Network attack tracing method and device based on internal and external network topology node analysis
By building the topological structure model and behavioral association network of internal and external network nodes, calculating the association weights and performing reverse deduction, the problem of low accuracy of network attack traceability in complex network environments is solved, and higher accuracy of attack traceability and comprehensiveness of network security threat analysis is achieved.
Patent Information
- Application Number
- CN202510160979.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-13
AI Technical Summary
The prior art is difficult to fully reflect the attack patterns in complex network environments in the source of cyber attacks, resulting in a reduction in the accuracy of attack tracing.
By obtaining the connection relationship and behavioral characteristics of internal and external network nodes, a topological structure model is built, the association weight of network nodes is calculated, the behavioral association network is constructed, and the attack path is determined through reverse deduction to locate the attack source.
It improves the accuracy of network attack tracing, can fully integrate the connection relationship between internal and external networks, identify hidden propagation paths in complex network environments, and accurately locate attack source through quantitative analysis and reverse deduction of correlation weights.
Smart Images

Figure CN119996004A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network attack tracing, and specifically to a network attack tracing method and device based on internal and external network topology node analysis. Background Art
[0002] With the rapid development of information technology and the popularization of the Internet, the network has become a key infrastructure for social, economic and political activities. However, the resulting network security issues are becoming increasingly severe. The frequency and complexity of network attacks are constantly increasing, bringing huge security risks to organizations, enterprises and individuals around the world. Network attacks include not only common attack types such as data leakage, network intrusion, malware propagation, denial of service attacks (DDoS), but also complex and long-term attack behaviors such as advanced persistent threats (APT). In the face of these attacks, timely and effective attack tracing has become one of the core issues in ensuring network security.
[0003] In related technologies, most network attack source tracing methods focus on the analysis of a single network topology, for example, they only rely on the internal network topology or external network topology to determine the attack source. When tracing the source of a network attack based on a single network topology, the network topology is relatively simple and the analysis process is not complicated. This improves the efficiency of network attack source tracing to a certain extent.
[0004] However, a single network topology (whether it is an internal network topology or an external network topology) can usually only show part of the connection relationship or attack path in the network, and cannot fully reflect the complex attack patterns that may exist in the entire network. In a complex multi-layered network environment, attacks may jump and disguise multiple nodes multiple times. In this case, it is difficult to accurately track through a single topology structure, which reduces the accuracy of tracing the source of network attacks. Summary of the invention
[0005] The present application provides a network attack tracing method and device based on internal and external network topology node analysis, which is used to improve the accuracy of network attack tracing.
[0006] In a first aspect of the present application, a network attack tracing method based on internal and external network topology node analysis is provided, which is applied to a server. The method includes: The method comprises: obtaining a connection relationship and behavior characteristics between an internal network node and an external network node, wherein the internal network topology diagram includes the internal network node, and the external network topology diagram includes the external network node; according to the connection relationship and the behavior characteristics, associating the internal network topology diagram with the external network topology diagram to obtain a topology structure model; calculating the association weights of the network nodes based on the topology structure model and the behavior characteristics, and constructing a behavior association network of the network nodes based on the association weights, wherein the behavior association network is used to characterize the behavior relationship between the network nodes; based on the association weights, reversely deducing from the target node to obtain an attack path to determine the attack source, wherein the target node is the attacked network node.
[0007] Optionally, the associating the internal network topology map with the external network topology map according to the connection relationship and the behavior characteristics to obtain a topology structure model specifically includes: Based on the connection relationship and the behavior characteristics, a time-series-based dependency matrix is constructed to analyze the dependency relationship between the internal network nodes and the external network nodes, wherein the dependency relationship includes direct connection dependency and multi-hop connection dependency; an association topology graph of the network nodes is generated according to the dependency relationship; based on the association topology graph, the topology structure model is constructed through a preset multi-level modeling method.
[0008] Optionally, calculating the association weights of the network nodes based on the topological structure model and the behavior characteristics, and constructing a behavior association network of the network nodes based on the association weights specifically includes: Extract the association features of the network nodes from the topological structure model; based on the association features, obtain the behavior pattern of the network nodes through a preset analysis model, and the behavior pattern at least includes normal communication behavior, abnormal communication behavior and dependency behavior; calculate the association weight according to the association features and the behavior pattern, and the association weight includes direct association weight, indirect association weight and dynamic adjustment weight; construct a behavior association network based on the association weight, in which the node represents the network node, the edge represents the connection relationship, and the weight of the edge represents the association strength of the connection relationship.
