attack Inference Method Based on Bayesian ATT&CK Network
Through the Bayesian ATT&CK network method, combining expert knowledge and real data sets, a Bayesian network model for complex network attacks is constructed, which solves the problem of lack of data sets and sequence modeling in the existing technology, and accurately inference and prediction of complex network attacks is achieved.
Patent Information
- Application Number
- CN202510330671.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-20
AI Technical Summary
The existing complex cyberattack inference methods lack a large number of real and credible data sets, lack of research on modeling complex cyberattack sequences, and lack of combination of expert knowledge and objective data.
A general complex network attack inference method based on Bayesian ATT&CK network is adopted to construct tactical timing logic through expert knowledge, establish a technology dependency network, and use real network attack data sets to optimize the network structure to build Bayesian ATT&CK network for inference.
It realizes logical coherent modeling and accurate inference of complex network attack sequences, improves attack pattern recognition and prediction capabilities, and has good adaptability and migration.
Smart Images

Figure CN119854045B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a general complex network attack inference method based on a Bayesian ATT&CK network. Background Art
[0002] Advanced Persistent Threat (APT, complex network attack) has posed a serious threat to global network security. Therefore, the defense against complex network attacks has attracted more and more attention from network security personnel and has gradually become a research hotspot.
[0003] The use of advanced network attack techniques and complex multi-step attacks pose challenges to the defense work. Currently, more and more research work models complex network attacks at the Tactics, Techniques, and Procedures (TTP) level of attack behavior, avoiding low-level features such as intrusion indicators, network, and host artifacts that are easily bypassed, and improving the robustness of the detection model. However, there are still two deficiencies in attack inference based on TTP: First, the attack event reports list the tactics and techniques used in the attack activities, but very few reports list the sequence information between the techniques, and the sequence information of the techniques is the key to attack prediction and attack investigation; Second, the analysis of the dependency relationship between the techniques is insufficient, restricting the inference ability for attack patterns.
[0004] Among the previous complex network attack inference methods, an intrusion alert correlation method based on a hidden Markov model proposed by H. A. Kholidy et al. although uses the original alert data, but cannot represent real APT attack behaviors; Seungoh Choi proposed an attack sequence modeling based on a hidden Markov model, but lacks the construction of a dataset for a real model and uses overly strong temporal assumptions; Antonia Nisioti et al. proposed a data-driven decision support framework named DISCLOSE that models only based on expert knowledge rather than objective data, and the rationality of the model lacks verification by real data; the BAN model proposed by Youngjoon Kim et al. is biased towards predicting the next attack and defense behaviors and does not achieve modeling of the complete attack sequence. The current research all has certain defects to varying degrees: lack of a large number of real and reliable datasets, lack of research on modeling complex network attack sequences, and lack of the combination of expert knowledge and objective data. Summary of the Invention
[0005] The object of the present invention is to provide a general complex network attack inference method based on a Bayesian ATT&CK network, which solves the problems existing in the prior art of lacking a large number of real and reliable datasets, lacking research on modeling complex network attack sequences, and lacking the combination of expert knowledge and objective data when performing complex network attack inference.
[0006] To achieve the above object, the present invention provides a general complex network attack inference method based on a Bayesian ATT&CK network, including the following steps:
[0007] Step 1, Tactical temporal logic modeling based on expert knowledge; Using the Cyber Kill Chain and empirical rules as the research basis, perform temporal logic modeling on the tactics in the ATT&CK framework to ensure that the generated tactical sequence is logically coherent and reflects the behavior patterns of real complex network attacks;
[0008] Step 2, Construction of a technology dependency network based on tactical temporal logic; The technology dependency network represents the dependency relationship between attack technologies through a weighted directed acyclic graph (DAG). Nodes represent technologies, edges represent the dependencies between technologies, and the dependency weights between technologies are evenly divided to construct a technology dependency network;
[0009] Step 3, Optimization of the technology dependency network structure based on technology co-occurrence; The structure optimization of the technology dependency network is based on the technology co-occurrence relationship in the real network attack dataset. Use the hill climbing algorithm combined with the Bayesian Information Criterion (BIC) scoring function to optimize the network structure, so that the technology dependency network can more accurately model the dependency relationship between technologies;
[0010] Step 4, Bayesian ATT&CK network modeling based on the technology dependency network and real dataset; Based on the technology dependency network and the anonymized dataset from real network attack events, use the maximum likelihood estimation method to learn the technology co-occurrence relationship in the dataset, and model the network structure and optimize the parameters according to the technology co-occurrence relationship, and thus construct a Bayesian network to obtain a Bayesian ATT&CK network that can reflect the dependency relationship between attack technologies;
[0011] Step 5, Inference of complex network attacks based on variational inference; Use the approximate inference method based on variational inference to infer the Bayesian ATT&CK network. By adjusting the parameters of the approximate distribution, make the approximate posterior distribution close to the true posterior distribution, and realize the inference of the attack technology that will appear next in complex network attacks.
