ATTCK-based power communication network attack tracing method

Through the ATT&CK-based power communication network attack traceability method, the network attack source data is processed, the degree of impact of the attack target and the common distance between the attack events is analyzed, and the problem of low accuracy of attack traceability in the power communication network is solved, and more efficient and accurate attack traceability is achieved.

CN119995922APending Publication Date: 2025-05-13国网思极网安科技(北京)有限公司 +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411882529.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The accuracy of network attack tracing in power communication networks is not high, mainly because there is a lot of redundancy in the network attack data, which affects the accuracy of attack tracing.

Method used

The power communication network attack traceability method based on ATT&CK is adopted. By obtaining multiple attack events in the network attack source data, the entity relationship extraction is performed, the triplets of each attack event are obtained, the degree of impact of the attack target is analyzed, the common distance between attack events is calculated, and the clustering and adjustment is performed. Finally, the attack chain is constructed for traceability.

Benefits of technology

It reduces redundant information in the network attack source data, reduces interference in the attack source tracing process, and improves the accuracy of attack source tracing and data processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995922A_ABST
    Figure CN119995922A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method and a device based on ATTamp; the CK-based power communication network attack tracing method comprises the following steps: acquiring a plurality of attack events in network attack source data, performing entity relationship extraction processing on each attack event to obtain a triple of each attack event, determining the influence degree of each attack target included in each attack event on the corresponding attack event according to the triple of each attack event, and tracing the attack source data according to the influence degree of each attack target included in each attack event. For any two attack events, based on the influence degree of the common attack target of the two attack events and all attack targets corresponding to the two attack events, determining a common distance, clustering the multiple attack events according to the common distance to obtain multiple groups of attack events, and adjusting the number of the attack events in each group of attack events to obtain multiple attack events; and based on the adjusted multiple groups of attack events, constructing an attack chain according to a preset attack tracing method. According to the invention, redundant information in the network attack source data can be reduced, the accuracy of network attack tracing is improved, and the data processing efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of information security technology, and in particular to a method for tracing the source of attacks on a power communication network based on ATT&CK. Background Art

[0002] In power communication networks, wireless networks are widely used because they are easy to deploy and maintain, but the openness of the network makes it more vulnerable to network attacks. Tracing the source of network attacks based on the ATT&CK framework can track the attacker's operation process and attack scenario, analyze the attacker's behavior pattern, and thus formulate effective preventive measures. However, due to the redundancy of a large amount of network attack data in the network, the accuracy of network attack tracing is affected. Summary of the invention

[0003] In view of this, the purpose of an embodiment of the present application is to propose a power communication network attack tracing method based on ATT&CK to solve the problem of low accuracy in network attack tracing.

[0004] Based on the above objectives, the embodiment of the present application provides a method for tracing the source of attacks on a power communication network based on ATT&CK, including:

[0005] Obtain multiple attack events from network attack source data;

[0006] Perform entity relationship extraction on each attack event to obtain a triple of each attack event, which includes the attack target, the relationship between the attack targets, and the attributes of the attack target;

[0007] According to the triples of each attack event, determine the influence degree of each attack target included in each attack event on the corresponding attack event;

[0008] For any two attack events, the commonality distance is determined based on the influence degree of the common attack target of the two attack events and all attack targets corresponding to the two attack events; wherein the common attack target is the attack target commonly targeted by the two attack events;

[0009] Clustering multiple attack events according to the commonality distance to obtain multiple groups of classified attack events;

[0010] According to a preset adjustment rule, the number of attack events in each group of attack events is adjusted to obtain multiple groups of attack events after adjustment;

[0011] Based on the adjusted multiple groups of attack events, an attack chain is constructed according to the preset attack tracing method.

[0012] Optionally, determining the influence degree of each attack target included in each attack event on the corresponding attack event according to the triplet of each attack event includes:

[0013] For each attack incident:

[0014] Construct a directed graph with each attack target as a node and the relationship between attack targets as an edge;

[0015] Based on the directed graph, determining a search path for each attack target according to a preset path search method;

[0016] For each attack target: the total number of attack targets on all search paths is taken as the first state association value, and the total number of search paths is taken as the second state association value; according to the first state association value, the second state association value and the attribute of the attack target, the relative influence parameter of the attack target is calculated; according to the first state association value, the second state association value and the relative influence parameter, the influence degree of the attack target is calculated.