[0009] Optionally, calculating the association weight according to the association feature and the behavior pattern specifically includes: The association weight is calculated using a first calculation formula; the first formula is: Among them, W final (i, j, t) is the association weight between network node i and network node j at time t, W d (i,j) is the direct association weight between network node i and network node j, is the indirect association weight between network node i and network node j, P(i,j) is the set of intermediate network nodes in all possible paths between network node i and network node j, and W d (i,k) and W d (k,j) is the direct association weight of each intermediate node k, L(i,j) is the path length between network node i and network node j, ΔB k (k) is the observed behavior characteristic value of the intermediate network node k, ΔB(i,j,t) is the dynamic behavior deviation between network nodes i and network nodes j at time t, (1+δ·ΔB(i,j,t) is the dynamic behavior adjustment factor, λ1 is the fusion coefficient of the direct association weight, λ2 is the fusion coefficient of the indirect association weight, and δ is the dynamic adjustment factor.
[0010] Optionally, based on the association weight, reverse deduction is performed from the target node to obtain an attack path to determine the attack source, specifically including: In the behavior association network, a first network node directly associated with the target node and a second network node indirectly associated with the target node are determined according to the association weight; the timing characteristics of the target node, the first network node and the second network node are obtained; in the behavior association network, the upstream propagation relationship between the first network node and the second network node is identified based on the timing characteristics, and an association propagation network of the target node is constructed; in the association propagation network, the priority score of each of the first network node and each of the second network node is calculated by a preset priority scoring algorithm; based on the priority score, multiple candidate attack paths are generated by a preset heuristic search strategy; the credibility scores of all the candidate attack paths are calculated, and the candidate attack path with the highest credibility score is determined as the attack path to determine the attack source.
[0011] Optionally, in the behavior association network, identifying the upstream propagation relationship between the first network node and the second network node based on the time series feature and constructing the association propagation network of the target node specifically includes: Based on the timing characteristics, determine the first timing relationship between the target node and the first network node, and the second timing relationship between the first network node and the second network node; determine the upstream propagation relationship of the target node according to the first timing relationship and the second timing relationship; based on the upstream propagation relationship and the association weight, construct an associated propagation network of the target node.
[0012] Optionally, after obtaining the attack path by reverse deducing from the target node based on the association weights in the behavior association network to determine the attack source, the method further includes: The behavior data of the attack source is obtained, and the behavior characteristics of the attack source are extracted from the behavior data; the behavior characteristics of the attack source are matched with a preset attack pattern library through a behavior matching algorithm to obtain a matching value; if the matching value is greater than or equal to a preset matching threshold, the attack source is determined to be a real attack source; if the matching value is less than the preset matching threshold, the attack path is redetermined based on the credibility score to redetermine the attack source.
[0013] In a second aspect of the present application, a network attack tracing system based on internal and external network topology node analysis is provided, including: an acquisition module, used to acquire a connection relationship and behavior characteristics between an internal network node and an external network node, the internal network topology map including the internal network node, and the external network topology map including the external network node; An association module, used to associate the internal network topology map with the external network topology map according to the connection relationship and the behavior characteristics to obtain a topology structure model; A construction module, used to calculate the association weights of the network nodes based on the topological structure model and the behavior characteristics, and to construct a behavior association network of the network nodes based on the association weights, wherein the behavior association network is used to characterize the behavior relationships between the network nodes; The inversion module is used to reversely deduce the attack path from the target node based on the association weight to determine the attack source, and the target node is the attacked network node.
[0014] In the third aspect of the present application, an electronic device is provided, including a processor, a memory, a user interface and a network interface, the memory is used to store instructions, the user interface and the network interface are both used to communicate with other devices, and the processor is used to execute the instructions stored in the memory so that the electronic device executes any one of the methods described above.
[0015] In a fourth aspect of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores instructions, and when the instructions are executed, any of the methods described above is executed.
[0016] In summary, one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. By associating the topological structures of internal and external networks, the limitations of a single network perspective can be avoided, and the internal and external network nodes in the attack propagation path and the behavioral characteristics of the internal and external network nodes can be integrated into a unified model. Based on the calculation of association weights, the behavioral association strength between nodes can be quantified, and the importance of different nodes in attack propagation can be distinguished, thereby effectively screening out possible attack paths. And by reversely deducing the attack path in the behavioral association network, the association weights and behavioral characteristics in the multi-hop propagation path are integrated to identify the path that best fits the attack mode and locate the real attack source. This solution can not only fully integrate the connection relationship between internal and external networks and reveal hidden propagation paths in complex network environments, but also trace network attacks through quantitative analysis and reverse deduction of association weights, thereby improving the accuracy of network attack tracing.
[0017] 2. By analyzing the dependency relationship between internal and external network nodes based on the time-series dependency matrix, the problem of inaccurate association modeling caused by the complexity of multi-hop connections between nodes and dynamic timing characteristics in traditional network topology analysis is solved. By distinguishing between direct connection dependencies and multi-hop connection dependencies, a more comprehensive network node association topology map is generated, and a topology structure model is constructed using a preset multi-level modeling method, achieving accurate association between internal and external network topologies in complex network environments. The accuracy of network node dependency analysis and the expressiveness of topology structure models are improved, providing a high-quality data foundation for association weight calculation and attack path identification in subsequent attack tracing, thereby enhancing the comprehensiveness and reliability of network security threat analysis.
