Network attack scene reconstruction method based on equipment fingerprint in 5G private network scene

By adopting a network attack scenario reconstruction method based on device fingerprint in 5G private network, the problem of IP address changes caused by network switching is solved, and the attack activity is fully tracked, which improves analysis accuracy and reduces the burden on analysts.

CN119922552AActive Publication Date: 2025-05-02POWERCHINA BEIJING ENG CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510063531.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-02
Estimated Expiration
2045-01-15

AI Technical Summary

Technical Problem

In 5G private networks, network switching causes IP addresses to change, and the IP addresses cannot be associated with infected devices, resulting in the inability to track complete attack activities, increasing the workload of analysts and the deviation of attack analysis.

Method used

The network attack scenario reconstruction method based on device fingerprint is adopted. By capturing the traffic that triggers the alarm, the traffic direction and length in the network flow are extracted as temporary fingerprints, the temporary fingerprint is written to the fingerprint database, the temporary fingerprint with similar time is extracted, the twin IP is determined, and the twin IP list of the attacked IP address is output, and the attack scenario is reconstructed.

Benefits of technology

It effectively reduces the impact of IP switching on attack scenario construction, improves analysis accuracy, reduces the burden on analysts, and has high versatility and less computing and storage overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922552A_ABST
    Figure CN119922552A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of digital information transmission, in particular to a network attack scene reconstruction method based on equipment fingerprints in a 5G private network scene, which comprises the following steps of: capturing traffic triggering an alarm, storing the traffic as a pcap packet, and generating a data packet list corresponding to each IP address and the traffic; t; a source address, a destination address, a source port, a destination port and a timestamp gt; the quintuple marks the network flow; extracting the direction and length of the flow in the network flow as temporary fingerprints; according to the method, temporary fingerprints with similar time are extracted from a fingerprint database, and twin IPs are judged, so that a twin IP list of an attacked IP address is output, related attack fragments are searched according to the twin IP list, and a plurality of attack fragments are associated to reconstruct an attack scene. According to the method, on the premise of not depending on the access authority of the control plane network element, a plurality of attack fragments are associated, a complete attack scene is restored, and analysts are helped to carry out analysis activities such as attack classification and attack prediction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital information transmission, and in particular to a method for reconstructing a network attack scenario based on device fingerprints in a 5G private network scenario. Background Art

[0002] Multi-step attacks, that is, attackers deploy multiple related attack steps to achieve a given goal. APT is a typical type of multi-step attack. Such complex attacks require the attack detection system to associate multiple related attack steps and reconstruct attack activities, thereby supporting the understanding of the attack target and attack process, and further formulating targeted defense measures, which is also called Attack Scenario Reconstruction.

[0003] The security of 5G private networks is crucial to social production. Therefore, in the face of complex attacks, reconstructing attack scenarios is also a problem that must be solved in 5G private network threat detection. 5G private network threat detection generally deploys an intrusion detection system in the network through a threat detection model, detects attack behaviors in mobile network traffic, generates alarms and sends them to the security incident analysis center, aggregates and verifies alarms, and then associates multiple related alarms on this basis to restore the attack scenario, thereby supporting the determination of attack types and further attack analysis.

[0004] Existing general attack scenario reconstruction technologies are generally based on IP address-based attack scenario reconstruction technologies and IP address-based and Dynamic Host Configuration Protocol (DHCP) log-based attack scenario reconstruction technologies. However, in 5G private networks, network switching will cause changes in IP addresses, and network switching may be triggered by multiple scenarios, such as a mobile device temporarily leaving the network coverage, a device restart, and a switch between Long Term Evolution (LTE) and 5G in a mobile network that does not support the N26 interface (the interface between AMF (Access and Mobility Management Function) and Mobility Management Entity (MME)). If the IP address of an infected device changes, security analysts cannot associate the IP address with the infected device, and therefore cannot track the complete attack activity associated with a specific device.

[0005] In 5G private networks, operators can also associate the IP address of the user entity (User Equipment, UE) with the unique identifier of the UE, namely the subscription permanent identifier (SUPI) or the user hidden identifier (SUCI) by mining the logs of the core network elements. However, considering the construction cost, the 5G private network control plane is a more widely used deployment mode. In this type of deployment mode, 5G private network operators do not have sufficient authority to access the logs and API interfaces of the control plane network elements, so the UE identifier is invisible to the 5G private network. Therefore, 5G operators cannot associate the IP address with the unique identifier of the mobile device through log mining.

