Network security attack tracing method based on generative large model
Through a generative large-scale model-based network security attack traceability method, system logs and network traffic are analyzed, combined with malware analysis and threat intelligence, digital forensics and artificial intelligence technology is used to solve the problem of difficult to accurately trace complex network attacks in the existing technology, and efficient attack traceability and defense measures are achieved.
Patent Information
- Application Number
- CN202411841836.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-06
AI Technical Summary
Existing cybersecurity attack traceability technologies are difficult to accurately identify and locate the attack source when facing complex cyber attacks, and attackers often use fake IP addresses, making traceability more difficult.
The network security attack traceability method based on a generative large model is adopted to analyze system logs, network logs and host device data, identify abnormal communication patterns and malicious activities, analyze malware samples, obtain external threat intelligence, and use digital forensic technology and artificial intelligence to conduct comprehensive analysis to judge the identity and motivation of the attacker.
It realizes accurate traceability of network security attacks, can effectively identify and locate attack sources in complex network environments, reduces the difficulties caused by forging IP addresses, and improves the efficiency of investigating and defense of network security incidents.
Smart Images

Figure CN119945710A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security attack tracing method based on a generative large model. Background Art
[0002] Network security attack tracing refers to the use of technical means to track and analyze the source and initiator of a network attack. Attack tracing is very important for the investigation and resolution of network security incidents. It can help network administrators determine the true source of the attack, take appropriate defensive measures, minimize losses, and prevent similar incidents from happening again.
[0003] Existing tracing technologies mainly rely on advanced intrusion detection systems, but these systems often find it difficult to accurately identify and locate the source of attack when faced with complex network attacks. In addition, network attackers often use forged IP addresses, making tracing even more difficult. Summary of the invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the present invention provides a network security attack tracing method based on a generative large model, which can solve the problems mentioned in the background technology.
[0006] To solve the above technical problems, the present invention provides the following technical solutions: A network security attack tracing method based on a generative large model, comprising: analyzing system logs, network logs, and host device and server data to find attack traces and abnormal behaviors;
[0007] Analyze network traffic to identify unusual communication patterns and malicious activity;
[0008] Analyze malware samples to extract attacker characteristics and tools;
[0009] Obtain external threat intelligence;
[0010] Analyze publicly available information;
[0011] Use digital forensics techniques to extract and analyze evidence from infected systems;
[0012] Use artificial intelligence and machine learning techniques to identify and analyze attack patterns;
[0013] Integrate multiple data sources such as logs, traffic, malware samples, and threat intelligence for comprehensive analysis to determine the identity and motivation of attackers.
[0014] As a preferred solution of the network security attack tracing method based on generative large model described in the present invention, the analysis of system logs, network logs, host device and server data includes determining log sources, configuring log records and centralized management.
[0015] As a preferred solution of the network security attack tracing method based on generative big model described in the present invention, wherein: determining the log source includes: determining the log data of servers, network devices, terminal devices, applications, databases and cloud services, and determining the priority according to the importance, sensitivity and potential risks of each network asset.
[0016] As a preferred solution of the network security attack tracing method based on generative large model described in the present invention, wherein: the analysis of network traffic includes capturing network traffic using network monitoring tools; analyzing the network traffic to identify abnormal communication patterns, malicious IP addresses and port scans; reconstructing the attacker's communication path to identify the source of the attack.
[0017] As a preferred solution of the network security attack tracing method based on the generative large model described in the present invention, the analyzing of malware samples includes: collecting malware samples from infected systems; analyzing the binary code of the malware samples, extracting character strings and configuration file information; running the malware samples in a sandbox environment, observing their behaviors and network communications; restoring the functions and logic of the malware samples through reverse engineering;
[0018] The acquisition of external threat intelligence includes: collecting threat intelligence from threat intelligence providers and open source intelligence channels; associating the threat intelligence with internal data; and identifying the behavior patterns of attackers;
[0019] Share said threat intelligence with other organizations and the security community;
[0020] The analysis of public information includes: collecting information from social media and forums; analyzing the information to identify the identity, motive and technical background of the attacker; and associating the information with internal data to confirm the identity of the attacker.