[0018] 3. By extracting the association features of network nodes from the topological structure model and combining the preset analysis model to determine the behavior patterns of network nodes (including normal communication behavior, abnormal communication behavior and dependency behavior), the problem of inaccurate weight calculation caused by the diversity of node behavior and dynamic changes in association relationships in complex networks is solved. By designing an association weight calculation formula that combines direct association weights, indirect association weights and dynamically adjusted weights, the direct connection between network nodes, the influence of intermediate nodes in the path and the deviation of dynamic behavior are comprehensively considered to achieve multi-dimensional quantification of the strength of association between nodes. The further constructed behavioral association network characterizes the strength and dynamic changes of the behavioral relationship between network nodes with nodes, edges and edge weights, which improves the ability to accurately model complex network behaviors and the ability to analyze dynamic associations. This method provides an accurate association weight basis for attack path identification and attack source location, and enhances the comprehensiveness and real-time nature of network attack tracing. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a flow chart of a network attack source tracing method based on internal and external network topology node analysis in an embodiment of the present application; Figure 2It is a structural diagram of a network attack tracing system based on internal and external network topology node analysis in an embodiment of the present application; Figure 3 It is a schematic diagram of the structure of an electronic device in an embodiment of the present application.
[0020] Explanation of the reference numerals: 201, acquisition module; 202, association module; 203, construction module; 204, inversion module; 205, verification module; 301, processor; 302, communication bus; 303, user interface; 304, network interface; 305, memory. DETAILED DESCRIPTION
[0021] In order to enable technicians in this field to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments.
[0022] In the description of the embodiments of the present application, words such as "for example" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "for example" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "for example" or "for example" is intended to present related concepts in a specific way.
[0023] In the description of the embodiments of the present application, the meaning of the term "multiple" refers to two or more. For example, multiple systems refer to two or more systems, and multiple screen terminals refer to two or more screen terminals. In addition, the terms "first" and "second" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance or implicitly indicating the indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. The terms "include", "comprise", "have" and their variations all mean "including but not limited to", unless otherwise specifically emphasized.
[0024] Figure 1 It is a flow chart of a network attack tracing method based on internal and external network topology node analysis in an embodiment of the present application.
[0025] See also Figure 1 In the embodiment of the present application, the network attack tracing method based on internal and external network topology node analysis is applied to the server, and the method includes: S101, obtaining a connection relationship and behavior characteristics between an internal network node and an external network node, wherein the internal network topology diagram includes the internal network nodes, and the external network topology diagram includes the external network nodes; The internal network topology diagram describes the physical or logical connection relationship of the internal network nodes, and is an abstraction of the device distribution and communication path in the internal network. For example, an internal network topology diagram shows that node 192.168.1.10 is a core switch that connects multiple terminal devices, and the server node 192.168.1.100 communicates with other nodes through the switch. The external network topology diagram reflects the interaction structure between the internal network nodes and the external network nodes, as well as the possible association relationship between external nodes. For example, the external network topology diagram shows that the external nodes 8.8.8.8 and 203.0.113.5 have established communication with the internal network node 192.168.1.50, and 203.0.113.5 is also associated with other external nodes.
[0026] The connection relationship between the internal network node and the external network node is the interactive information of the actual communication between the internal network node and the external network node, including the direction, frequency, protocol type, port number, traffic characteristics, etc. of the communication. This information describes which internal network nodes have established connections with which external nodes, as well as the communication characteristics between them. The system can capture the communication data packets between the internal and external networks through network monitoring tools (such as Wireshark, Tcpdump) or traffic analysis equipment (such as firewalls, intrusion detection systems IDS), and extract the IP addresses, port numbers, protocol types (such as TCP, UDP, HTTP, HTTPS) and timestamps of the communicating parties. For example, through packet capture analysis, it was found that the internal network node 192.168.1.10 and the external network node 8.8.8.8 frequently established HTTPS sessions within a specific time period.
[0027] The behavioral characteristics of internal network nodes and external network nodes describe the behavioral patterns of internal network nodes and external network nodes during the communication process, including the communication frequency of nodes, data flow direction, protocol usage, access targets, traffic characteristics, etc. These behavioral characteristics are important bases for analyzing the association between nodes, identifying abnormal behaviors, and tracing attack paths. For internal network nodes, their behavioral characteristics can be obtained by analyzing the communication patterns in network traffic, such as the interaction frequency between nodes, the number of sent and received data packets, the communication protocols used (such as TCP, UDP, HTTP, HTTPS, etc.), and the specific target address or port number accessed. At the same time, node behaviors can also be extracted through the log records of network devices (such as firewalls, switches, routers), such as login events, file access records, or abnormal operation behaviors. For external network nodes, their behavioral characteristics are mainly identified through the analysis of internal and external traffic interaction data, including the access frequency of external nodes, data packet characteristics (such as packet size, time interval), the distribution of target ports, and whether there are data anomalies or attack behaviors (such as frequent scanning or detection operations).
