EDR-oriented traceability model and behavior chain storage mechanism thereof

Through the EDR-oriented traceability model and behavior chain preservation mechanism, combined with a variety of tools and decentralized storage technology, the shortcomings of existing EDR technologies in attack traceability and forensic analysis are solved, and high accuracy and high reliability attack traceability and evidence preservation are achieved.

CN119995955AActive Publication Date: 2025-05-13CHONGQING UNIV OF POSTS & TELECOMM

Patent Information

Application Number
CN202510076293.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-13
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

The existing EDR technology has relatively weak support for attack traceability and forensic analysis, lacks cross-system and time traceability data query and storage mechanisms, and the traditional centralized storage method is susceptible to the risks of single point of failure and data tampering.

Method used

The EDR-oriented traceability model and its behavior chain preservation mechanism are adopted, and the five main modules of data collection, threat detection, forensic analysis, behavior chain storage and attack traceability are combined with tools such as Audibeat, GRR, Volatility, and Autopsy to achieve multi-level and multi-dimensional traceability analysis, and the data is tamper-free and reliable through decentralized storage (IPFS) and blockchain technology.

Benefits of technology

It improves the accuracy of attack detection and the accuracy of attack tracing, supports legal evidence collection and long-term preservation of electronic evidence, reduces the risk of single point of failure and data tampering in traditional storage methods, and enhances the integrity and reliability of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995955A_ABST
    Figure CN119995955A_ABST
Patent Text Reader

Abstract

The invention discloses an EDR-oriented traceability model and a method of a behavior chain preservation mechanism of the EDR-oriented traceability model. According to the method, traceability analysis of network attack behaviors is realized through functional modules such as data collection, threat detection, forensic analysis, archiving storage and attack traceability, and behavior chains are stored as electronic forensic evidences. The method comprises the following specific steps: collecting data such as system logs, operation logs and memory mirror images from terminal equipment through an EDR system and a GRR tool; a threat detection algorithm and MITRE ATTamp which are built in the EDR are utilized; the CK framework performs real-time behavior analysis, discovers potential threats and triggers a response; analyzing a memory mirror image and file data in combination with a third-party evidence obtaining tool, and reconstructing an attack behavior chain; through a hybrid mechanism of decentralized storage (IPFS) and local storage and a block chain technology, the integrity and non-tampering property of data are ensured; and finally, analyzing the relevance between the behavior chains by using an attack traceability module, and constructing a complete attack traceability graph. According to the method, the accuracy of attack behavior tracing and the security of data storage are effectively improved, the risk of data loss and tampering in a traditional tracing method is reduced, and powerful support is provided for subsequent network security event investigation and legal evidence obtaining.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an EDR (Endpoint Detection and Response)-oriented tracing model and a behavior chain preservation mechanism thereof. Background Art

[0002] With the rapid development of information technology, network security has become a focus of attention in all industries. Faced with increasingly complex and hidden network attacks, traditional security protection technologies (such as firewalls, intrusion detection systems (IDS), and virus scanning tools) have gradually exposed their shortcomings and are unable to effectively respond to modern and changing security threats. Therefore, endpoint detection and response (EDR) technology has gradually become an important part of the modern defense system due to its advantages in threat detection and source tracing analysis. EDR technology monitors endpoint behavior, detects and responds to potential threats in real time, and provides key information for subsequent attack investigations. In addition, forensic analysis and data tracing have also become important links in security incident response, which can help security personnel deeply understand the process and impact of attack behavior, and formulate targeted defense strategies.

[0003] However, most of the existing EDR technologies only focus on threat detection and real-time response, and the support for detailed forensic analysis and attack tracing after the attack is relatively weak. In addition, most of the existing EDR technologies rely only on local storage and lack cross-system and cross-time traceability data query and storage mechanisms, which makes it difficult to conduct in-depth analysis and investigation efficiently after the attack occurs. In the preservation of forensic evidence, the traditional centralized storage method is susceptible to single point failures and faces the risk of data being maliciously tampered with. Although decentralized storage technologies (such as IPFS) provide the advantages of distributed storage, in practical applications, how to ensure the authenticity and immutability of stored data still requires the support of effective verification mechanisms. Blockchain technology, with its data immutability, provides a possible solution for data integrity, but directly storing large-scale data on the blockchain will result in high storage costs and low operational efficiency. In addition, existing technologies usually calculate hashes and encrypt data for unified storage. Although this method simplifies the data structure, it also brings some problems. For example, when a certain part of the data needs to be accessed, the entire data packet must be decrypted, which not only reduces the query efficiency but also increases the complexity of the operation. In addition, the unified hash calculation method may cause any small change in the data packet to cause the overall hash value to change, increasing the difficulty of verifying some data. At the same time, if the encryption key is leaked, all data will be exposed at the same time, making it difficult to implement fine-grained access control. Summary of the invention