[0012] Preferably, the tactical temporal logic in Step 1 is extracted from two aspects: on the one hand, it is extracted based on the correspondence between the ATT&CK framework and the kill chain model, and on the other hand, it is extracted based on the attack process rules; The kill chain model includes the following stages: reconnaissance, weaponization, delivery, external exploitation, installation, command and control, operation, impact.
[0013] Preferably, the specific content of Step 2 is: Let S be the set of all tactics, T be the set of all attack technologies, and define a mapping , where Denote all subsets of the technology set T; for any tactic S, through mapping, the set of technologies associated with tactic S can be obtained. When tactic S is executed, all involved technologies are in set T; if tactic S2 depends on tactic S1, then the technology set T2 corresponding to tactic S2 also depends on the technology set T1 corresponding to tactic S1. The dependency weights between technologies adopt an equalization method, and the calculation formula for the dependency weights between any two technologies is as follows:
[0014] ;
[0015] In the formula, represents the dependency weight from technology a to technology b; represents the number of tactical stages where technology a is located; represents the number of tactical stages containing technology b that the tactical stage i where technology a is located can transfer to; represents all the tactical stages that the tactical stage i where technology a is located can transfer to; represents the total number of technologies contained in tactical stage j.
[0016] Preferably, the process of step 3 is as follows: Establish a technology dependency whitelist based on the dependency relationships in the technology dependency network obtained in step 2. On the basis of the technology dependency whitelist, learn the technology co-occurrence relationships in attack events, and use the hill-climbing algorithm to optimize the network structure in combination with the Bayesian Information Criterion (BIC) scoring function, so that the model can better fit the data and have better generalization performance. The principle of the BIC scoring function is based on the Bayesian information criterion, which comprehensively considers the goodness of fit of the model and the model complexity to avoid overfitting. The calculation expression of the BIC scoring function is as follows:
[0017] ;
[0018] In the formula, represents the network structure, represents the number of model parameters, represents the number of dataset samples, represents the likelihood function, defined as the joint probability of observing technology , and the expression is as follows:
[0019] ;
[0020] In the formula, the parameter is the probability parameter in the technology dependency network, represents the sub-technology node in the technology dependency network.
[0021] Preferably, the process of step 4 is as follows:
[0022] S41. Based on the technical dependency network in step 3 and the dataset from real network attack events, use the maximum likelihood estimation method (MLE) to model the Bayesian network and calculate the joint probability distribution. The expression is as follows:
[0023] ;
[0024] In the formula, represents the sub - technical node in the technical dependency network, represents the parent - technical node in the technical dependency network.
[0025] S42. Through the maximum likelihood estimation method, learn the co - occurrence relationship of technologies in the dataset and optimize the parameters. The expression for optimizing the parameters is as follows:
[0026] ;
[0027] In the formula, is the parameter, is the probability of the technology under the condition of the given parent node;
[0028] S43. Calculate the estimated value of the parameter to obtain the Bayesian ATT&CK network. The expression is as follows:
[0029] ;
[0030] In the formula, represents the dataset used for parameter learning, G represents the technical dependency network, represents the parameter based on maximum likelihood estimation, represents parameter maximization, represents the parameter in the technical dependency network.
[0031] Preferably, the process of step 5 is as follows:
[0032] S51. Use the approximate inference method based on variational inference to infer the Bayesian network and maximize the variational lower bound , and the expression is as follows:
[0033] ;
[0034] In the formula, represents the expectation with respect to expectation, represents the joint distribution, represents the unobserved technology, is the approximate distribution;
[0035] S52. Calculate the conditional probability of the next technology through the Bayesian network. The calculation expression is as follows:
[0036] ;
[0037] In the formula, represents the probability of the technology node appearing under the condition that the state is determined at the technology node ; represents the probability of the technology node appearing; represents the probability of the technology node appearing.