[0028] After obtaining the connection relationship and behavior characteristics of the internal and external network nodes, these data need to be integrated and stored. The integration process includes mapping the connection relationship between the internal and external network nodes, associating the internal network topology with the external network topology, and combining the behavior characteristics of each node to form a complete network data set; data storage requires the selection of an appropriate storage method, such as using a relational database to store structured connection data, or using a graph database (such as Neo4j) to store network topology and node characteristics.
[0029] S102, according to the connection relationship and behavior characteristics, the internal network topology map is associated with the external network topology map to obtain a topology structure model; Specifically, based on the connection relationship and behavior characteristics, a time-series-based dependency matrix is constructed to analyze the dependency relationship between internal network nodes and external network nodes, and the dependency relationship includes direct connection dependency and multi-hop connection dependency; an association topology graph of network nodes is generated according to the dependency relationship; based on the association topology graph, a topology structure model is constructed through a preset multi-level modeling method.
[0030] Among them, the purpose of constructing a dependency matrix based on time series is to quantify the dependency relationship between the nodes in the inner network and the nodes in the outer network, and to dynamically analyze these relationships. Specifically, the dependency matrix uses nodes as the index of rows and columns, and the element value of the matrix represents the dependency strength of one node on another node. Dependencies are divided into two categories: direct connection dependency and multi-hop connection dependency. Direct connection dependency means that there is direct communication between nodes (such as a direct TCP / UDP session between inner network node A and outer network node B); multi-hop connection dependency means that there is no direct connection between nodes, but indirect communication through other nodes (such as node A is indirectly connected to node B through node C). The dependency matrix based on time series also needs to be combined with time series information, such as counting the change in dependency strength over a period of time based on the timestamp of the communication. For example, if the outer network node X frequently and highly accesses the specific port of the inner network node Y, and node Y forwards data to the inner network node Z, then the multi-hop dependency of node X on node Z and the direct dependency of node X on node Y can be recorded in the dependency matrix.
[0031] Through the constructed dependency matrix, the dependencies between internal and external network nodes can be further analyzed to quantify the degree of interaction and communication patterns between them. This analysis helps to identify key nodes and potential attack paths. For direct connection dependencies, for example, if there is direct high-frequency communication between external node M and internal node N, it can be inferred that node M has a strong dependency on N, which may be normal access behavior (such as service requests) or potential attack behavior (such as DDoS attacks). For multi-hop connection dependencies, indirect dependencies can be identified by analyzing the multi-hop paths in the dependency matrix. For example, external node A has no direct connection with internal node B, but communicates through internal node C, which indicates that node A may be using node C as a springboard to interact with B. This pattern may be a sign of an internal lateral movement attack. Through the analysis of dependencies, key transit nodes, abnormal dependencies, and even potential paths of the attack chain in the network can be identified.
[0032] After the dependency analysis is completed, it can be mapped to the association topology of the network nodes to intuitively represent the dependency and communication path between nodes. The association topology is an enhanced version of the network topology. It not only shows the connection structure of the internal and external network nodes, but also marks the weights between nodes according to the strength of the dependency (for example, communication frequency, traffic size, etc.). Specifically: the nodes in the topology include internal network nodes and external network nodes, and the attributes of the nodes can reflect their behavioral characteristics (such as high-traffic nodes, abnormal nodes). The edges between nodes represent the dependency, and the weights of the edges reflect the strength of the dependency, such as the frequency of direct connections, the transmission strength of multi-hop paths, etc. For example, in the association topology, assuming that the external node A realizes the dependency on the internal node D through the internal nodes B and C, the edges of A→B, B→C, and C→D can be marked with weights respectively to indicate the degree of indirect dependency of A on D. If A's communication behavior is abnormal (such as high-frequency access), the association topology can help identify its possible attack path.
[0033] After generating the association topology graph, it is necessary to construct a topology model through a preset multi-level modeling method in order to analyze the relationship between network nodes from different levels and granularities. The multi-level modeling method usually includes a node behavior layer, a node association layer, and a global topology layer. The node behavior layer analyzes the behavioral characteristics of a single node (such as communication frequency, traffic size, protocol type, etc.); the node association layer analyzes the direct or indirect dependencies between nodes and adjusts the weights of the edges in the topology structure based on the dependency strength; the global topology layer analyzes the overall structure of the internal and external networks from a global perspective, identifying key nodes (such as communication hubs, bottleneck nodes) and key paths (such as possible attack paths).
[0034] S103, extracting correlation features of network nodes from the topological structure model; Association features refer to the direct or indirect association properties between network nodes in the topology model. These features usually include communication frequency, data traffic, protocol type, path dependency, and multi-hop association. Specifically, the process of extracting association features needs to combine the information of nodes and edges in the topology model to analyze the interaction intensity, communication mode, and dependency between nodes. For example, in the topology model, if there is high-frequency direct communication between nodes A and B (such as 1,000 connections per day), the direct association features of nodes A and B can be extracted, including communication frequency and traffic size; at the same time, if node A communicates indirectly with node D through node C, the multi-hop dependency features of nodes A and D can be extracted.