[0006] In summary, the above two methods cannot restore the complete attack scenario. This poses two challenges to attack detection. 1) Increased workload. Analysts need to deal with more attack activities. For analysts, incomplete attack activities often mean that there may be missed alarms, which requires additional verification work. 2) Bias in attack analysis. Since attack analysis usually relies on time series alarm sequences, incomplete sequences may lead to biased analysis results. Summary of the invention

[0007] In order to solve the association problem caused by the fragmentation of attack activities, the present invention provides a network attack scenario reconstruction method based on device fingerprints in a 5G private network scenario.

[0008] The present invention provides a network attack scenario reconstruction method based on device fingerprint in a 5G private network scenario, which adopts the following technical solution:

[0009] A network attack scenario reconstruction method based on device fingerprint in a 5G private network scenario includes the following steps:

[0010] Capture the traffic that triggers the alarm and store it as a pcap packet, generating a list of packets corresponding to each IP address and traffic;

[0011] The network flow is marked by the five-tuple of <source address, destination address, source port, destination port, timestamp>;

[0012] Extract the direction and length of traffic in the network flow as a temporary fingerprint, and write the temporary fingerprint into the fingerprint database;

[0013] Extract temporary fingerprints with similar time from the fingerprint database, determine the twin IP, and output the twin IP list of the attacked IP address;

[0014] According to the twin IP list, find related attack fragments, associate multiple attack fragments, and reconstruct the attack scenario.

[0015] In a specific feasible implementation plan, before capturing the traffic that triggers the alarm, the network traffic is obtained through a network intrusion detection device, potential attack behaviors in the network traffic are detected, alarms and monitoring logs are generated, and the alarms and monitoring logs are written into an alarm database;

[0016] Correlate the infected IP with the alert to get the attack fragment.

[0017] In a specific feasible implementation scheme, when extracting the direction and length of traffic in a network flow, for each IP address, the busiest K network flows are screened; and the direction and length of traffic in the K network flows are extracted.

[0018] In a specific implementation scheme, the network characteristics of the flow k of a single network flow are expressed as f k =<±length i >, where k = 1, 2, ..., K, length i It represents the length of the i-th flow in the network flow, and the sign indicates the direction, where communication from UE to dedicated service is positive and communication from dedicated service to user is negative.

[0019] In a specific feasible implementation, when extracting the direction and length of traffic in the network flow, the traffic captured in the time window after the rising edge and the traffic captured in the time window before the falling edge are filtered;

[0020] Only the network features of the traffic in the time window after the rising edge and before the falling edge are extracted as the temporary fingerprint of the device.

[0021] In a specific implementation scheme, the timestamp when the IP appears in the network is the rising edge, denoted as t0; the timestamp when the IP disappears is the falling edge, denoted as t m

[0022] After filtering the traffic captured in the time window after the rising edge and the traffic captured in the time window before the falling edge, if the traffic does not belong to these two time windows and the timestamp is earlier than t0 or later than t m , then t0 or t m Updated to the timestamp of the traffic.

[0023] In a specific implementation scheme, before extracting temporary fingerprints with similar time from the fingerprint database, model training is performed:

[0024] Using Triplet network;

[0025] Take anchor points, positive examples and negative examples as input samples and embed the input samples into the vector space;

[0026] Calculate the Euler distance between (anchor point, positive example) and (anchor point, negative example), and use the Euler distance as a measure of temporary fingerprint similarity;

[0027] The training goal is to make the distance between the same category as small as possible and the distance between different categories as large as possible.

[0028] In a specific feasible implementation scheme, the output result of the Triplet network is optimized by a loss function L, and the formula of the loss function L is: L=J(F(a, p), 0)+J(F(a, n), 1).