[0017] Optionally, the attributes of the attack target include network traffic data of the attack target and status data indicating whether the attack target is normal;

[0018] Calculate the relative impact parameter of the attack target according to the first state association value, the second state association value and the attribute of the attack target, in the following method:

[0019]

[0020] Among them, h x is the relative impact parameter of the attack target x; l x is the state-associated feature vector of the attack target x, l i is the state-related feature vector of attack target i, Y(l x ,l i ) means l x and l i The cosine similarity between them, n is the total number of attack targets in the directed graph; the state association feature vector includes the first state association value, the second state association value, the network traffic data and the state data of the attack target.

[0021] Optionally, the influence degree of the attack target is calculated according to the first state association value, the second state association value and the relative influence parameter, and the method is:

[0022]

[0023] Among them, H x is the impact degree of attack target x; a x is the first state association value of the attack target x, b x It is the second state associated value of the attack target x.

[0024] Optionally, based on the impact degree of the common attack target of the two attack events and all attack targets corresponding to the two attack events, the commonality distance is determined, including:

[0025] Determining a common difference parameter of the two attack events according to the influence degree of the common attack target in one attack event and the influence degree of the common attack target in another attack event;

[0026] Determine common characteristic parameters of the two attack events according to all attack targets of one attack event and all attack targets of the other attack event;

[0027] The commonality distance between the two attack events is determined according to the commonality difference parameter and the commonality feature parameter.

[0028] Optionally, determining the common difference parameters of the two attack events according to the influence degree of the common attack target in one attack event and the influence degree of the common attack target in the other attack event includes:

[0029] Calculating the Manhattan distance between the influence degree of the common attack target in one attack event and the influence degree in another attack event, and using the calculation result as the commonality difference parameter;

[0030] Based on all attack targets of one attack event and all attack targets of another attack event, the common characteristic parameters of the two attack events are determined, including:

[0031] Calculating the Jaccard coefficient between all attack targets of one attack event and all attack targets of another attack event, and using the calculation result as the common characteristic parameter;

[0032] Determining the commonality distance between two attack events according to the commonality difference parameter and the commonality feature parameter includes:

[0033] The commonality difference parameter and the commonality feature parameter are multiplied to obtain the commonality distance.

[0034] Optionally, multiple attack events are clustered according to the commonality distance to obtain multiple groups of classified attack events, including:

[0035] Using the preset clustering algorithm, multiple attack events are clustered based on the common distance between any two attack events to obtain multiple groups of classified attack events.

[0036] Optionally, the number of attack events in each group of attack events is adjusted according to a preset adjustment rule, including:

[0037] For each attack event in a group of attack events, count the number of times each attack target in the attack event appears in all attack events in the group of attack events;

[0038] The number of times each attack target appears is compared with a preset adjustment threshold, and the attack targets whose number of times is less than the adjustment threshold are deleted.

[0039] Optionally, the adjustment threshold is determined according to the total number of attack events in each group of attack events.

[0040] Optionally, based on the adjusted multiple groups of attack events, an attack chain is constructed according to a preset attack source tracing method, including:

[0041] For the adjusted multiple groups of attack events, the ATT&CK framework is used to build the attack chain of each attack event.

[0042] From the above, it can be seen that the power communication network attack tracing method based on ATT&CK provided by the embodiment of the present application obtains multiple attack events in the network attack source data, extracts entity relationships for each attack event, obtains the triples of each attack event, and determines the degree of influence of each attack target included in each attack event on the corresponding attack event according to the triples of each attack event. For any two attack events, based on the degree of influence of the common attack target of the two attack events and all attack targets corresponding to the two attack events, the common distance is determined, and the multiple attack events are clustered according to the common distance to obtain multiple groups of classified attack events, and the number of attack events in each group of attack events is adjusted to obtain multiple groups of adjusted attack events; based on the adjusted multiple groups of attack events, an attack chain is constructed according to a preset attack tracing method. The present application can reduce redundant information in network attack source data, reduce interference in the process of network attack tracing, improve the accuracy of network attack tracing, and improve data processing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0044] Figure 1 A schematic diagram of a method flow of an embodiment of the present application;