[0004] The present invention provides a method for a traceability model and a behavior chain preservation mechanism for EDR, aiming to realize the traceability analysis of malicious attack behaviors in terminal devices through multi-level and multi-dimensional technical means, and preserve the chain of attack behaviors as electronic forensic evidence. This method effectively improves the accuracy of attack detection and the precision of attack tracing through five main modules: data collection, threat detection, forensic analysis, behavior chain storage, and attack tracing, and has important application value in supporting legal evidence collection and long-term preservation of electronic evidence.

[0005] Step 1: Data Collection

[0006] This method uses the Audibeat log collection tool and the GRR forensic tool to obtain key data from different terminal devices through the data collection module. Audibeat is responsible for collecting system logs, operation logs, network traffic data, and file activity logs on terminal devices to help identify potential threat clues. These data will be transmitted to the threat detection module for real-time analysis. At the same time, the GRR tool is responsible for remotely collecting memory images, file data, registry information, and endpoint data to provide deep forensic support. When the EDR system detects a potential threat, GRR will transmit the data to external forensic tools (such as Volatility and Autopsy) in real time to ensure that data is obtained and analyzed from multiple angles and in all directions, thereby providing a strong basis for subsequent attack tracing and legal evidence collection.

[0007] Step 2: Threat Detection

[0008] In the threat detection module, the collected log data is first preprocessed, including formatting, removing irrelevant information, and standardizing. Then, the data is analyzed in real time through the threat detection algorithm built into the EDR system, and the MITRE ATT&CK framework is used to identify threats and capture abnormal behavior patterns, such as malware propagation, ransomware activity, and intranet penetration. Once a potential threat is detected, the system automatically triggers a response mechanism to issue an alarm, isolate the device, or take other protective measures based on the severity of the threat. In addition, the system will generate a detailed threat analysis report for the security team to analyze and handle, thereby improving the timeliness and accuracy of threat response.

[0009] Step 3: Forensic Analysis

[0010] In the forensic analysis module, after the threat detection module finds an anomaly, the system will integrate with third-party forensic tools (such as Volatility, Autopsy, and GRR) to deeply analyze memory images and file data. The GRR tool remotely obtains data from the target terminal device and transmits it to third-party forensic tools, which are used to analyze memory images, hard disk data, and network activities. In this way, the forensic analysis module can reconstruct the attack behavior chain and accurately restore the attacker's intrusion path and attack methods. Combined with the tactics and techniques in the MITRE ATT&CK framework, the system can effectively extract source data related to the attacker's behavior, providing a basis for attack tracing and legal evidence collection.

[0011] Step 4: Archive and store

[0012] The archiving and storage module ensures the long-term preservation and integrity of the behavior chain data through a multi-level storage mechanism. Each behavior chain consists of multiple behavior nodes. The data of each node will be encrypted by AES and stored in the decentralized storage system (IPFS), and the hash value of the data will be calculated at the same time. The generated identifier (cid) and hash value will be associated with the behavior chain data to ensure that the data cannot be tampered with. In addition, the behavior chain itself will also calculate the hash value and encrypt and store it in IPFS to generate a global identifier (CID). In order to ensure data security, the system also combines the local storage system for backup and verifies data integrity through blockchain storage. When the data in IPFS is tampered with or lost, the system can restore the data from the local storage and verify its integrity through the blockchain, thereby ensuring the validity and reliability of electronic evidence.