[0038] Therefore, the present invention adopts the above-mentioned general complex network attack inference method based on the Bayesian ATT&CK network. This method introduces two types of expert knowledge, the kill chain model and empirical rules, into the ATT&CK framework to construct the tactical temporal logic, ensuring that the generated attack sequences are logically coherent and can reflect the typical behavior patterns of complex network attacks in the real world. At the same time, a weighted directed acyclic graph (DAG) is used to represent the dependency relationship between attack techniques. The guidance of tactical transfer in the complex network attack process based on expert knowledge is extended to the guidance of technique transfer, and a technique dependency network reflecting the dependency relationship between techniques is constructed. Based on the technique co-occurrence relationship in the anonymized dataset of real network attack events, the hill climbing algorithm and the Bayesian Information Criterion (BIC) scoring function are used to further optimize the structure of the technique dependency network, making it more accurately reflect the dependency relationship between attack techniques. By making full use of the technique dependency network and the technique co-occurrence relationship in the real network attack dataset, structure learning and parameter learning are carried out on the Bayesian ATT&CK network, effectively ensuring the logical coherence and practical applicability of the inference results. Moreover, the inference method proposed by the present invention is independent of specific threat detection systems and has good adaptability and transferability, enabling it to be flexibly applied in a multi-network environment.
[0039] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a step diagram of a general complex network attack inference method based on the Bayesian ATT&CK network of the present invention;
[0041] Figure 2 is a flowchart of a general complex network attack inference method based on the Bayesian ATT&CK network of the present invention;
[0042] Figure 3 is a schematic diagram of a technique dependency network based on tactical temporal logic according to an embodiment of the present invention;
[0043] Figure 4 is a flowchart of Bayesian ATT&CK inference network modeling according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] The following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0045] Please refer to Figures 1-4 , a general complex network attack inference method based on the Bayesian ATT&CK network, comprising the following steps:
[0046] Step 1, Tactical temporal logic modeling based on expert knowledge; Using the Cyber Kill Chain and empirical rules as the research basis, perform temporal logic modeling on the tactics in the ATT&CK framework to ensure that the generated tactical sequence is logically coherent and reflects the behavior patterns of real complex network attacks; Among them, the tactical temporal logic is extracted from two aspects: on the one hand, it is extracted based on the correspondence between the ATT&CK framework and the Cyber Kill Chain model, and on the other hand, it is extracted based on the attack process rules; By integrating the tactics in the ATT&CK framework and the tactical temporal relationship in the Cyber Kill Chain, perform tactical temporal logic modeling. The Cyber Kill Chain model includes the following stages: reconnaissance, weaponization, delivery, external exploitation, installation, command and control, action, impact; The correspondence between ATT&CK and the Cyber Kill Chain is shown in Table 1 below
[0047] Table 1 Correspondence between ATT&CK and the Cyber Kill Chain
[0048]
[0049] Among them, external reconnaissance and weaponization correspond to the PRE-ATT&CK part in the ATT&CK model, which is difficult to detect and predict in practice. ATT&CK for enterprise covers the latter five stages of the Cyber Kill Chain. During the modeling process, combine the techniques and procedures in the ATT&CK framework, map the tactics and techniques in each attack stage to the corresponding stages of the Cyber Kill Chain, and generate tactical temporal logic.
[0050] At the same time, by analyzing the information about attack methods in existing security reports and security articles, and mapping this information to the tactics and techniques in the ATT&CK framework, the following rules ensure that the generated attack sequence is logically coherent and can reflect the typical behavior patterns of complex network attacks in the real world:
[0051] Rule 1: , , such that is executed before T;
[0052] Rule 2: , such that is executed before T;
[0053] Rule 3: If T belongs to a continuous technology, it does not need to be repeatedly executed on the same host.