[0045] Figure 2 A schematic diagram of a directed graph of an embodiment of the present application;

[0046] Figure 3 This is a schematic diagram of the process of tracing using the ACC&CK framework in an embodiment of the present application;

[0047] Figure 4This is a structural block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0048] In order to make the objectives, technical solutions and advantages of the present disclosure more clearly understood, the present disclosure is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0049] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should be the usual meanings understood by people with ordinary skills in the field to which the present disclosure belongs. The "first", "second" and similar words used in the embodiments of the present application do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connecting" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to represent relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0050] In related technologies, attack events in power communication networks are analyzed and traced based on the ATT&CK framework. Actual network attacks often have complex attack strategies and a large attack range. There is a certain redundancy in network attack data. For example, in order to improve the success rate of attacks, during the attack process, targets with less correlation with the attack targets may be attacked multiple times, resulting in more redundant information in the attack time against a single attack target. A large amount of redundant information not only interferes with the analysis of attack behavior patterns and attack target relationships, affects the accuracy of network attack tracing, but also reduces processing efficiency.

[0051] In view of this, an embodiment of the present application provides an attack tracing method for an electric power communication network based on ATT&CK, which analyzes the influence of attack targets on attack events, determines the common distance between attack events according to the influence of common attack targets between attack events and the similarity of all attack targets, clusters attack events according to the common distance, and adjusts each type of attack event by deleting a certain number of attack events, and then performs tracing analysis based on the adjusted attack events, which can reduce the interference of redundant information, improve the accuracy of network attack tracing, and improve the efficiency of data processing.

[0052] The technical solution of the present application is further described in detail below through specific embodiments.

[0053] like Figure 1As shown, the embodiment of the present application provides a network attack source tracing method, including:

[0054] S101: Acquire multiple attack events in network attack source data;

[0055] In this embodiment, during the operation of the network, all recorded network attack source data are obtained by reading the system log. The network attack source data recorded in the system log includes multiple attack events, each of which includes an attack target, an attack strategy, an attack technique, network traffic data of the attack process, and state data of the attack target, etc. In some embodiments, there may be multiple attack targets in one attack event, and there is a specific attack sequence between different attack targets. For example, the formulated attack strategy is to attack multiple attack targets that are associated with the final attack target one by one.

[0056] In some scenarios, in order to realize the tracing of network attacks on the power communication network, the fluentd log collector is used to obtain the system logs in the power communication network, and the network attack source data in the power communication network is obtained through the system logs, and then multiple attack events of the power communication network are obtained.

[0057] S102: extracting entity relations from each attack event to obtain a triplet of each attack event, where the triplet includes an attack target, a relationship between attack targets, and attributes of the attack target;

[0058] In this embodiment, after obtaining multiple attack events in the network attack source data, for each attack event, the entity relationship extraction method is used to identify the target entity, the relationship between the target entity, and the triple consisting of the attributes of the target entity from the attack event, that is, the attack target (as the target entity), the relationship between the attack targets, and the attributes of the attack target are identified, forming a triple consisting of the attack target, the relationship between the attack targets, and the attributes of the attack target. Among them, the attributes of the attack target include the attack technology against the attack target, the network traffic data of the network node where the attack target is located when the network attack occurs, and the status data used to indicate whether the attack target is normal, etc. The status data takes a value of 0 or 1, and a value of 0 indicates a normal state, and a value of 1 indicates a fault interruption; the relationship between the attack targets is a causal relationship between the attack targets suffering from an attack and a state change. For example, because the attack target A is attacked by the attack target B, the attack target A changes its state, and this causal relationship exists between the two attack targets.

[0059] Optionally, triples may be identified from attack events based on an entity relationship triple extraction model. This application does not provide a specific description or explanation of the entity relationship triple extraction model.