[0013] The system also introduces a multi-level hash mechanism. In addition to storing the CID of the behavior chain, it also calculates independent hash values ​​that are not related to the CID. Through these independent hash values, the system can still verify the integrity of the data when the CID fails. This mechanism enhances the system's ability to resist data tampering and provides a strong technical guarantee for dealing with IPFS or blockchain changes.

[0014] Step 5: Attack tracing

[0015] In the attack tracing module, the system uses archived behavior chain data and source data to comprehensively analyze the correlation between attack behaviors through tracing algorithms and build an attack tracing graph. First, the system verifies the integrity of archived data based on the CID and independent hash value stored in the blockchain. Then, feature matching, time series analysis, and graph analysis techniques are used to extract key data related to the attack, such as access sources, operation characteristics, network traffic patterns, etc., to build a correlation matrix for the behavior chain. Using graph embedding technology and machine learning algorithms, the system can discover potential correlations between attack behaviors and further explore the attacker's action path.

[0016] In addition, the system also uses clustering and anomaly detection methods to group attack chains based on behavioral characteristics and identify behavioral patterns similar to known attack characteristics. Through automated cluster analysis, the system can quickly locate typical attack types or new attack behaviors, thereby improving the efficiency and accuracy of tracing. Ultimately, all tracing results are presented through visualization tools to generate attack tracing diagrams, providing the security team with information such as attack paths, means, and target systems to support subsequent response and legal evidence collection.

[0017] Compared with the prior art, the present invention has the following beneficial effects:

[0018] The present invention integrates the EDR system with third-party forensic tools (such as GRR, Volatility, and Autopsy), which improves the comprehensiveness and analysis depth of forensic data and reduces the limitation that a single tool cannot fully cover various types of attack behaviors.

[0019] The hybrid storage mechanism of decentralized storage (IPFS) and local storage improves the reliability of data storage, ensures the immutability of evidence, and reduces the risk of evidence loss or tampering that may occur in traditional centralized storage.

[0020] The introduction of graph analysis methods and machine learning technologies for attack tracing uses graph embedding, clustering, and anomaly detection algorithms to improve the accuracy and automation of attack behavior analysis and reduce manual analysis and missed detection in traditional tracing methods. Through graph analysis and machine learning, the system can automatically discover potential connections in the attack chain, quickly identify complex attack paths, and improve tracing efficiency and emergency response capabilities.

[0021] The introduction of a multi-level hash verification mechanism improves the verification capability of data integrity and reduces the verification risk brought by a single hash mechanism. By performing independent hash calculations on the behavior chain and source data, the system can more effectively detect whether the data has been tampered with and provide additional verification methods to ensure data integrity even if the CID fails. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 EDR tracing model diagram

[0023] Figure 2 Flowchart for archiving and storage

[0024] Figure 3 It is the attack behavior chain diagram and its node data structure DETAILED DESCRIPTION

[0025] The present invention will be described in detail below in conjunction with the accompanying drawings. It should be noted that the described embodiments are only for the purpose of illustration and are not intended to limit the scope of the present invention.

[0026] The present invention provides a method for tracing a source model and its behavior chain preservation mechanism for EDR. The flow chart of the method is as follows: Figure 1 As shown, the following steps are included:

[0027] Step 1: The data collection module first collects data from different terminal devices through Audibeat log collection (or the data collection function of the EDR system) and GRR forensic tools. The Audibeat tool is responsible for collecting log data on the terminal device, including system logs, operation logs, network traffic data, file activity logs, etc. This data can be transmitted to the threat detection module for further analysis. At the same time, the GRR tool is used to collect deep forensic data on the terminal device, such as system memory images, file data, registry information, and endpoint data. When the EDR system detects a potential threat, the GRR tool collects this data in real time and transmits it to external forensic tools such as Volatility and Autopsy for in-depth analysis. Specifically, the GRR tool is responsible for remotely acquiring data from the target device and transmitting this data to the integrated third-party forensic tool, which further parses the memory image and file data to help reconstruct the attack behavior chain. In this way, the combination of the GRR tool and the external forensic tool ensures that the key evidence of the terminal device can be fully acquired and deeply analyzed when an attack occurs, providing strong support for subsequent tracing and forensic work.