[0021] As a preferred solution of the network security attack tracing method based on the generative large model described in the present invention, the use of digital forensics technology includes: protecting the infected system to prevent evidence from being tampered with or destroyed; collecting data from the hard disk, memory and network; analyzing the data using digital forensics tools; extracting attack traces; generating a forensics report;
[0022] The use of artificial intelligence and machine learning technology includes: collecting and preprocessing network logs, traffic data and malware samples; training models using machine learning algorithms; applying the models to new data to automatically detect and classify attack behaviors; and optimizing the models based on feedback and new data.
[0023] As a preferred solution of the network security attack tracing method based on the generative big model described in the present invention, the fusion of multiple data sources includes: integrating data from different sources into a unified platform; using association analysis technology to associate information from different data sources; reconstructing the attack path; and combining multiple analysis results to determine the identity and motivation of the attacker.
[0024] To further solve the above technical problems, the present invention provides the following technical solutions: A network security attack tracing system based on a generative large model, comprising: a data acquisition module for analyzing system logs, network logs, and host device and server data to find attack traces and abnormal behaviors;
[0025] Traffic detection module, which is used to analyze network traffic and identify abnormal communication patterns and malicious activities;
[0026] Software analysis module, used to analyze malware samples and extract attacker characteristics and tools;
[0027] Intelligence acquisition module, used to obtain external threat intelligence;
[0028] Intelligence analysis module, used to analyze public information;
[0029] A forensic analysis module for extracting and analyzing evidence from infected systems using digital forensics techniques;
[0030] Attack identification module, which uses artificial intelligence and machine learning technology to identify and analyze attack patterns;
[0031] The comprehensive judgment module is used to integrate multiple data sources such as logs, traffic, malware samples and threat intelligence, conduct comprehensive analysis, and determine the identity and motives of the attacker.
[0032] A computer device includes a memory and a processor, wherein the memory stores a computer program, and is characterized in that when the processor executes the computer program, the steps of the network security attack tracing method based on the generative large model as described above are implemented.
[0033] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the steps of the network security attack tracing method based on a generative large model as described above are implemented.
[0034] Beneficial effects of the present invention: The present invention obtains a network security attack tracing method based on a generative large model through the above design, which adopts the method of analyzing log data, finding attack traces and abnormal behaviors, implementing traffic and malware analysis, and obtaining intelligence from the outside, extracting and analyzing evidence from infected systems, using artificial intelligence for identification, integrating multiple data sources, and comprehensively determining the identity and motives of attackers, thereby realizing attack tracing and making tracing simpler and more convenient. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0036] Figure 1 This is a schematic diagram of the overall process of a network security attack tracing method based on a generative large model proposed by the present invention;
[0037] Figure 2 This is a computer device diagram in a network security attack tracing method based on a generative large model proposed by the present invention. DETAILED DESCRIPTION
[0038] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.
[0039] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0040] Example 1, reference Figure 1 , as an embodiment of the present invention, provides a network security attack tracing method based on a generative large model.
[0041] S1: Data analysis and collection, by analyzing system logs, network logs, and high school equipment and server data to find attack traces and abnormal behaviors;
[0042] S2: Traffic analysis, identifying abnormal communication patterns and malicious activities by analyzing network traffic;
[0043] S3: Analyze malware, extract the characteristics and tools of attackers by analyzing malware samples;
[0044] S4: Obtain intelligence and use external threat intelligence to assist in tracing and analysis;
[0045] S5: Analyze intelligence, by analyzing publicly available information and analyzing collected information;
[0046] S6: Digital Forensics, extracting and analyzing evidence from infected systems through digital forensics techniques;
[0047] S7: Analyze attacks, using AI and machine learning techniques to identify and analyze attack patterns and determine attack patterns;
[0048] S8: Data fusion combines multiple data sources including logs, traffic, malware samples and threat intelligence to conduct comprehensive analysis and comprehensively determine the identity and motivation of the attacker.
[0049] In this embodiment, the acquisition of data analysis and collection in step S1 includes determining log sources, configuring log records and centralized management.
[0050] List all IT assets, including servers, network equipment such as routers, switches, firewalls, terminal devices such as PCs, laptops, mobile devices, applications, databases, cloud services, etc.
[0051] Assess importance and determine priorities based on the importance, sensitivity, and potential risks of each asset. For example, business-critical servers, externally exposed services, and systems that store sensitive data should be given priority.
[0052] Enable logging and ensure that all critical systems and devices have logging enabled.