[0060] S103: Determine, based on the triples of each attack event, the degree of influence of each attack target included in each attack event on the corresponding attack event;

[0061] In this embodiment, after identifying the triples of each attack event, the influence of each attack target in the attack event on the attack event is determined according to the triples of each attack event. The method includes:

[0062] For each attack incident:

[0063] Construct a directed graph with each attack target as a node and the relationship between attack targets as an edge;

[0064] Based on the directed graph, the search path for each attack target is determined according to the preset path search method;

[0065] For each attack target: the total number of attack targets on all search paths is taken as the first state association value, and the total number of search paths is taken as the second state association value; according to the first state association value, the second state association value and the attribute of the attack target, the relative influence parameter of the attack target is calculated; according to the first state association value, the second state association value and the relative influence parameter, the influence degree of the attack target is calculated.

[0066] In this embodiment, considering the complex associations between the attack targets in the attack event, in order to analyze the associations between the attack targets, a directed graph for describing the attack targets and the relationships between the attack targets is constructed based on the triples of the attack event. Figure 2 As shown, for each triple of an attack event, all attack targets in the triple are taken as nodes, the relationships between the attack targets are taken as edges, the nodes corresponding to the attack targets with relationships are connected, and a directed graph corresponding to each attack event is constructed. For example, the state of attack target 2 changes due to the attack of attack target 1, so in the directed graph, attack target 1 points to attack target 2.

[0067] Based on the constructed directed graph, the search path of each attack target in the attack event is determined according to the preset path search method, and the association relationship of each attack target in the directed graph is determined. The association relationship of each attack target can reflect the degree of association influence generated when the attack target is attacked and the state changes in the attack event. Specifically, for each attack target in the directed graph, the attack target is used as the starting node, and the depth first search algorithm (Deep First Search, DFS) is used to determine all search paths of the attack target, and the total number of attack targets on all search paths is used as the first state association value a of the attack target, and the total number of search paths is used as the second state association value b of the attack target. The first state association value and the second state association value of the attack target can reflect the degree of association influence generated when the state of the attack target changes. The larger the first state association value and the second state association value, the greater the association influence generated by the attack target.

[0068] After determining the first state association value and the second state association value of the attack target, the relative impact parameter of the attack target in the attack event is calculated according to the first state association value, the second state association value and the attribute of the attack target. The calculation method is:

[0069]

[0070] Among them, h x is the relative impact parameter of the attack target x; l x is the state-associated feature vector of the attack target x, l i is the state-related feature vector of attack target i, Y(l x ,l i ) means l x and l i The cosine similarity between them, n is the total number of attack targets in the directed graph. The state association feature vector of the attack target includes the first state association value, the second state association value, the network traffic data and the state data of the attack target.

[0071] The relative influence parameter calculated according to formula (1) can reflect the degree of association influence of the attack target in the attack event. The smaller the relative influence parameter of the attack target, the greater the difference between the association influence range of the attack target and the association influence range of other attack targets in the attack event, the greater the deviation between the attributes of the attack target and the attributes of other attack targets, and the more significant the association influence of the attack target in the attack event.

[0072] According to the first state association value, the second state association value and the relative impact parameter of the attack target, the impact degree of the attack target is calculated. The calculation method is:

[0073]

[0074] Among them, H x is the impact degree of attack target x; a x is the first state association value of the attack target x, b x is the second state association value of the attack target x. The greater the impact of the attack target, the greater the correlation between the state change of the attack target and the state changes of other attack targets in the attack event, and the greater the impact of the attack target in the attack event.

[0075] S104: For any two attack events, determine a commonality distance based on the influence degree of a common attack target of the two attack events and all attack targets corresponding to the two attack events; wherein the common attack target is an attack target commonly targeted by the two attack events;

[0076] In this embodiment, after determining the influence degree of each attack target in each attack event, for any two attack events, based on the influence degree of the common attack target of the two attack events in the corresponding attack events and all attack targets corresponding to the two attack events, the commonality distance between the two attack events is determined, and the method includes:

[0077] Determine the common difference parameters of the two attack events according to the influence degree of the common attack target in one attack event and the influence degree of the common attack target in the other attack event;

[0078] Determine common characteristic parameters of the two attack events according to all attack targets of one attack event and all attack targets of the other attack event;

[0079] The commonality distance between two attack events is determined based on the commonality difference parameter and the commonality feature parameter.