[0028] Step 2: In the threat detection module, the log data from the data collection module is first preprocessed, including data formatting, irrelevant information filtering, and information standardization. The processed data will be analyzed in real time by the threat detection algorithm built into the EDR system to identify potential security threats. Specifically, the system combines various tactics and techniques in the MITRE ATT&CK framework, and uses pattern matching-based algorithms, behavior analysis algorithms (such as machine learning-based anomaly detection algorithms), and statistical analysis methods to detect abnormal behavior patterns, such as malware self-replication, ransomware encryption, and suspicious activities of intranet penetration. For each detected threat, the system will take corresponding response measures based on the severity and category of the threat: for lower-level threats, the system may only trigger an alarm; for medium- and high-level threats, it may immediately isolate the infected device, or perform protective measures such as network isolation, antivirus, and access blocking. In addition, the EDR system will automatically interact with the security response platform to generate a detailed threat analysis report to help the security team deeply analyze and handle threats, and further improve the accuracy and timeliness of threat response. This process relies on advanced behavioral analysis and adaptive response strategies to ensure that the system can detect and respond to various potential attacks in a timely and accurate manner, minimizing security risks.

[0029] Step 3: In the forensic analysis module, when the threat detection module finds abnormal activities and triggers a response, the module will integrate with third-party forensic tools (such as Volatility, Autopsy, GRR, etc.). Specifically, the GRR tool is responsible for obtaining deep forensic data from the affected terminal devices, including memory images, file data, registry information, and endpoint data. The collected raw data will be transmitted to third-party forensic tools for further analysis. The Volatility tool is mainly used for parsing memory images to help extract key information such as process information, network connections, and module loading. Autopsy is used to analyze data traces in hard disks and file systems to track attackers' file operations and data flows. The combination of the EDR system and these tools ensures efficient management and in-depth analysis of large-scale data, and can accurately construct the attack behavior chain. Through these integrations, the forensic analysis module can not only extract important source data from massive data, but also reconstruct the attacker's intrusion path and attack methods based on the strategies and techniques in the MITRE ATT&CK framework, providing strong support for subsequent attack tracing and legal evidence collection.

[0030] Step 4: The archiving and storage module is responsible for long-term storage of the behavior chain data and source data. The flow chart is as follows Figure 3Each behavior chain consists of multiple behavior nodes. The source data block of each behavior node is encrypted (AES) and stored in the decentralized storage system IPFS to obtain an identifier (cid), and the hash of the source data block is calculated. The generated identifier and hash value will be added to the behavior chain data to achieve the association between the behavior chain data and the source data. Its data structure is as follows: Figure 2 Each node contains a timestamp, the name of the behavior node, the hash value of the associated source data, and the identifier (cid) of the source data storage location. In addition, the behavior chain itself will also calculate the hash value (HASH) and encrypt it and store it in IPFS to generate the global identifier (CID) of the behavior chain. Finally, the hash value of the behavior chain data and its corresponding CID will be stored on the blockchain to ensure the integrity and unforgeability of the data.

[0031] In order to improve the reliability and robustness of the data, the system further introduces a hybrid storage mechanism that combines decentralized storage (IPFS) and local storage. When the source data is encrypted and stored in IPFS, the system will synchronously back up the data and its calculated hash value to the local storage system. The local storage system can be a secure database or file system that is specifically used to save copies of the behavior chain data. In addition, the system will periodically trigger consistency verification tasks to compare the hash values ​​of the data in the local storage and IPFS to ensure that the two are consistent. Once the data in IPFS is tampered with or lost, the system can quickly restore the data from the local storage and verify the integrity of the restored data through the original CID stored in the blockchain. In this way, even if the data on IPFS fails, the system can still ensure the effectiveness and reliability of the evidence in the electronic forensics process.

[0032] In order to further enhance data integrity verification, the system also uses a multi-level hash mechanism. Before storing the CID of the behavior chain in the blockchain, the system will also calculate and store a set of independent hash values ​​that are not related to the CID (such as the original hash value of the behavior chain data). These independent hash values ​​are generated based on the original data and are mainly used to provide additional verification methods when the CID is invalid or tampered with. CID is used to quickly retrieve data, and the independent hash value can directly verify the integrity of the data. Even if the data in IPFS is tampered with and the CID is invalid, the system can still verify whether the data restored from the backup is consistent with the original data through the original hash value. This mechanism not only enhances the ability to resist data tampering, but also provides strong technical protection for possible IPFS mechanism changes or attacks.