[0054] Step 2: Construction of a technology dependency network based on tactical temporal logic; the technology dependency network represents the dependency relationship between attack technologies through a weighted directed acyclic graph DAG, where nodes represent technologies, edges represent the dependencies between technologies, and the dependency weights between technologies are evenly divided to construct a technology dependency network; the specific content is as follows: Let S be the set of all tactics, and T be the set of all attack technologies. Define a mapping , where represents all subsets of the technology set T; for any tactic S, the set of technologies associated with tactic S can be obtained through the mapping. When tactic S is executed, the technologies involved are all in the T set; if tactic S2 depends on tactic S1, then the technology set T2 corresponding to tactic S2 also depends on the technology set T1 corresponding to tactic S1. The dependency weights between technologies are evenly divided. The calculation formula for the dependency weights between any two technologies is as follows:
[0055] ;
[0056] In the formula, represents the dependency weight from technology a to technology b; represents the number of tactical stages where technology a is located; represents the number of tactical stages containing technology b that can be transferred from the tactical stage i where technology a is located; represents the total number of tactical stages that can be transferred from the tactical stage i where technology a is located; represents the total number of technologies contained in the tactical stage j.
[0057] Step 3: Optimization of the technology dependence network structure based on technology co-occurrence; the structure optimization of the technology dependence network is based on the technology co-occurrence relationship in the real network attack dataset. The hill-climbing algorithm is used in combination with the Bayesian Information Criterion (BIC) scoring function to optimize the network structure, so that the technology dependence network can more accurately model the dependence relationship between technologies. The specific process is as follows: establish a technology dependence whitelist based on the dependence relationship in the technology dependence network obtained in Step 2, learn the technology co-occurrence relationship in the attack events on the basis of the technology dependence whitelist, use the hill-climbing algorithm, and combine the BIC scoring function to optimize the network structure, so that the model can better fit the data and have better generalization performance. The principle of the BIC scoring function is based on the Bayesian Information Criterion. It comprehensively considers the goodness of fit of the model and the model complexity to avoid overfitting. The calculation expression of the BIC scoring function is as follows:
[0058] ;
[0059] In the formula, represents the network structure, represents the number of model parameters, represents the number of dataset samples, represents the likelihood function, which is defined as the joint probability of observing the technology , and the expression is as follows:
[0060] ;
[0061] In the formula, the parameters are the probability parameters in the technology dependence network, which describe the probability distribution of the occurrence of each technology node given its parent nodes. For example, if the parent node of a certain technology node is , then the parameters include all possible values. The likelihood function is used to represent the probability of the occurrence of the attack technology given the network parameters. It measures the explanatory ability of the model parameters for the known attack technologies, and the specific form depends on the relationship of the known attack technologies and its model assumptions. In the specific operation, the hill-climbing algorithm starts from the initial network structure and tries to optimize the network structure of the technology dependence network by adding, deleting or reversing edges. The network structure with the highest BIC score is found as the finally obtained technology dependence network structure, which can effectively represent the technology dependence relationship in complex network attacks.
[0062] Step 4: Bayesian ATT&CK network modeling based on the technology dependency network and real dataset; Based on the technology dependency network and the anonymized dataset from real network attack events, use the maximum likelihood estimation method to learn the technology co-occurrence relationships in the dataset, and model the network structure and optimize the parameters according to the technology co-occurrence relationships, thereby constructing a Bayesian network to obtain a Bayesian ATT&CK network that can reflect the dependency relationships between attack techniques; The specific process is as follows:
[0063] S41. Based on the technology dependency network in Step 3 and the dataset from real network attack events, use the maximum likelihood estimation method (MLE) to model the Bayesian network and calculate the joint probability distribution. The expression is as follows:
[0064] ;
[0065] In the formula, represents the sub-technology node in the technology dependency network, represents the parent technology node in the technology dependency network;
[0066] Through the maximum likelihood estimation method, learn the technology co-occurrence relationships in the dataset and optimize the parameters. The optimized Bayesian network can better reflect the actual APT attack pattern. The goal of parameter learning is to maximize the conditional probability of the observed data in the network model, thereby obtaining the conditional probability of each node technology.
[0067] S42. Through the maximum likelihood estimation method, learn the technology co-occurrence relationships in the dataset and optimize the parameters. The expression for parameter optimization is as follows:
[0068] ;
[0069] In the formula, is the parameter, is the probability of the technology given the parent node;
[0070] S43. Calculate the estimated value of the parameter to obtain the Bayesian ATT&CK network. The expression is as follows:
[0071] ;
[0072] In the formula, represents the dataset used for parameter learning, G represents the technology dependency network, represents the parameter based on the maximum likelihood estimation, represents the parameter maximization, represents the parameter in the technology dependency network. Based on this, perform parameter learning of the Bayesian network to obtain the best Bayesian ATT&CK inference network.