[0080] Specifically, for each attack event, an attack target set consisting of attack targets is constructed; for the attack target sets of any two attack events, the common attack target of the two attack events is determined by calculating the intersection of the two attack target sets. If there are multiple common attack targets, the influence degree of each common attack target in one of the attack events constitutes the first attack feature sequence, and the influence degree of each common attack target in another attack event constitutes the second attack feature sequence. The attack feature sequence composed of the influence degree of the common attack targets can reflect the common characteristics of the attack targets of the attack events.

[0081] In some implementations, determining the common difference parameter of the two attack events based on the influence of the common attack target in one of the attack events and the influence of the common attack target in the other attack event includes: calculating the Manhattan distance between the influence of the common attack target in one of the attack events and the influence of the common attack target in the other attack event, and using the calculation result as the common difference parameter. That is, the Manhattan distance between the first attack feature sequence and the second attack feature sequence is calculated to obtain the common difference parameter of the two attack events. The larger the value of the common difference parameter, the greater the difference in the influence of the attack behavior patterns of the two attack events.

[0082] In some embodiments, determining the common feature parameters of the two attack events based on all attack targets of one attack event and all attack targets of another attack event includes: calculating the Jaccard coefficient between all attack targets of one attack event and all attack targets of another attack event, and using the calculation result as the common feature parameter. That is, the Jaccard coefficient between the set of attack targets of one attack event and the set of attack targets of another attack event is calculated to obtain the common feature parameter. The larger the value of the common feature parameter, the more similar the attack behavior characteristics of the two attack events are.

[0083] According to the commonality difference parameter and the commonality characteristic parameter, the commonality distance between the two attack events is determined, including: multiplying the commonality difference parameter and the commonality characteristic parameter to obtain the commonality distance, and the calculation method is:

[0084] θ c,t =v c,t ×p c,t (3)

[0085] Among them, θ c,t is the commonality distance between attack event c and attack event t; v c,t is the common difference parameter between attack event c and attack event t, p c,t is the common feature parameter between attack event c and attack event t. The larger the common distance, the more similar the attack behavior characteristics of the two attack events are, indicating the difference in the common features and correlation impact of the comprehensive attack targets.

[0086] S105: clustering multiple attack events according to common distances to obtain multiple groups of classified attack events;

[0087] In this embodiment, after determining the common distance between any two attack events, a clustering algorithm is used to cluster multiple attack events based on the common distance between the two attack events, and the multiple attack events are divided into multiple groups. In some methods, an agglomerative hierarchical clustering method can be used to cluster based on the common distance between the two attack events. The smaller the common distance, the higher the similarity of the two attack events. In the clustering iteration process, the two attack events with the smallest common distance are divided into one group. When the preset iteration conditions are met, multiple groups of attack events can be obtained. The attack events in the same group have a higher similarity, that is, the attack events in the same group have a large number of common attack targets, and the associated impacts between the attack targets are close. This embodiment does not explain the specific process and principle of the agglomerative hierarchical clustering method.

[0088] S106: adjusting the number of attack events in each group of attack events according to a preset adjustment rule to obtain multiple groups of attack events after adjustment;

[0089] In this embodiment, after obtaining multiple groups of attack events through clustering, for each group of attack events, a certain number of redundant attack events are deleted to achieve the purpose of reducing redundant information. Wherein, according to the preset adjustment rules, the number of attack events in each group of attack events is adjusted, including:

[0090] For each attack event in a group of attack events, count the number of times each attack target in the attack event appears in all attack events in the group of attack events;

[0091] The number of times each attack target appears is compared with a preset adjustment threshold, and the attack targets whose number of times is less than the adjustment threshold are deleted.

[0092] In this embodiment, considering that redundant information is significantly different from normal attack events in the same group of attack events, for each group of attack events, the number of times each attack target of each attack event appears in the group of attack events is counted, and whether the attack target belongs to redundant information is determined based on the relationship between the number of times it appears and a preset adjustment threshold. The adjustment threshold is determined based on the total number of attack events in each group of attack events, for example, the result of rounding down one third of the total number of attack events in a group of attack events is used as the adjustment threshold.

[0093] For example, there are 100 attack events in a group of attack events. The attack target B in attack event A appears 50 times in the 100 attack events, and the attack target C appears 20 times in the 100 attack events. The adjustment threshold of this group of attack events is 33. Since the number of times the attack target C appears is less than the adjustment threshold, the attack target C is regarded as redundant information and is deleted from the attack events where the attack target C is located.