[0033] When performing a query operation, the system will first locate and retrieve the data in IPFS through the CID in the blockchain. If the retrieved data is tampered with or the CID cannot be effectively matched, the system will automatically switch to local storage, retrieve the backup data for query, and use the original hash value stored in the blockchain to verify the integrity of the backup data. If the verification is successful, the system will re-upload the restored data to IPFS to generate a new CID, and associate the newly generated CID with the original hash value in the blockchain to form a new effective chain of evidence. The entire query and recovery process ensures the traceability of the operation through detailed logging and auditing mechanisms, further improving the credibility of the system.

[0034] By combining encrypted storage of behavior chain data and source data, local backup mechanism, multi-level hash verification mechanism and blockchain storage, the system not only ensures the integrity and immutability of evidence during storage and evidence collection, but also provides the function of dealing with data tampering, loss and system changes. This design provides all-round protection for evidence preservation and auditing, while achieving efficient cross-system query and robust data verification capabilities.

[0035] Step 5: In the traceability module, the system uses the previously archived behavior chains and source data, combined with the traceability algorithm, to comprehensively analyze the correlation between different attack behaviors, and finally construct a complete attack traceability graph. First, the system verifies the archived behavior chains and source data based on the CID and independent hash value stored in the blockchain to ensure the integrity and credibility of the forensic data. Subsequently, through techniques such as feature matching and time series analysis, key attack-related data in the behavior chain, such as access sources, operation characteristics, network traffic patterns, and timestamps, are extracted. The system uses these data to construct an association matrix, identify potential associations between different behavior chains, and reveal potential associations between behavior chains through graph analysis techniques. By constructing a graph model of attack behaviors, each behavior node represents an attack event or behavior (for example, malicious file download, privilege escalation operation, etc.), and the edges between nodes represent the causal relationship or time series dependency between different attack behaviors. To further explore the associations between behaviors, the system introduces graph embedding technology to map the nodes and edges in the graph to a low-dimensional vector space. This enables us to discover potential attack paths and hidden attack patterns by calculating the similarities between nodes. For example, through node embedding, we can detect whether attackers reuse the same malicious tools or use similar attack methods in different attack chains, which helps to improve the accuracy of tracing and reduce the missed detection rate.

[0036] In addition, in order to enhance the automation and accuracy of tracing, the system also applies machine learning algorithms, especially clustering algorithms and anomaly detection methods. Through the clustering algorithm, the system can automatically group attack behaviors and identify behavioral chains similar to known attack patterns, thereby quickly locating typical attack types or new attacks. During the clustering process, the machine learning model automatically classifies similar behaviors according to the characteristics of the behavior nodes (such as file hashes, network traffic patterns, process behaviors, etc.), helping the security team to quickly identify potential attack paths. In addition, the anomaly detection algorithm analyzes historical behavior data to identify emerging attack features that differ greatly from conventional patterns. Through these methods, the system can continuously optimize the accuracy and timeliness of attack tracing, helping the security team to locate the source of the attack and the attacker's action trajectory more quickly and accurately.

[0037] Finally, all the traceability results are presented through visualization tools to generate an attack traceability graph, which not only shows the attacker's intrusion path, but also includes detailed information of each behavior node, correlation analysis results, and key contextual information (such as the characteristics of the attack tool, identification of the attack target, etc.). This graph analysis method combines graph embedding technology with machine learning, greatly improving the data analysis capabilities in the attack traceability process, so that in complex multi-stage attacks, the system can accurately reconstruct the attack process and provide accurate evidence support for subsequent responses and legal evidence collection.

[0038] Example: EDR-oriented traceability model and behavior chain preservation mechanism

[0039] Assume that a complex intranet attack occurred in an organization's network environment. The attacker hacked into an employee's computer by exploiting a vulnerability, further expanding the scope of the attack and stealing sensitive data. The attack went through multiple stages, including initial access, privilege escalation, data collection, and information leakage. The organization deployed the EDR-oriented tracing model and its behavior chain preservation mechanism of the present invention. The following is the specific implementation process of how the system works to resolve this attack.