[0029] In a specific feasible implementation scheme, outputting a twin IP list of the attacked IP address includes the following steps:

[0030] According to the current alarm IP address F x , the rising edge timestamp w of the IP address r1 , and the preset time window width q, calculate the start time and end time of the time window under different ranges;

[0031] Find the value corresponding to F in each time window x Matching twin IP address F y , if there exists F y , then F y Write into the twin IP list and put F x Updated to F y , put F x The timestamp w r1 Updated to F y The timestamp w r2 , and then repeat the above steps to find the twin IP address until the twin IP address cannot be found, and write all the found twin IP addresses into the twin IP list;

[0032] If there is no F in the time window y , then extract F x The temporary fingerprint of F x The temporary fingerprint, rising edge timestamp and falling edge timestamp of the fingerprint database are used to extract a group of possible reference IP addresses;

[0033] Calculate the reference IP address F z With F x According to the preset similarity threshold, if the IP address F z With F x The similarity is greater than or equal to the similarity threshold, indicating that the control IP address F z Fx The twin IP address is written into the twin IP list, and F x Updated to F z , and put F x The timestamp w r1 Updated to F y The timestamp w r3 , and then repeat the similarity calculation process to search for the twin IP address from the control IP address until the twin IP address cannot be found, and write all the found twin IP addresses into the twin IP list.

[0034] In summary, the present invention has the following beneficial effects:

[0035] 1. Accurately identify whether two communicating entities are the same device based on network fingerprints, with less computing and storage overhead, less changes to the existing network system, and high versatility.

[0036] 2. It can effectively reduce the impact of IP switching on attack scenario construction by associating attack events through fingerprints rather than simply performing association analysis based on IP addresses. Therefore, while improving the accuracy of analysis, it greatly reduces the burden on analysts. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 This is a schematic diagram of the attack segment.

[0038] Figure 2 This is a diagram of the Curiosity attack scenario.

[0039] Figure 3 It is a flow chart of the network attack scenario reconstruction method based on device fingerprint in 5G private network scenario.

[0040] Figure 4 It is the schematic diagram of temporary fingerprint comparison. DETAILED DESCRIPTION

[0041] The following is combined with Figure 1-4 The present invention is described in further detail.

[0042] Reference Figure 1 and Figure 2 , A is a complete attack activity. If the IP address does not change, analysts can obtain the complete attack activity through attack scenario reconstruction technology. However, due to the change of the IP address, the entire attack activity is divided into three independent segments A1-A3, which are called attack segments. This will lead to a deviation in the analyst's understanding of the attack activity. The analyst mistakenly believes that each attack segment is a complete attack activity, but in fact, it is only a partial segment of an attack activity.

[0043] To further illustrate, let’s take the typical Android worm “Curiosity” as an example to explain the principle and impact of attack activity fragmentation.

[0044] The attack process can be summarized into 5 steps:

[0045] Event 1: Victim Bob (10.238.53.59) receives a text message containing a download link for the Curiosity malware.

[0046] Event 2: Out of curiosity, Bob opens the link, and the virus is downloaded from the FTP server (110.232.4.23) and installed on the phone.

[0047] Event 3: The malware continuously sends Bob’s private information to the control server (communication & command, CC) (10.232.4.78), including IMEI, version number, text messages, and contact lists.

[0048] Event 4: The CC server sends instructions to Bob's phone through Google's Android Cloud to Device Messaging (C2DM) server (7.34.212.5), and asks Bob's phone to send a multicast SMS. (C2DM is a service that helps developers send data from the server to Android applications)

[0049] Event 5: Bob sent a group text message containing a download link for the Curiosity malware.

[0050] Assume that the Network Intrusion Detection System (NIDS) can correctly detect all abnormal behaviors. According to the traditional attack correlation method, attack events 2, 3, and 4 can be associated based on the same Bob's IP: 10.238.53.59, thereby reconstructing the attack scenario. In wireless networks, many scenarios can cause IP addresses to change, such as getting on and off a highway, UE losing connection in an elevator, or users leaving 5G coverage and reconnecting to LTE in mobile networks that do not support the N26 interface. Assume that Bob leaves the coverage area and re-enters at time t2. The IP address changes to 10.241.36.7, and the Curiosity malware continues to leak Bob's private information to the CC server. At time t3, the IP address changes again to 10.217.65.78 and receives commands through the Google C2DM service.

[0051] Analysts used the same method to reconstruct the attack scenario, from which they obtained the following attack activity information:

[0052] Activity 1: 10.238.53.59 downloaded a malware file and sent the user’s private data to the C&C server. However, the analysts were not aware of the complete set of information stolen by the malware and the commands sent by the C&C server to 10.238.53.59.