[0094] S107: Based on the adjusted multiple groups of attack events, an attack chain is constructed according to a preset attack tracing method.

[0095] In this embodiment, by deleting a certain number of attack events in each group of attack events, redundant information is effectively reduced. For each group of attack events after deleting redundant information, an attack chain of each attack event is constructed based on the ATT&CK framework.

[0096] Specifically, Figure 3 As shown in the figure, each adjusted attack event is taken as input, and the attack chain construction algorithm is used to construct the attack chain of the attack event based on the vulnerabilities in the ACC (Apache Commons Collections) library. Among them, the attack chain includes attack tactics and attack techniques. The attack chain construction process includes: using the sequence composed of all attack tactics in the ATT&CK framework as the attack tactic sequence, using the sequence composed of all attack techniques as the attack technique sequence, mapping the attack tactics existing in the input attack event with the elements in the attack tactic sequence, mapping the attack techniques existing in the attack event with the elements in the attack technique sequence, and constructing the attack behavior matrix.

[0097] For example, the attack behavior matrix constructed is U = [u1,u2,…,u q ], where u i =[m1,m2,…,m r ],u i ,m j ={0,1}; where q is the total number of attack tactics in the ATT&CK framework, and r is the total number of attack techniques corresponding to the attack tactics; u i Indicates whether the attack event uses the i-th attack tactic. If so, u i 1, if not used, u i =0; m j Indicates whether the attack event uses the jth attack technique. If so, m j 1, if not used, m j is 0.

[0098] The attack behavior matrix U is mapped to the matrix provided by the ATT&CK framework for marking. The red mark corresponds to the attack technology with a value of 1, and the arrow marks the transfer of attack technology and technology. The attack technology and arrows under the attack tactics form the attack chain of the attack event. By analyzing the starting node of the attack chain, the information of the attack source is obtained, and the traceability information including the attack source is generated by combining the network topology and device information.

[0099] The power communication network attack tracing method based on ATT&CK provided in the embodiment of the present application extracts entity relationships of multiple attack events in the network attack source data to obtain triples of each attack event, determines the degree of influence of each attack target included in each attack event on the corresponding attack event based on the triple, determines the common distance of the two attack events based on the degree of influence of the common attack target of the two attack events and all attack targets corresponding to the two attack events, clusters the multiple attack events according to the common distance, divides the multiple attack events into multiple groups, deletes the redundant information in each group of attack events, and constructs an attack chain for the adjusted attack events based on the ATT&CK framework. The present application can effectively reduce the redundant information in the network attack source data, improve the accuracy of network attack tracing, and improve the efficiency of data processing.

[0100] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the described method.

[0101] It should be noted that the above is a description of a specific embodiment of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0102] For the convenience of description, the above devices are described in terms of functions divided into various modules. Of course, when implementing the embodiments of the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0103] The apparatus of the above-mentioned embodiment is used to implement the corresponding method in the above-mentioned embodiment, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0104] Figure 4 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.

[0105] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0106] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0107] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0108] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0109] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0110] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0111] The electronic device of the above embodiment is used to implement the corresponding method in the above embodiment, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0112] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0113] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples. Based on the concept of the present disclosure, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0114] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the known power supply / ground connection with the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device can be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform to be implemented in the embodiments of the present application (that is, these details should be fully within the scope of understanding of those skilled in the art). In the case of elaborating specific details (e.g., circuits) to describe exemplary embodiments of the present disclosure, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0115] Although the present disclosure has been described in conjunction with specific embodiments of the present disclosure, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.

[0116] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the present disclosure.

Claims

1. A power communication network attack tracing method based on ATT&CK, characterized in that: include: Obtain multiple attack events from network attack source data; Perform entity relationship extraction on each attack event to obtain a triple of each attack event, which includes the attack target, the relationship between the attack targets, and the attributes of the attack target; According to the triples of each attack event, determine the influence degree of each attack target included in each attack event on the corresponding attack event; For any two attack events, the commonality distance is determined based on the influence degree of the common attack target of the two attack events and all attack targets corresponding to the two attack events; wherein the common attack target is the attack target commonly targeted by the two attack events; Clustering multiple attack events according to the commonality distance to obtain multiple groups of classified attack events; According to a preset adjustment rule, the number of attack events in each group of attack events is adjusted to obtain multiple groups of attack events after adjustment; Based on the adjusted multiple groups of attack events, an attack chain is constructed according to the preset attack tracing method.