[0073] Step 5: Inference of complex network attacks based on variational inference; Use the approximate inference method based on variational inference to infer the Bayesian ATT&CK network. By adjusting the parameters of the approximate distribution, make the approximate posterior distribution close to the true posterior distribution, and realize the inference of the attack techniques that will appear in the next step in complex network attacks. In this step, use the approximate inference method based on variational inference to infer the Bayesian network and infer the attack techniques that may appear in the next step of APT attacks. Variational inference approximates the posterior probability distribution as a simpler distribution, and then maximizes or approximately maximizes a certain similarity measure between the two distributions to find the best approximation. The core idea is to adjust the parameters of the approximate distribution so that the approximate posterior distribution is as close as possible to the true posterior distribution. The specific process is as follows:
[0074] S51. Introduce a parameterized approximate distribution Q to make it possible to approximate the true posterior probability distribution P as much as possible. Use the approximate inference method based on variational inference to infer the Bayesian network and maximize the variational lower bound , and the expression is as follows:
[0075] ;
[0076] In the formula, represents the expectation with respect to expectation, represents the joint distribution, represents the unobserved techniques, is the approximate distribution; The variational inference algorithm optimizes the variational lower bound by iteratively updating the parameters until it converges to a stable approximate distribution. In each iteration, update the parameterized approximate distribution Q to make the variational lower bound continuously increase, so as to gradually approximate the true posterior probability distribution;
[0077] S52. Calculate the conditional probability of the next technique through the Bayesian network, and the calculation expression is as follows:
[0078] ;
[0079] In the formula, represents the probability that the technology node appears under the condition that the state of the technology node is determined, represents the probability that the technology node appears, represents the probability that the technology node appears. This formula represents the probability of inferring the next attack technique given the previous attack techniques. By inferring the several techniques with the highest probabilities, the attacker's next actions can be predicted, and finally the inference of complex network attacks can be realized.
[0080] Therefore, the present invention adopts the above-mentioned general complex network attack inference method based on the Bayesian ATT&CK network, which uses the kill chain and empirical knowledge as the research basis, conducts a temporal logic modeling on the tactics in the ATT&CK framework to ensure that the generated attack sequence is logically coherent and reflects the behavior pattern of real complex network attacks. Based on the tactical temporal logic sequence, the guidance of expert knowledge on tactical transfer is extended to the guidance on technique transfer, and a technique dependence network is constructed. By using the anonymized dataset from real network attack events and leveraging the co-occurrence relationship of techniques in the dataset, the technique dependence network is further optimized. Based on the technique dependence network and the co-occurrence relationship of techniques in the real network attack dataset, the Bayesian ATT&CK network performs structure learning and parameter learning to construct a network model independent of specific threat detection systems, thereby realizing the inference of complex network attacks independent of specific systems.
[0081] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify or equivalently replace the technical solutions of the present invention, and these modifications or equivalent replacements cannot make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A general complex network attack inference method based on Bayesian ATT&CK network, characterized in that: The following steps are involved: Step 1: Modeling the tactical temporal logic based on expert knowledge: Using the kill chain and empirical rules as the research basis, model the temporal logic of the tactics in the ATT&CK framework; Step 2: Construct a technology dependency network based on tactical temporal logic. The technology dependency network uses a weighted directed acyclic graph (DAG) to represent the dependency relationship between attack technologies. Nodes represent technologies, and edges represent the dependency between technologies. The dependency weights between technologies are evenly differentiated to form a technology dependency network. Step 3: Optimize the structure of the technology dependency network based on technology co-occurrence. The structure optimization of the technology dependency network is based on the technology co-occurrence relationship in the real network attack data set, and the network structure is optimized using the hill climbing algorithm combined with the Bayesian Information Criterion (BIC) scoring function. Step 4: Bayesian ATT&CK network modeling based on technology dependency network and real data set; Based on the technology dependency network and anonymized data sets from real network attack events, the maximum likelihood estimation method is used to learn the technology co-occurrence relationship in the data set, and the network structure is modeled and the parameters are optimized based on the technology co-occurrence relationship. Based on this, a Bayesian network is constructed to obtain a Bayesian ATT&CK network that can reflect the dependency relationship between attack technologies. Step 5: Inference of complex network attacks based on variational inference: Use the approximate inference method based on variational inference to infer the Bayesian ATT&CK network. By adjusting the parameters of the approximate distribution, the approximate posterior distribution is made close to the true posterior distribution, so as to infer the next attack technology in the complex network attack.