[0053] Set the log level. Set the appropriate log level as needed, such as DEBUG, INFO, WARNING, ERROR, CRITICAL, to balance the amount of information and storage requirements.
[0054] Configure the log format to ensure that the log format is unified to facilitate subsequent analysis and processing. Common log formats include JSON, CSV, and Syslog.
[0055] Choose a log management tool, such as ELK Stack, Splunk, Graylog, Logstash, Fluentd, etc., to centrally collect and manage logs.
[0056] Configure log forwarding, configure the system and devices to send logs to the central log management platform. You can use Syslog, SNMP, API and other protocols for log forwarding.
[0057] Log storage: ensure that there is sufficient storage space to save log data and set appropriate retention periods based on compliance requirements.
[0058] In this embodiment, determining the log source includes determining the log data on the server, network equipment, terminal equipment, application program, database and cloud service, and determining the priority according to the importance, sensitivity and potential risk of each network asset.
[0059] It should be noted that determining the server includes the following steps:
[0060] List all servers. First, list all servers in the organization, both physical and virtual.
[0061] Classify servers according to their roles and uses, such as Web servers, application servers, database servers, file servers, etc.
[0062] Assess the importance and determine the priority of each server based on its importance, sensitivity, and potential risks. Critical business servers, servers storing sensitive data, and externally exposed services should be given priority.
[0063] Assess importance and prioritize each device based on its importance, sensitivity, and potential risk. Critical network edge devices, core switches, firewalls, etc. should be prioritized.
[0064] In this embodiment, the traffic analysis in step S2 includes traffic capture, data analysis and traffic reconstruction, using a network monitoring tool to capture network traffic, analyze traffic data, identify abnormal communication patterns, malicious IP addresses and port scans, reconstruct the attacker's communication path, and identify the source of the attack.
[0065] Preferably, the data analysis takes the following steps:
[0066] 1. Data Collection
[0067] Log data, collects log data from various network devices, servers, applications, and security devices.
[0068] Network traffic, use packet capture tools or traffic analysis tools to capture network traffic.
[0069] Threat intelligence, obtain threat intelligence from external threat intelligence providers or open source intelligence.
[0070] 2. Data Preprocessing
[0071] Data cleaning: remove invalid data, duplicate data and noise data.
[0072] Data conversion, converting data in different formats into a unified format for easy analysis.
[0073] Time synchronization, ensure that the timestamps of all data are synchronized, and use NTP for time synchronization.
[0074] 3. Data Analysis
[0075] Statistical analysis, calculation of total traffic, peak traffic, average traffic and other statistical indicators.
[0076] Pattern recognition uses rules and pattern matching techniques to identify known attack patterns and abnormal behaviors.
[0077] Time series analysis, analyzing the changing trends of data over time and identifying abnormal time patterns.
[0078] Correlation analysis: Correlation analysis is performed on data from different sources to reconstruct attack paths or fault chains.
[0079] User behavior analysis: analyzing user behavior patterns and identifying abnormal user activities.
[0080] Machine learning, using supervised and unsupervised learning algorithms, automatically identifies anomalous behavior and potential threats.
[0081] 4. Visualization and reporting
[0082] Visualization: Use visualization tools to display data in the form of charts, dashboards, etc. to help analysts understand the data intuitively.
[0083] Report generation, generates detailed analysis reports including descriptions of abnormal behavior, timelines, affected systems, and recommended defensive measures.
[0084] Real-time monitoring: Set up a real-time monitoring and alarm system to automatically send alarm notifications when abnormal behavior is detected.
[0085] Preferably, the flow reconstruction adopts the following steps:
[0086] 1. Traffic capture
[0087] Packet capture tools, use tools such as Wireshark and tcpdump to capture network traffic.
[0088] Traffic mirroring, using a Switched Port Analyzer or Test Access Point device to copy traffic to an analysis tool.
[0089] NetFlow / sFlow / IPFIX, configure network devices to generate NetFlow, sFlow, or IPFIX data. These protocols can provide metadata for traffic.
[0090] 2. Traffic Analysis
[0091] Session reconstruction: analyze TCP / UDP sessions and reconstruct the complete communication process.
[0092] Protocol analysis, identifying and analyzing traffic of various network protocols.
[0093] Traffic feature extraction: Extract traffic features for further analysis.
[0094] Anomaly detection, detects unusual traffic patterns, such as unusual connection attempts, unusual packet sizes, etc.