[0040] Step 1: Data Collection

[0041] At the beginning of the attack, the organization's EDR system collected various log data from employee terminals in real time through the Audibeat log collection tool, including system logs, network traffic, operation logs, etc. In addition, the GRR forensic tool was triggered under the guidance of the EDR system and began to collect deep forensic data from the terminal, including memory images, registry information, and all file activity records. The GRR tool uses its remote forensics capabilities to automatically transfer this data to integrated external forensic tools (such as Volatility and Autopsy). The Volatility tool parses the memory image data, restores the process tree and network connection information, and provides further evidence support; Autopsy analyzes the file system and tracks the malicious operations performed by the attacker in the file system.

[0042] Step 2: Threat Detection

[0043] After collecting a large amount of log data, the threat detection module pre-processes the data, formats it, and filters out irrelevant data. Then, the system uses the built-in threat detection algorithm combined with the MITRE ATT&CK framework to perform real-time behavioral analysis on the data. Through behavioral analysis algorithms (such as anomaly detection algorithms based on machine learning), the system can quickly detect attacker behavior patterns, such as malware self-replication, privilege escalation, data encryption, etc. After the system detects an anomaly, it automatically triggers an alarm and isolates the affected terminal devices, while initiating protective measures, such as blocking the attacker's external communications, antivirus, and blocking suspicious processes.

[0044] Step 3: Forensic Analysis

[0045] After the threat detection module triggers an alarm and executes response measures, the forensic analysis module starts working immediately. The system obtains deep forensic data from the attacked terminal device by integrating with third-party forensic tools such as Volatility and Autopsy. The memory image and file data collected by the GRR tool are transmitted to these tools for detailed analysis. For example, the Volatility tool parses the memory image to restore the attacker's process and network connection information, while Autopsy analyzes data traces in the file system to help trace the attacker's file operations. The EDR system further combines these forensic data with known attack tactics and techniques based on the MITRE ATT&CK framework to accurately reconstruct the attack behavior chain and reveal the attacker's intrusion path and attack methods.

[0046] Step 4: Behavior chain storage and archiving

[0047] The system saves the extracted behavior chain data and source data in the decentralized storage system IPFS through encrypted storage. The source data block of each behavior node is stored through AES encryption, and a unique identifier (CID) and hash value are generated for it. Then it is added to the behavior chain data, so that a close association is formed between the behavior chain data and the source data, and the integrity and non-tamperability of the data are ensured. In addition, in order to enhance the reliability of the data, the system will also regularly synchronize and back up the data and hash values ​​in IPFS to the local storage system, and store the hash value and CID of the behavior chain on the chain through blockchain technology to ensure the integrity and audit traceability of the stored data.

[0048] Step 5: Attack tracing and graph analysis

[0049] With the archiving and storage of behavior chain data, the system enters the attack tracing stage. Based on the archived behavior chain and source data, the system first uses the tracing algorithm to conduct a comprehensive analysis of the data. Through feature matching and time series analysis, the system extracts key attack-related data, including access sources, operation characteristics, network traffic patterns, timestamps, etc. In order to reveal the potential associations between different behavior chains, the system uses graph analysis technology. By constructing a graph model of attack behavior, each behavior node represents a specific attack activity, and the edges between nodes represent the causal relationship or time dependency between attack behaviors. Furthermore, the system maps the nodes and edges in the graph to a low-dimensional vector space through graph embedding technology, and uses the similarity between nodes to discover the potential relationship of the attack path. Graph embedding not only helps identify similar malicious tools used by attackers in multiple chains, but also reveals hidden attack paths, improving the accuracy and efficiency of tracing.

[0050] In addition, the system combines clustering algorithms and anomaly detection methods to automatically group and classify behavior chains. Through clustering, the system can quickly identify behavior chains similar to known attack patterns, helping the security team quickly locate the source of the attack and analyze the attack methods. Anomaly detection can discover emerging attack behaviors that do not conform to conventional patterns, further improving the accuracy of tracing.

[0051] Finally, the system generates an attack traceability graph through visualization tools, which intuitively shows the attacker's intrusion path, attack methods, and the relationship between the target system. The attack traceability graph not only presents detailed information on each behavior node, but also provides in-depth attack path analysis through graph embedding and clustering algorithms.