[0035] S104, based on the correlation characteristics, obtain the behavior pattern of the network node through a preset analysis model, the behavior pattern at least including normal communication behavior, abnormal communication behavior and dependency behavior; In step S104, based on the extracted network node association features, the communication behavior of the node is classified and identified through a preset behavior analysis model, thereby obtaining the behavior pattern of the network node. The construction of the preset analysis model is the basis for identifying the behavior pattern of the network node. It can combine rule matching, statistical analysis and machine learning algorithms to accurately classify node behavior. Through the rule matching model, it is possible to quickly detect whether the node behavior conforms to the normal mode according to the predefined communication rules (such as access frequency threshold or port whitelist); with the help of the statistical analysis model, it is possible to identify abnormal behaviors that deviate from the normal range by calculating the mean and deviation values of features such as communication frequency and traffic; at the same time, using machine learning models (such as classification models or clustering models) can more efficiently classify complex node behavior patterns, such as distinguishing normal access from potential malicious behavior.
[0036] During the analysis process, normal communication behavior refers to the expected network node behavior that follows conventional communication rules, usually manifested as a stable communication pattern and reasonable traffic characteristics. For example, internal network nodes periodically access external servers to synchronize data, or work terminals access external resources through common protocols such as HTTP and HTTPS. These are all normal communication behaviors. Classifying normal communication behaviors through analysis models can not only reduce the false alarm rate, but also lay a baseline for the detection of abnormal behaviors. For example, node A accesses an external server 50 times a day through the HTTPS protocol and the traffic is evenly distributed. This behavior characteristic conforms to the normal pattern and can therefore be classified as normal communication behavior.
[0037] Abnormal communication behavior refers to behavior that deviates from the normal communication pattern, usually manifested as high-frequency communication, abnormal port access, data traffic surge, or communication during abnormal time periods. The preset analysis model can quickly locate these abnormal behaviors by comparing with normal behavior characteristics, combining rule thresholds and statistical deviations. For example, if a node initiates connection attempts to port 22 (SSH) of a large number of external IP addresses in a short period of time, it may indicate a brute force attack; or if the node communication frequency suddenly surges from 50 times a day to 1,000 times a day, and occurs during the midnight period, it may indicate that the node has been controlled and is involved in malicious activities.
[0038] In addition to normal and abnormal communication behaviors, dependency behaviors between nodes also need to be identified through analysis models. Dependency behaviors describe direct or indirect communication dependencies between nodes, such as multi-hop communication paths established through intermediate nodes, or the dependency of certain nodes on key service nodes. These dependency characteristics can be extracted by analyzing the paths and interactions between nodes in the topology model. For example, node A communicates with external node D through intermediate node B, forming a multi-hop dependency relationship of A→B→D; or node B, as the communication hub of the network, connects multiple internal and external nodes, indicating that node B has a high importance in the network.
[0039] S105. Calculate association weights according to association characteristics and behavior patterns, where the association weights include direct association weights, indirect association weights, and dynamic adjustment weights; Specifically, the association weight is calculated using the first calculation formula; the first formula is: Among them, W final (i,j,t) is the association weight between network node i and network node j at time t, W d (i,j) is the direct association weight between network node i and network node j, is the indirect association weight between network node i and network node j, P(i,j) is the set of intermediate network nodes in all possible paths between network node i and network node j, and W d (i,k) and W d (k,j) is the direct association weight of each intermediate node k, L(i,j) is the path length between network node i and network node j, ΔB k (k) is the observed behavior characteristic value of the intermediate network node k, ΔB(i,j,t) is the dynamic behavior deviation between network nodes i and network nodes j at time t, (1+δ·ΔB(i,j,t) is the dynamic behavior adjustment factor, λ1 is the fusion coefficient of the direct association weight, λ2 is the fusion coefficient of the indirect association weight, and δ is the dynamic adjustment factor.
[0040] Among them, Wd (i, j) represents the direct association weight between network node i and network node j, which is calculated based on the communication characteristics and behavior characteristics of the two network nodes. The formula is W d (i,j)=α·C f (i,j)+β·T f (i,j)+γ·R f (i,j)+θ·S(B(i),B(j)), where, C f (i,j) is the communication frequency between network node i and network node j, T f (i,j) is the data flow between network node i and network node j, R f (i,j) is the response delay between network node i and network node j, It represents the similarity of the behavior characteristics between network node i and network node j, α, β, γ, θ are weight coefficients, and α+β+γ+θ=1.
[0041] For direct association weights, direct associations between network nodes refer to the strength of the connection between two network nodes, such as the frequency of communication, number of interactions, or weight between them. This part of the weight directly reflects the closeness of the connection between the two network nodes and is the basis of the final result. In order to control the importance of direct associations in the overall calculation, its influence can be adjusted through an adjustment parameter. In this way, the priority of direct associations can be determined according to the application scenario, such as increasing its weight in networks with direct interactions.