[0095] 3. Attack path reconstruction
[0096] Source IP and destination IP, identify the attack source IP and victim destination IP.
[0097] Timeline,Reconstruct the timeline of the attack based on timestamps.
[0098] Attack phase: Identify the different phases of an attack, such as reconnaissance, penetration, privilege escalation, data theft, etc.
[0099] Attack tools and techniques: Analyze the tools and specific techniques used by attackers, such as malware, vulnerability exploits, etc.
[0100] 4. Reporting and Response
[0101] Report generation: Generate detailed traffic reconstruction reports, including attack paths, affected systems, attack methods, etc.
[0102] Incident response: Based on the results of traffic reconstruction, the incident response process is initiated and necessary measures are taken, such as isolating the affected systems, fixing vulnerabilities, and strengthening protection.
[0103] Continuous monitoring, set up continuous traffic monitoring to detect and respond to future attacks in a timely manner.
[0104] In this embodiment, the malware analysis in step S3 is divided into several steps: sample collection, static analysis, dynamic analysis and reverse engineering. First, malware samples are collected from the infected system. Second, the binary code of the malware is analyzed to extract information such as strings and configuration files. Third, the malware is run in a sandbox environment to observe its behavior and network communication. Finally, the functions and logic of the malware are restored through reverse engineering to gain an in-depth understanding of the attacker's technical details.
[0105] Sample collection is achieved by deploying honeypots and honeynets to attract and capture malware, downloading samples from public malware sample libraries, capturing malware samples in suspicious traffic through network traffic monitoring tools, receiving suspicious file reports from users, and obtaining malware samples from hacker forums, underground markets, etc.
[0106] Static analysis uses tools to determine the file type and structure, calculate the hash value of the file for unique identification and comparison, use the strings tool to extract readable strings, and look for possible commands, URLs, IP addresses, etc. For Windows executable files, use tools to analyze the PE header, obtain information such as the import table, export table, resource section, etc., check the resources embedded in the file such as icons, pictures, and configuration files, and use YARA rules to match known malware features.
[0107] Dynamic analysis is to use sandbox tools, such as Cuckoo Sandbox and Joe Sandbox, to run malware in an isolated environment, use network monitoring tools, such as Wireshark and tcpdump, to capture the network traffic of malware, use system monitoring tools, such as Process Monitor and RegShot, to record the malware's operations on the file system, registry, processes, etc., use memory forensics tools to analyze the malware's behavior in memory, and record the malware's behavior, such as file operations, registry modifications, network connections, process injections, etc.
[0108] Reverse engineering is to use disassembly tools, such as IDA Pro and Ghidra, to convert binary files into assembly code. For malware written in high-level languages, use decompilation tools, such as JD-GUI and dotPeek, to convert them into source code. Use debugging tools, such as OllyDbg and x64dbg, to single-step execute the malware and observe its execution flow and key functions. Manually analyze the disassembled or decompiled code to identify key functions, algorithms, and data flows. If the malware uses encryption technology, try to decrypt key data. Use IDA Pro plug-ins and scripts to assist in analysis.
[0109] In this embodiment, the intelligence acquisition in step S4 is to collect threat intelligence from threat intelligence providers and open source intelligence channels, and associate the collected intelligence with internal data to identify the behavior patterns of attackers, share intelligence with other organizations and security communities, and expand information sources.
[0110] In this embodiment, the analysis intelligence in step S5 is to collect information from public channels such as social media and forums, analyze the collected information, identify the identity, motive and technical background of the attacker, associate the public information with internal data, and further confirm the identity of the attacker.
[0111] In this embodiment, the digital forensics in step S6 is to protect the infected system, prevent evidence from being tampered with or destroyed, collect data from hard disks, memory, networks, etc., use digital forensics tools to analyze data, extract attack traces, and generate a detailed forensics report.
[0112] The steps of digital forensics are as follows:
[0113] Define your goals and determine the purpose of the forensics, such as investigating a data breach, insider fraud, cyberattack, etc.
[0114] Legal advice: Consult legal advisors to ensure that the evidence collection process complies with local laws and regulations.
[0115] Develop a plan to create a detailed evidence collection plan, including the scope of the evidence collection, timeline, required tools and resources.
[0116] Assemble the team, assemble the forensic team, and assign roles and responsibilities.