[0052] Through this embodiment, the system successfully detected and responded to intranet attacks, reconstructed the complete chain of attack behaviors, and ensured the integrity, immutability and efficient traceability of forensic data through graph analysis, machine learning and decentralized storage technology, providing strong support for the investigation and response of network security incidents.

Claims

1. A method for a traceability model for EDR and a behavior chain preservation mechanism thereof, characterized by: This mechanism realizes the source analysis of attack behaviors through functional modules such as data collection module, threat detection module, forensic analysis module, archiving and storage module and attack tracing module, and stores the behavior chain as electronic forensic evidence. The specific steps are as follows: Step 1: Data collection, using the Audibeat log collection tool or the collection function of the EDR system, as well as the GRR forensics tool, to collect data from different terminal devices. The collected data includes but is not limited to system logs, operation logs, network traffic data, file activity logs, memory images, file data, registry information, and endpoint data; Step 2: Threat detection, pre-processing the collected data, filtering irrelevant information and formatting it. Subsequently, the EDR system's built-in threat detection algorithm and the MITRE ATT&CK framework are used to perform real-time behavioral analysis on the data, detect abnormal behavior patterns, and trigger preset response mechanisms (such as alerts, isolation of infected devices, or other protective operations) when potential threats are found. Step 3: Forensic analysis: Through integration with third-party forensic tools, we deeply analyze the collected memory images and file data, and combine them with the behavioral analysis data provided by the threat detection module to reconstruct the complete process of the attack behavior. Step 4: Archiving and storage: The attack behavior chain data and related source data reconstructed by the forensic analysis module are stored as electronic forensic evidence to provide support for subsequent legal evidence collection or traceability investigation. Step 5: Attack tracing, using previously archived behavior chains and source data, combined with tracing algorithms, comprehensively analyze the correlation between different attack behaviors, and finally construct a complete attack tracing map.

2. The method for the EDR-oriented traceability model and its behavior chain preservation mechanism according to claim 1 is characterized in that: The source data includes log data, network traffic, memory images and other information collected from terminal devices. The behavior chain data is based on the source data and is constructed according to the technical model framework in the MITRE ATT&CK framework. It contains multiple behavior nodes, each of which represents an operation of the attacker, such as privilege escalation, intranet penetration or malware propagation. By analyzing the association of these nodes, the attack path can be reconstructed and evidence can be provided for electronic forensics.

3. The method of the EDR-oriented traceability model and its behavior chain preservation mechanism according to claim 1 is characterized in that: The data collection in step 1 includes using the Audibeat tool to collect log data on the terminal device and transmit the log data to the threat detection module for analysis. At the same time, the GRR tool is used to collect deep forensic data, including system memory images, file data, registry information, and endpoint data.

4. The method of the EDR-oriented traceability model and its behavior chain preservation mechanism according to claim 1 is characterized in that: The threat detection process in step 2 includes the following three sub-steps: Step 1: Preprocess the collected log data, including data formatting, removing irrelevant information, and standardizing information; Step 2: Use the built-in threat detection algorithm of the EDR system to perform real-time behavioral analysis on the pre-processed data to identify potential security threats; Step 3: Dig deeper into the analysis results based on the MITRE ATT&CK framework to further identify abnormal behaviors and trigger corresponding response mechanisms.

5. The method of the EDR-oriented tracing model and its behavior chain preservation mechanism according to claim 1 is characterized in that: In the forensic analysis in step 3, when the threat detection module finds an anomaly, it will combine third-party tools (such as Volatility, Autopsy, and GRR, etc.) to conduct in-depth analysis of the memory image and file data, reconstruct the attack behavior chain, and ensure comprehensive tracing of the attack behavior.