2. According to claim 1, a general complex network attack inference method based on Bayesian ATT&CK network is characterized in that: The tactical timing logic in step 1 is extracted from two aspects: on the one hand, it is extracted based on the correspondence between the ATT&CK framework and the kill chain model, and on the other hand, it is extracted based on the attack process rules; the kill chain model includes the following stages: reconnaissance, weaponization, delivery, external exploitation, installation, command and control, action, and influence.
3. According to claim 2, a general complex network attack inference method based on Bayesian ATT&CK network is characterized in that: The specific content of step 2 is: Let S be the set of all tactics, T be the set of all attack techniques, and define a mapping ,in Represents all subsets of the technology set T; for any tactic S, the set of technologies associated with tactic S is obtained through mapping. When tactic S is executed, the technologies involved are all in the T set; if tactic S2 depends on tactic S1, then the technology set T2 corresponding to tactic S2 also depends on the technology set T1 corresponding to tactic S1. The dependency weights between technologies are averaged and differentiated. The calculation formula for the dependency weights between any two technologies is as follows: ; In the formula, Indicates the dependency weight from technology a to technology b; Indicates the tactical stage number of technology a; The number of tactical stages containing technology b that tactical stage i where technology a is located can transfer to; It represents the number of all tactical stages to which tactical stage i where technology a is located can be transferred; Represents the number of all techniques contained in tactical stage j.
4. According to claim 3, a general complex network attack inference method based on Bayesian ATT&CK network is characterized in that: The process of step 3 is as follows: establish a technology dependency whitelist based on the dependency relationship in the technology dependency network obtained in step 2, learn the technology co-occurrence relationship in the attack event based on the technology dependency whitelist, use the hill climbing algorithm, and combine the Bayesian Information Criterion BIC scoring function to optimize the network structure. The calculation expression of the BIC scoring function is as follows: ; In the formula, Represents the network structure, represents the number of parameters of the model, represents the number of samples in the dataset, represents the likelihood function, defined as the observation technique The joint probability of is expressed as follows: ; In the formula, the parameters is the probability parameter in the technology dependency network, Represents a sub-technology node in the technology dependency network.
5. According to claim 4, a general complex network attack inference method based on Bayesian ATT&CK network is characterized in that: The process for step 4 is as follows: S41. Based on the technology dependency network in step 3 and the data set from real network attack events, the maximum likelihood estimation method MLE is used to model the Bayesian network and calculate the joint probability distribution. The expression is as follows: ; In the formula, Represents a sub-technology node in the technology dependency network, Represents the parent technology node in the technology dependency network; S42. Through the maximum likelihood estimation method, the technical co-occurrence relationship in the data set is learned and the parameters are optimized. The expression for optimizing the parameters is as follows: ; In the formula, As parameters, is the probability of a technology given a parent node; S43. Calculate the estimated values of the parameters and obtain the Bayesian ATT&CK network. The expression is as follows: ; In the formula, represents the parameter learning using the dataset, G represents the technology dependency network, represents the parameters estimated based on maximum likelihood, represents parameter maximization, Represents the parameters in the technology dependency network.
6. According to claim 5, a general complex network attack inference method based on Bayesian ATT&CK network is characterized in that: The process for step 5 is as follows: S51. Use the approximate inference method based on variational inference to infer the Bayesian network and maximize the variational lower bound , the expression is as follows: ; In the formula, Indicates about expect, represents the joint distribution, represents unobserved technology, is an approximate distribution; S52. Calculate the conditional probability of the next step of technology through the Bayesian network. The calculation expression is as follows: ; In the formula, Indicates at technology node Under the condition of determining the state, the technology node The probability of occurrence, Indicates technology node The probability of occurrence, Indicates technology node Probability of occurrence.
Citation Information
Patent Citations
Novel method and system for constructing attack graph of power system based on ATT and CK
CN117834169A
Network attack link tracking and threat situation reasoning method based on knowledge graph
CN119544327A