[0117] In this embodiment, the attack analysis in step S7 is to collect and preprocess a large amount of network logs, traffic data and malware samples, use machine learning algorithms, train models, apply the models to new data, automatically detect and classify attack behaviors, and continuously optimize the models based on feedback and new data.
[0118] Analyzing attacks is a critical part of cybersecurity and involves a detailed study of attack events to understand the attacker’s methods, means, and intent. By analyzing attacks, security teams can better defend against future attacks, fix existing vulnerabilities, and take appropriate remedial actions. The following are the general steps and methods of attack analysis:
[0119] 1. Incident detection and initial response
[0120] target, identify attack incidents and initiate initial response.
[0121] Monitoring and alerting, detecting abnormal behavior through tools such as intrusion detection systems, intrusion prevention systems, and security information and event management systems.
[0122] Initial response: Once an attack is detected, the emergency response plan is immediately initiated, including isolating the affected systems, blocking further attack attempts, etc.
[0123] 2. Evidence Collection
[0124] The goal is to collect all evidence related to the attack, including logs, network traffic, system status, etc.
[0125] Log collection: collect system logs, application logs, security logs, etc.
[0126] Network traffic capture, use packet capture tools to capture network traffic.
[0127] Memory dump, obtain the memory dump of the affected system for subsequent analysis.
[0128] File system imaging: Create a disk image of the affected system to ensure the integrity and non-tamperability of the evidence.
[0129] 3. Evidence Analysis
[0130] Target, conduct a detailed analysis of the collected evidence to determine the nature, method and scope of the attack.
[0131] Log analysis: analyze system logs, application logs, and security logs to extract attack timelines and key events.
[0132] Network traffic analysis, analyzing captured network traffic to identify malicious activities, data exfiltration, command and control communications, etc.
[0133] Memory analysis: Analyze memory dumps to find running malicious processes, injected code, open files and network connections, etc.
[0134] File system analysis: analyze the file system to find hidden files, deleted files, modified files and timestamps, etc.
[0135] Malware analysis, which performs static and dynamic analysis of suspicious files to determine their nature and functionality.
[0136] Timeline reconstruction, constructs a timeline of attack events to help understand the development process of the attack.
[0137] 4. Attack tracing
[0138] Target, determine the attacker's identity, origin, and possible motivations.
[0139] IP address analysis, analyzing the attacker’s IP address and determining the geographic location using IP geolocation services.
[0140] Domain name analysis: Analyze the domain names used in the attack and find registration information and other associated domain names.
[0141] Threat intelligence, using external threat intelligence sources to find historical activities and correlation information of attackers.
[0142] Behavioral analysis, analyzing the attacker’s behavioral patterns to identify their tactics, techniques, and procedures.
[0143] 5. Impact Assessment
[0144] Objective: Assess the impact of attacks on systems, data, and business.
[0145] System inspection to check the status of the affected system and determine the extent of the damage.
[0146] Data integrity check: Check the integrity of the data to determine whether the data has been tampered with or leaked.
[0147] Business impact assessment, which evaluates the impact of an attack on business operations, including financial losses, reputational damage, etc.
[0148] In this embodiment, the data fusion in step S5 is to integrate data from different sources into a unified platform, use correlation analysis technology to associate information from different data sources, reconstruct the attack path, and combine multiple analysis results to comprehensively determine the identity and motives of the attacker.
[0149] Technical advantages: 1. Easy to understand: Rules are usually based on expert knowledge and experience, easy to understand and explain. 2. Flexibility: Different rules can be defined according to specific needs and scenarios. 3. Customizability: Rules can be customized according to specific performance standards to meet different evaluation needs.
[0150] Embodiment 2, which is an embodiment of the present invention, provides a network security attack tracing system based on a generative large model, including: a data acquisition module for analyzing system logs, network logs, and host device and server data to find attack traces and abnormal behaviors;
[0151] Traffic detection module, which is used to analyze network traffic and identify abnormal communication patterns and malicious activities;
[0152] Software analysis module, used to analyze malware samples and extract attacker characteristics and tools;
[0153] Intelligence acquisition module, used to obtain external threat intelligence;
[0154] Intelligence analysis module, used to analyze public information;
[0155] A forensic analysis module for extracting and analyzing evidence from infected systems using digital forensics techniques;
[0156] Attack identification module, which uses artificial intelligence and machine learning technology to identify and analyze attack patterns;
[0157] The comprehensive judgment module is used to integrate multiple data sources such as logs, traffic, malware samples and threat intelligence, conduct comprehensive analysis, and determine the identity and motives of the attacker.