[0042] For indirect association weight, in real networks, there may not be a direct connection between two network nodes, but they may be indirectly related through other nodes. For example, network node A and network node B may not have a direct connection, but an indirect relationship is established through network node C. The calculation of this part needs to consider path weight, path length and node stability.
[0043] The relationship between network nodes is not static, but will be adjusted dynamically over time and with changes in behavior. For example, the frequency of interaction between two network nodes may increase or decrease over time, and the behavioral characteristics of network nodes may fluctuate abnormally. These changes will affect the strength of the association between network nodes. By analyzing the behavioral changes of two network nodes at a specific time, the association weight between network nodes can be dynamically adjusted to make the calculation results more in line with the actual situation.
[0044] S106, constructing a behavior association network based on the association weights, in which a node represents a network node, an edge represents a connection relationship, and an edge weight represents an association strength of the connection relationship; In a behavior association network, nodes represent specific entities in the network, such as servers, terminal devices, external hosts or intermediate routers in the intranet, and edges represent the communication or interaction relationship between these entities. Each edge not only represents a simple connection relationship, but also quantifies the strength of the relationship through a weight value, so that the behavior association network can more intuitively reflect the interaction characteristics between nodes. For example, the edge between intranet node A (192.168.1.10) and external node B (8.8.8.8) indicates that there is a communication relationship between the two, and the weight of the edge is determined based on factors such as communication frequency, traffic, and protocol, thereby reflecting the closeness of the relationship.
[0045] The edge weights in the behavioral association network are derived from the extraction of association features and the identification of behavioral patterns, and specifically include direct association weights, indirect association weights, and dynamic adjustment weights. The direct association weight is calculated based on the frequency, traffic size, and protocol type of direct communication between nodes, reflecting the intensity of direct interaction between two nodes; the indirect association weight is calculated by analyzing the dependencies on multi-hop paths, and is used to quantify the indirect interaction relationship between nodes; the dynamic adjustment weight is analyzed through time series to analyze the changes in the association relationship between nodes and capture dynamic behavioral characteristics. By combining these weights, the actual strength of the node connection relationship can be more comprehensively reflected. For example, the direct association weight between node A and node B is 0.8, and the multi-hop dependency weight is 0.6. If the communication frequency surges in a certain period of time, the dynamic adjustment weight may further increase the total weight of the two nodes.
[0046] In a behavior association network, the weight of the edge directly affects the results of network analysis. High-weight edges indicate frequent communication and strong dependence between nodes, which are usually key paths or core interaction links for business operations; low-weight edges indicate weak or sporadic interactions between nodes, which may have little impact on the overall network. By analyzing edge weights, we can identify key interaction relationships in the network and paths that need to be protected. For example, the edge weight between node A and node B is 0.9, indicating that the two communicate frequently and are core business paths; while the edge weight between node C and node D is only 0.2, indicating that their interaction is an occasional connection and has little impact on the overall network.
[0047] The introduction of dynamic weight adjustment enables the behavior association network to timely reflect the changes in the association relationship between nodes in the network, especially the ability to capture abnormal behaviors and emergencies is greatly enhanced. When the communication frequency between certain nodes suddenly increases, the traffic surges, or the access port is abnormal, the dynamic weight adjustment will increase the weight of the edge accordingly to highlight these abnormal behaviors. For example, the communication frequency between node A and node B is usually 50 times a day, but one day it suddenly rises to 1000 times, and it occurs during non-working hours. At this time, the dynamic weight adjustment will increase the weight of the edge from 0.8 to 1.0, thereby prompting network managers to pay attention to the abnormal behavior.
[0048] The behavior association network provides structured support for network security analysis and optimization through the comprehensive display of nodes, edges and weights. Its application is mainly reflected in anomaly detection, key path analysis and correlation mining. By analyzing the distribution and dynamic changes of edge weights, abnormal communication paths can be identified. For example, a sudden increase in the weight of an edge indicates that there may be malicious traffic; by identifying high-weight nodes and edges, key communication links or dependent nodes can be located, the network structure can be optimized and protection strategies can be formulated; through correlation mining, multi-hop dependency paths between nodes can be revealed and potential hidden communication links can be identified. For example, the behavior association network analysis found that node A is a dependency hub for multiple terminals, and its edge weight is generally high, indicating that A is a key node and needs to be protected. For example, in a behavior association network, the edge weight of node A and node B is 0.9, indicating that the communication between A and B is very frequent and the dependence is strong; while the edge weight of node C and node D is 0.2, indicating that the interaction between them is weak or sporadic. If the edge weight of node A and node B suddenly rises to 1.0 one day, it may be necessary to further analyze whether there is abnormal behavior.