[0053] Activity 2: 10.241.36.7 sent some private information to the C&C server. However, analysts do not know why he contacted the C&C server, nor do they know what the next attack action will be.

[0054] Activity 3: 10.217.65.78 communicates with Google C2DM servers. Without context, it is difficult to determine if this is an attack.

[0055] IP switching makes it difficult for analysts to understand the relationship between the three activities. The victim IPs of different activities are different, and they seem to be independent attack activities. Therefore, in this example, the fragmentation of attack activities in the 5G private network scenario poses two challenges to attack detection. First, it misleads analysts' understanding of attack activities, including causes, intentions, and impacts. For example, in activity 1, UE10.238.53.59 did not receive any control commands, so analysts did not know whether the attack activity had propagation characteristics. In activity 2, analysts observed a fragmented attack fragment, and UE10.217.65.78 contacted the CC server without downloading malware. Analysts also did not know the next action of the UE after receiving the command from the CC server. In addition, the incomplete alarm sequence will affect further analysis of the attack, such as attack event prediction. For example, it is difficult to correctly predict the next action of activity 1, and event prediction lacks evidence without additional information (such as code analysis). Analysts must make extra efforts to mine contextual attack information.

[0056] Reference Figure 3 In order to solve the above problems, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario disclosed in the present invention includes the following steps:

[0057] S100, obtaining network traffic.

[0058] The network traffic in the 5G private network is obtained through network intrusion detection equipment (such as NIDS), potential attack behaviors in the network traffic are detected, alarms and monitoring logs are generated, and the alarms and monitoring logs are written to the alarm database. The infected IP is associated with the alarm to obtain the attack fragment. The network intrusion detection equipment is deployed in the 5G private network in a bypass mode.

[0059] S200, device fingerprint extraction.

[0060] Capture the traffic that triggers the alarm and store it as a pcap package. By parsing the pcap package, generate a data packet list corresponding to each IP address and traffic. Based on the generated data packet list, mark the network flow with a five-tuple of <source address, destination address, source port, destination port, timestamp>.

[0061] For each IP address, we prioritize the K busiest network flows and the communication sessions to which these K network flows belong, i.e., most of the traffic is in this communication session. The busiest means that there is the most traffic in this communication session. The traffic in these network flows indicates the applications running on the device and represents the temporary fingerprint of the device. By extracting the direction and length of the traffic in these K network flows as the network features of the network flows, we can obtain the temporary fingerprint of the device. The network feature of the traffic k of a single network flow is represented as f k =<±length i >, where k = 1, 2, ..., K, length i represents the length of the i-th flow in the network flow, and the sign represents the direction, with communication from UE to dedicated service being positive and communication from dedicated service to user being negative. For each IP address, the flow feature is the set of network features of the flow of all network flows under the IP address, which can be expressed as: T = {f1, f2, ..., f K}.

[0062] Since the amount of traffic contained in a communication session may be large, this will bring storage and computing overhead and bring additional noise to fingerprint extraction. Therefore, the scale of features is reduced by adopting a sampling mechanism, specifically:

[0063] The timestamp when the IP appears in the network is defined as the rising edge, denoted as t0; the timestamp when the IP disappears is defined as the falling edge, denoted as t m .

[0064] Filter the traffic captured in the time window after the rising edge, denoted as: w r =[t0, t0+δ], δ is the observation time window; the flow captured in the time window before the falling edge is recorded as: W d =[t m -δ,t m ]; extract only w r and w d The network features of the traffic in the two windows are used as the temporary fingerprint F of the device. That is, for the traffic arriving in the network flow, the five-tuple in the traffic is extracted and it is determined whether it belongs to w r and w d If the traffic does not belong to the two windows, it is directly released. Furthermore, if the timestamp of the traffic is earlier than t0 or later than t m, then t0 or t m Update to the timestamp of the traffic; if it belongs to w r or d Window, the temporary fingerprint F of the device is updated. Furthermore, a time threshold is set. If the idle time of the current IP address exceeds the time threshold, it means that the temporary fingerprint F of the IP address is extracted. Then, the temporary fingerprint F of the IP address is written into the fingerprint database.

[0065] Combination Figure 4 , S300, extract temporary fingerprints with similar time from the fingerprint database, determine the twin IP, and then output the twin IP list of the attacked IP address.