[0158] Example 3, reference Figure 2, is an embodiment of the present invention, which is different from the previous embodiment in that: if the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0159] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0160] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0161] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0162] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A network security attack tracing method based on a generative large model, characterized in that: include: Analyze system logs, network logs, and host device and server data to look for traces of attacks and unusual behavior; Analyze network traffic to identify unusual communication patterns and malicious activity; Analyze malware samples to extract attacker characteristics and tools; Obtain external threat intelligence; Analyze publicly available information; Use digital forensics techniques to extract and analyze evidence from infected systems; Use artificial intelligence and machine learning techniques to identify and analyze attack patterns; Integrate multiple data sources for comprehensive analysis to determine the attacker's identity and motivation.
2. The network security attack tracing method based on the generative large model as claimed in claim 1 is characterized by: The analysis of system logs, network logs, and host device and server data includes determining log sources, configuring logging, and centralized management.
3. The network security attack tracing method based on the generative large model as claimed in claim 2 is characterized by: Determining the log source includes: determining the log data of servers, network devices, terminal devices, applications, databases and cloud services, and determining the priority according to the importance, sensitivity and potential risks of each network asset.
4. The network security attack tracing method based on the generative large model as claimed in claim 3 is characterized by: Said analyzing network traffic comprises capturing network traffic using a network monitoring tool; Analyze the network traffic to identify abnormal communication patterns, malicious IP addresses, and port scans; reconstruct the attacker's communication path and identify the source of the attack.
5. The network security attack tracing method based on the generative large model as claimed in claim 4 is characterized by: The analyzing of malware samples includes: collecting malware samples from infected systems; analyzing binary codes of the malware samples to extract strings and configuration file information; running the malware samples in a sandbox environment to observe their behaviors and network communications; and restoring the functions and logic of the malware samples through reverse engineering; The acquisition of external threat intelligence includes: collecting threat intelligence from threat intelligence providers and open source intelligence channels; associating the threat intelligence with internal data; and identifying the behavior patterns of attackers; Share said threat intelligence with other organizations and the security community; The analysis of public information includes: collecting information from social media and forums; analyzing the information to identify the identity, motive and technical background of the attacker; and associating the information with internal data to confirm the identity of the attacker.
6. The network security attack tracing method based on the generative large model as claimed in claim 5 is characterized by: The use of digital forensics technology includes: protecting infected systems to prevent evidence from being tampered with or destroyed; collecting data from hard disks, memory and networks; analyzing the data using digital forensics tools; extracting attack traces; and generating forensics reports; The use of artificial intelligence and machine learning technology includes: collecting and preprocessing network logs, traffic data and malware samples; training models using machine learning algorithms; applying the models to new data to automatically detect and classify attack behaviors; and optimizing the models based on feedback and new data.
7. The network security attack tracing method based on the generative large model according to claim 6 is characterized by: The fusion of multiple data sources includes: integrating data from different sources into a unified platform; using correlation analysis technology to associate information from different data sources; reconstructing the attack path; and combining multiple analysis results to determine the identity and motivation of the attacker.
8. A network security attack tracing system based on a generative large model, based on the network security attack tracing method based on a generative large model according to any one of claims 1 to 7, characterized in that: include, Data collection module, which is used to analyze system logs, network logs, and host device and server data to find traces of attacks and abnormal behaviors; Traffic detection module, which is used to analyze network traffic and identify abnormal communication patterns and malicious activities; Software analysis module, used to analyze malware samples and extract attacker characteristics and tools; Intelligence acquisition module, used to obtain external threat intelligence; Intelligence analysis module, used to analyze public information; A forensic analysis module for extracting and analyzing evidence from infected systems using digital forensics techniques; Attack identification module, which uses artificial intelligence and machine learning techniques to identify and analyze attack patterns; The comprehensive judgment module is used to integrate multiple data sources such as logs, traffic, malware samples and threat intelligence, conduct comprehensive analysis, and determine the identity and motives of the attacker.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network security attack tracing method based on a generative large model as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security attack tracing method based on a generative large model as described in any one of claims 1 to 7 are implemented.