[0049] S107, based on the association weight, reversely deduce from the target node to obtain the attack path to determine the attack source, and the target node is the attacked network node; Specifically, in a behavior association network, a first network node directly associated with a target node and a second network node indirectly associated with the target node are determined according to association weights; timing features of the target node, the first network node and the second network node are obtained; in the behavior association network, the upstream propagation relationship between the first network node and the second network node is identified based on the timing features, and an association propagation network of the target node is constructed; in the association propagation network, the priority scores of each first network node and each second network node are calculated by a preset priority scoring algorithm; based on the priority scores, multiple candidate attack paths are generated by a preset heuristic search strategy; the credibility scores of all candidate attack paths are calculated, and the candidate attack path with the highest credibility score is determined as the attack path to determine the attack source.
[0050] Among them, in the behavior association network, according to the association weight, first determine the first network node that is directly associated with the target node and the second network node that is indirectly associated with the target node through a multi-hop path. The directly associated first network node refers to the node that has direct communication or interaction with the target node, usually connected by a high-weight edge; the indirectly associated second network node is the node that has a multi-hop dependency relationship with the target node through an intermediate node, and the size of the association weight reflects the intensity of its indirect influence. For example, if the target node is server A (192.168.1.10), the first network node directly associated with it may be client B (192.168.1.20), and its edge weight is 0.9; and the second network node indirectly associated with A through the intermediate node C (192.168.1.30) may be the external host D (203.0.113.5), and its indirect association weight is 0.7.
[0051] After determining the directly associated nodes and indirectly associated nodes of the target node, the time series features of these nodes are further extracted to analyze the propagation relationship between them. Time series features refer to the time sequence of communication behaviors between nodes, the change pattern of communication frequency over time, etc., which can reflect the propagation path of attack behaviors. For example, attack behaviors usually have a time sequence, starting from the attack source and gradually spreading to the target node. Assume that the target node A starts to receive a large amount of malicious traffic at 10:00:00. The time series analysis shows that node B starts to communicate with A at 09:59:30, and node D communicates with node B for the first time at 09:58:00. This time sequence indicates that the attack may spread from D to B and then reach A.
[0052] In the behavior association network, based on the timing characteristics of the target node, the first network node and the second network node, the communication and propagation order between the nodes is analyzed to identify the upstream propagation relationship of each node and construct an associated propagation network of the target node.
[0053] Specifically, based on the timing characteristics, determine the first timing relationship between the target node and the first network node, and the second timing relationship between the first network node and the second network node; determine the upstream propagation relationship of the target node according to the first timing relationship and the second timing relationship; and construct an associated propagation network of the target node based on the upstream propagation relationship and the associated weight.
[0054] Among them, the first time sequence relationship between the target node and the first network node is extracted based on the time sequence of the communication behavior. The first time sequence relationship reflects whether the first network node has communicated with the target node before receiving the data or traffic, as well as the time sequence and intensity of the communication. In the network attack scenario, the first network node is usually the node that directly interacts with the target node, and the attack traffic may reach the target node directly through these nodes. By analyzing the communication time between the two nodes, it can be determined whether the first network node may be the direct source of the attack propagation. Assume that the target node A is a server (192.168.1.10) and the first network node B is a client (192.168.1.20). The time sequence characteristics show that node B established a connection with node A at 10:00:00 and subsequently sent a large amount of data to A, while node A began to behave abnormally at 10:00:01. Based on this time sequence analysis, it can be determined that node B has a first time sequence relationship with node A.
[0055] The second timing relationship between the first network node and the second network node is determined by analyzing whether the second network node initiates communication earlier than the first network node in time. The second timing relationship reflects whether the attack may propagate to the first network node through the second network node and then to the target node. By analyzing the communication time sequence between these nodes, the upstream propagation chain of the attack can be further inferred. If the communication time of the second network node is earlier than that of the first network node and there is a multi-hop association, it can be determined that there is a propagation relationship between the two. In the above scenario, the first network node B (192.168.1.20) received a communication request from the second network node D (203.0.113.5) at 09:59:30, and the characteristics of this communication request (such as traffic, port, etc.) are highly similar to the subsequent communication behavior of B to the target node A. According to the time sequence, it is determined that node D has a second timing relationship with node B, that is, the attack may propagate from D to B.
[0056] Based on the first and second temporal relationships, the upstream propagation relationship of the target node is determined by comprehensively analyzing the time sequence, communication characteristics, and association weights between nodes. The upstream propagation relationship is used to describe the potential propagation path from the target node to the attack source, including direct propagation and indirect propagation. When calculating the propagation relationship, it is necessary to verify whether the temporal characteristics meet the time sequence logic, and at the same time, the credibility of the propagation path is evaluated in combination with the association weight. For example, if the temporal characteristics of a path are logical and the association weight is high, the path is more likely to be the actual propagation path. According to the first temporal relationship (B→A) and the second temporal relationship (D→B), it can be inferred that the upstream propagation relationship of the target node A is D→B→A, that is, the attack may be initiated from node D, passed through node B and finally transmitted to the target node A.