[0066] Find paired IP addresses through the Triplet network. The Triplet network is a distance metric learning method for scenarios with a small number of samples. In the offline model training phase, three samples (anchor point, positive example, and negative example) are received as input samples, and the input samples are embedded in the vector space. The distance between (anchor point, positive example) and (anchor point, negative example) is used to determine whether the input samples belong to the same type. Taking the Euler distance l as a measure of temporary fingerprint similarity, the calculation formula is: in, represents the jth feature of sample a, Represents the j-th feature of sample b, j = 1, 2, ..., n.

[0067] Three convolutional neural networks are used as embedding layers to extract the features of three samples. The three convolutional neural networks correspond to the three samples one by one, that is, one convolutional neural network is used to extract the features of one sample. The convolutional neural network includes a convolutional layer, a pooling layer, and a fully connected layer. The three convolutional neural networks share network parameters.

[0068] Map K*100 temporary fingerprints into a two-dimensional space, and obtain three low-dimensional vectors through the embedding process of the neural network. Calculate the Euler distance between the low-dimensional vectors, and measure the similarity between samples through the Euler distance. Furthermore, since identifying paired IP addresses is a binary classification problem, the activation function tanh() is used to scale the Euler distance to the interval [0, 1], and the calculation result output by the activation function tanh() is binary processed, that is, if the calculation result output by the activation function tanh() is less than 0.5, then 0 is output, and if the calculation result output by the activation function tanh() is greater than or equal to 0.5, then 1 is output. When the output result is 0, it indicates that the two temporary fingerprints indicate the same device, and when the output result is 1, it indicates that the two temporary fingerprints indicate different devices.

[0069] The goal of training is to make the Euler distance between the same category as small as possible and the Euler distance between different categories as large as possible. Therefore, the output result is optimized through the loss function L. The formula of the loss function L is: L = j(F(a, p), 0) + j(F(a, n), 1), where F(·, ·) represents the Triplet network, F(a, p) represents the Euler distance between the anchor sample a and the positive sample p in the Triplet network; F(a, n) represents the Euler distance between the anchor sample a and the negative sample n in the Triplet network; j(·, ·) represents the cross entropy loss function.

[0070] The generation process of the twin IP list is as follows: Based on the IP address F of the current alarm x , the rising edge timestamp w of the IP address r1 , and the preset time window width q, calculate the start time and end time of the time window under different ranges. In each time window, directly find the x Matching twin IP address F y , if there exists F y , then F y Write into the twin IP list and put F x Updated to F y , and put F x The timestamp w r1 Updated to F y The timestamp w r2 , and then repeat the above steps to search for the twin IP address until the twin IP address cannot be found, and write all the found twin IP addresses into the twin IP list.

[0071] If there is no F in the time window y , then extract F x The temporary fingerprint of F x The temporary fingerprint, rising edge timestamp and falling edge timestamp of the fingerprint database are used to extract a set of possible reference IP addresses. The reference IP address F is calculated through the Triplet network. z With F x According to the preset similarity threshold, if the IP address F z With F x The similarity is greater than or equal to the similarity threshold, indicating that the control IP address F z F x The twin IP address is written into the twin IP list, and F x Updated to F z , and put F x The timestamp w r1 Updated to F y The timestamp w r3, and then repeat the similarity calculation process to search for the twin IP address from the control IP address until the twin IP address cannot be found, and write all the found twin IP addresses into the twin IP list.

[0072] S400, reconstruct the attack scenario.

[0073] For the first-time victim or attacker IP, compare and query the temporary fingerprint based on the IP address and timestamp. If the twin IP list is obtained, iteratively search for attack fragments related to the twin IP and establish a connection between the two attack fragments. The above method can be used to associate multiple attack fragments caused by IP address switching, thereby reconstructing the attack scenario.

[0074] The above are all preferred embodiments of the present invention, and are not intended to limit the protection scope of the present invention. Therefore, any equivalent changes made based on the structure, shape, and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A network attack scenario reconstruction method based on device fingerprint in a 5G private network scenario, characterized by: The steps include: Capture the traffic that triggers the alarm and store it as a pcap packet, generating a list of packets corresponding to each IP address and traffic; The network flow is marked by the five-tuple of <source address, destination address, source port, destination port, timestamp>; Extract the direction and length of traffic in the network flow as a temporary fingerprint, and write the temporary fingerprint into the fingerprint database; Extract temporary fingerprints with similar time from the fingerprint database, determine the twin IP, and output the twin IP list of the attacked IP address; According to the twin IP list, find related attack fragments, associate multiple attack fragments, and reconstruct the attack scenario.