2. The method according to claim 1, characterized in that According to the triplet of each attack event, determine the influence degree of each attack target included in each attack event on the corresponding attack event, including: For each attack incident: Construct a directed graph with each attack target as a node and the relationship between attack targets as an edge; Based on the directed graph, determining a search path for each attack target according to a preset path search method; For each attack target: the total number of attack targets on all search paths is taken as the first state association value, and the total number of search paths is taken as the second state association value; according to the first state association value, the second state association value and the attribute of the attack target, the relative influence parameter of the attack target is calculated; according to the first state association value, the second state association value and the relative influence parameter, the influence degree of the attack target is calculated.

3. The method according to claim 2, characterized in that The attributes of the attack target include network traffic data of the attack target and status data indicating whether the attack target is normal; Calculate the relative impact parameter of the attack target according to the first state association value, the second state association value and the attribute of the attack target, in the following method: Among them, h x is the relative impact parameter of the attack target x; l x is the state-associated feature vector of the attack target l, l i is the state-associated feature vector of attack target i, l(l x ,l i ) indicates l x and l i The cosine similarity between them, n is the total number of attack targets in the directed graph; the state association feature vector includes the first state association value, the second state association value, the network traffic data and the state data of the attack target.

4. The method according to claim 3, characterized in that The influence degree of the attack target is calculated according to the first state association value, the second state association value and the relative influence parameter, in the following method: Among them, H x is the impact degree of attack target x; a x is the first state association value of the attack target x, b x It is the second state associated value of the attack target x.

5. The method according to claim 1, characterized in that: Based on the impact degree of the common attack target of the two attack events and all attack targets corresponding to the two attack events, the commonality distance is determined, including: Determining a common difference parameter of the two attack events according to the influence degree of the common attack target in one attack event and the influence degree of the common attack target in another attack event; Determine common characteristic parameters of the two attack events according to all attack targets of one attack event and all attack targets of the other attack event; The commonality distance between the two attack events is determined according to the commonality difference parameter and the commonality feature parameter.

6. The method according to claim 5, characterized in that According to the influence degree of the common attack target in one attack event and the influence degree of the common attack target in another attack event, the common difference parameters of the two attack events are determined, including: Calculating the Manhattan distance between the influence degree of the common attack target in one attack event and the influence degree in another attack event, and using the calculation result as the commonality difference parameter; Based on all attack targets of one attack event and all attack targets of another attack event, the common characteristic parameters of the two attack events are determined, including: Calculating the Jaccard coefficient between all attack targets of one attack event and all attack targets of another attack event, and using the calculation result as the common characteristic parameter; Determining the commonality distance between two attack events according to the commonality difference parameter and the commonality feature parameter includes: The commonality difference parameter and the commonality feature parameter are multiplied to obtain the commonality distance.

7. The method according to claim 1, characterized in that Clustering multiple attack events according to the commonality distances to obtain multiple groups of attack events after classification, including: Using the preset clustering algorithm, multiple attack events are clustered based on the common distance between any two attack events to obtain multiple groups of classified attack events.

8. The method according to claim 1, characterized in that: According to the preset adjustment rules, the number of attack events in each group of attack events is adjusted, including: For each attack event in a group of attack events, count the number of times each attack target in the attack event appears in all attack events in the group of attack events; The number of times each attack target appears is compared with a preset adjustment threshold, and the attack targets whose number of times is less than the adjustment threshold are deleted.

9. The method according to claim 8, characterized in that The adjustment threshold is determined according to the total number of attack events in each group of attack events.

10. The method according to claim 1, characterized in that Based on the adjusted multiple groups of attack events, an attack chain is constructed according to the preset attack tracing method, including: For the adjusted multiple groups of attack events, the ATT&CK framework is used to build the attack chain of each attack event.