6. The method of the EDR-oriented traceability model and its behavior chain preservation mechanism according to claim 1 is characterized in that: The archiving and storage in step 4 combines a hybrid mechanism of decentralized storage (IPFS and blockchain) and local storage, as well as a multi-level hashing mechanism. The process includes the following sub-steps: Step 1: Calculate the hash value (hash1, hash2…) of the source data block of each behavior node in the behavior chain data, store it in the decentralized storage system IPFS through encryption, and generate an identifier (cid). At the same time, the source data, cid and related hash values ​​are synchronously backed up to the local storage system; Step 2: Add the generated identifier and hash value to the behavior chain data to ensure the association between the behavior chain data and the source data; Step 3: Calculate the hash value (HASH) of the entire behavior chain data, encrypt it and store it in IPFS to generate the global identifier (CID) of the behavior chain; at the same time, synchronously back up the data, CID and its HASH to the local storage system; Step 4: Store the hash value (HASH) of the behavior chain data and its corresponding CID on the blockchain to ensure the integrity and unforgeability of the data.

7. The hybrid storage mechanism of decentralized storage and local storage according to claim 5 is characterized in that: After the system synchronously backs up the data, identifiers and their hash values ​​to the local storage system, if the data in IPFS is tampered with or lost, the system can restore the data from the local storage and verify the integrity of the data through the hash value stored in the blockchain to ensure the validity and reliability of the evidence.

8. The multi-level hash mechanism according to claim 5, characterized in that: Before storing the CID of the behavior chain in the blockchain, the system will also calculate and store independent hash values ​​that are not related to the CID (such as the original hash value of the behavior chain data). These independent hash values ​​are generated based on the original data and are mainly used to provide additional verification methods when the CID is invalid or tampered with. CID is used to quickly retrieve data, and the independent hash value can directly verify the integrity of the data. Even if the data in IPFS is tampered with and the CID is invalid, the system can still verify whether the data restored from the backup is consistent with the original data through the original hash value. This mechanism enhances the protection against data tampering and provides strong technical support for responding to changes or attacks on the IPFS mechanism.

9. The method of the EDR-oriented tracing model and its behavior chain preservation mechanism according to claim 1 is characterized in that: Step 5 of attack tracing includes the following sub-steps: Step 1: Based on the CID and independent hash value stored in the blockchain, verify the archived behavior chain and source data to ensure the integrity and credibility of the forensic data; Step 2: Extract key attack-related data, such as access sources, operation characteristics, network traffic patterns, and timestamps, through signature matching, time series analysis, and other technologies; Step 3: Identify potential connections between different behavior chains by building a correlation matrix, and use graph analysis techniques (such as graph embedding or graph-based machine learning methods) to mine attack paths; Step 4: Use clustering and classification techniques to group behavior chain data through pattern recognition and behavior feature similarity to identify behavior chains that match known attack features; Step 5: Combine static analysis and dynamic analysis methods to conduct in-depth mining of operation records and file information in the source data to extract contextual information of attack behaviors, such as intrusion tool features and abnormal network requests. Step 6: Based on the results of correlation analysis, an attack traceability diagram is automatically generated to show the attacker's intrusion path, attack methods and the relationship between the target system or data, assisting the security team in attack incident investigation and emergency response.

10. The first sub-step according to claim 8, characterized in that: It can locate the specific content that may have been tampered with. First, extract the behavior chain data from IPFS according to the CID, decrypt and calculate the hash value, and compare it with the original hash value stored on the blockchain. If the hash value is consistent, it means that the data has not been tampered with; If the hash values ​​are inconsistent, the hash value of the source data is further verified. If the source data hash values ​​are consistent, it means that the source data has not been tampered with, but the behavior chain information may have been tampered with. If the source data hash values ​​are also inconsistent, the specific behavior node and source data where the tampering occurred can be accurately located, thereby clarifying the specific location and content of the tampering.

Citation Information

Patent Citations

  • Data trusted storage sharing system and method based on block chain

    CN113961535A

  • Network attack traceability evidence obtaining method

    CN115134250A

  • Threat traceability analysis method, traceability analysis model establishment method and device

    CN117040879A

  • Attack traceability storage and attack scene restoration method based on block chain technology

    CN117527359A

  • Full-life-cycle filing and tracing method based on multi-modal data

    CN118377683A

Cited By

  • Supervision method applied to network security emergency linkage system

    CN120281569A

  • Railway information infrastructure safety management and control system based on data processing

    CN120434067A

  • Artificial intelligence model traceability and tamper-proofing method and system based on block chain enhancement

    CN120512320A

  • Blockchain-based enhanced artificial intelligence model provenance and tamper-proofing method and system

    CN120512320B