2. According to claim 1, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario is characterized by: Before capturing the traffic that triggers the alarm, obtain the network traffic through the network intrusion detection device, detect potential attack behaviors in the network traffic, generate alarms and monitoring logs, and write the alarms and monitoring logs into the alarm database; Correlate the infected IP with the alert to get the attack fragment.

3. According to claim 1, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario is characterized by: When extracting the direction and length of traffic in a network flow, for each IP address, the busiest K network flows are screened; and the direction and length of traffic in the K network flows are extracted.

4. According to claim 3, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario is characterized in that: The network characteristics of a single network flow k are expressed as f k =<±length i >, where k = 1, 2, ..., K, length i It represents the length of the i-th flow in the network flow, and the sign indicates the direction, where communication from UE to dedicated service is positive and communication from dedicated service to user is negative.

5. According to claim 3, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario is characterized in that: When extracting the direction and length of traffic in a network flow, filter the traffic captured in the time window after the rising edge and the traffic captured in the time window before the falling edge; Only the network features of the traffic in the time window after the rising edge and before the falling edge are extracted as the temporary fingerprint of the device.

6. According to claim 5, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario is characterized in that: The timestamp when the IP appears in the network is the rising edge, denoted as t0; the timestamp when the IP disappears is the falling edge, denoted as t m After filtering the traffic captured in the time window after the rising edge and the traffic captured in the time window before the falling edge, if the traffic does not belong to these two time windows and the timestamp is earlier than t0 or later than t m , then t0 or t m Updated to the timestamp of the traffic.

7. According to claim 1, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario is characterized by: Before extracting temporary fingerprints with similar time from the fingerprint database, perform model training: Using Triplet network; Take anchor points, positive examples and negative examples as input samples and embed the input samples into the vector space; Calculate the Euler distance between (anchor point, positive example) and (anchor point, negative example), and use the Euler distance as a measure of temporary fingerprint similarity; The training goal is to make the distance between the same category as small as possible and the distance between different categories as large as possible.

8. The network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario according to claim 7 is characterized in that: The output result of the Triplet network is optimized by the loss function L, and the formula of the loss function L is: L=j(F(a, p), 0)+j(F(a, n), 1).

9. According to claim 1, the network attack scenario reconstruction method based on device fingerprint in the 5G private network scenario is characterized by: Outputting the twin IP list of the attacked IP address includes the following steps: According to the current alarm IP address F x , the rising edge timestamp w of the IP address r1 , and the preset time window width q, calculate the start time and end time of the time window under different ranges; Find the value corresponding to F in each time window x Matching twin IP address F y , if there exists F y , then F y Write into the twin IP list and put F x Updated to F y , put F x The timestamp w r1 Updated to F y The timestamp w r2 , and then repeat the above steps to find the twin IP address until the twin IP address cannot be found, and write all the found twin IP addresses into the twin IP list; If there is no F in the time window y , then extract F x The temporary fingerprint of F x The temporary fingerprint, rising edge timestamp and falling edge timestamp of the fingerprint database are used to extract a group of possible reference IP addresses; Calculate the reference IP address F z With F x According to the preset similarity threshold, if the IP address F z With F x The similarity is greater than or equal to the similarity threshold, indicating that the control IP address F z F x The twin IP address is written into the twin IP list, and F x Updated to F z , and put F x The timestamp w r1 Updated to F y The timestamp w r3 , and then repeat the similarity calculation process to search for the twin IP address from the control IP address until the twin IP address cannot be found, and write all the found twin IP addresses into the twin IP list.

Citation Information

Patent Citations

  • Traffic corresponding relation matching method and device before and after translation of SNAT equipment

    CN111654556A

  • Cross-scene equipment fingerprint identification method and device, electronic equipment and storage medium

    CN114357427A

  • Real-time attack scene reconstruction method, system and equipment for multi-step attack

    CN115801458A

  • Topology pruning optimization method based on multi-step network attack identification and scene reconstruction

    CN116915450A

  • Method for detecting attack traffic, and related device

    WO2024099078A1