[0057] After determining the upstream propagation relationship of the target node, the associated propagation network of the target node is constructed by combining the association weights in the behavior association network. The associated propagation network is a subnetwork with the target node as the core, in which the weight of each edge represents the communication strength or dependency between nodes, and each node represents an entity involved in the propagation. By comprehensively considering the temporal characteristics and association weights of the upstream propagation relationship, the possible attack propagation path of the target node can be accurately drawn. The associated propagation network not only shows the possible direction of attack propagation, but also provides a basis for subsequent attack path analysis. When constructing the associated propagation network of the target node A, it is known that the association weight of node D→B is 0.8, the association weight of node B→A is 0.9, and the temporal relationship is consistent. Therefore, nodes D, B and A are connected to form a propagation path D→B→A, in which the weights of each edge are 0.8 and 0.9 respectively. In addition, if node C has a direct propagation relationship with node A and the association weight is 0.5, it can be added to the associated propagation network as another possible path.
[0058] Time series features include the time when the communication occurs, the change pattern of communication intensity over time, the order of communication, etc. These features can help infer the propagation path of the attack. By combining the association weight and time sequence, it is possible to determine whether the communication has the possibility of attack propagation, and connect the relevant nodes to form a propagation chain. The associated propagation network is a subgraph with the target node as the core, which contains all possible upstream nodes and their propagation paths. Assuming that the target node A receives a large amount of malicious traffic at 10:00:00, the time series analysis shows that node B initiated communication with A at 09:59:30, and node D communicated with node B at 09:58:00. Through this time sequence, it can be identified that D→B→A is a possible propagation path. The constructed associated propagation network includes nodes A, B, D and their propagation paths.
[0059] In the associated propagation network, each first network node and second network node is prioritized by a preset priority scoring algorithm to evaluate its possibility as an attack source. The preset priority scoring algorithm comprehensively considers the following factors: timing characteristics, association weights, behavior patterns, node reachability, and propagation path complexity. Specifically, the timing characteristics are used to determine whether the node has participated in the communication earlier in the attack propagation chain; the association weight reflects the communication intensity or dependency between nodes. The higher the weight, the more likely the node is an important node in the propagation chain; the behavior pattern analysis (based on the result of the aforementioned step S104) helps to evaluate whether the communication behavior of the node is abnormal, such as whether there is abnormal traffic or abnormal port access; the node's reachability determines its possibility as a propagation transit or attack hub by analyzing the node's position in the network topology; the propagation path complexity is used to evaluate whether the node's associated path conforms to the propagation law of the attack, such as the priority of the short path may be higher. The priority score is usually calculated using a weighted formula, which is expressed as follows: priority score = α × timing feature score + γ × behavior pattern score + δ × node reachability score + ε × propagation path complexity score, where α, γ, δ, and ε are weight parameters that are adjusted based on the specific network environment or attack characteristics to ensure the rationality of the scoring results.
[0060] In the associated propagation network, based on the priority score of the node, a preset heuristic search strategy is used to generate candidate attack paths. The heuristic search strategy combines the node priority score, temporal features and associated weights to generate a propagation chain from the target node to the upstream node in a step-by-step exploration manner. The core of the heuristic search is to give priority to nodes with high priority scores during the search process to quickly narrow the search scope and avoid ineffective exploration of low-priority nodes and unreasonable paths. Specifically, the target node is initialized as the search end point, starting from the directly associated nodes of the target node, and the path is gradually extended to the upstream nodes; in each step of the search, the candidate nodes are screened based on the priority score, and the nodes with higher scores and the paths extended from them are explored first; the rationality of each extended path is evaluated in real time, including the coherence of the temporal features in the path, the total associated weight and the overall complexity of the path; the search depth or the number of path hops is limited to avoid generating too long paths and ensure the search efficiency. Output multiple candidate paths that meet the screening conditions, each candidate path represents a possible attack propagation chain.
[0061] At the same time, the system will dynamically evaluate the rationality of the candidate paths to ensure that the generated candidate paths are coherent in time sequence, of moderate length and with sufficiently high associated weights. In addition, the heuristic search will give priority to propagation chains with lower path complexity, that is, paths with fewer hops and more concentrated node priority scores.
[0062] Optional, in Figure 1After step S107 of the illustrated embodiment, the following steps may be performed: Obtain the behavior data of the attack source and extract the behavior characteristics of the attack source from the behavior data; match the behavior characteristics of the attack source with the preset attack pattern library through the behavior matching algorithm to obtain the matching value; if the matching value is greater than or equal to the preset matching threshold, the attack source is determined to be the real attack source; if the matching value is less than the preset matching threshold, the attack path is re-determined based on the credibility score to re-determine the attack source.
[0063] After determining the attack source, first obtain the behavior data of the attack source. Behavioral data refers to the communication behavior characteristics of the attack source node in the network, including but not limited to communication frequency, traffic size, access port, communication protocol used, data packet content characteristics, etc. These data can be collected through network traffic monitoring tools, log analysis systems, or traffic capture tools. The acquisition of behavioral data is the basis for subsequent analysis and can help identify the specific behavioral characteristics of the attack source. Assume that node D is initially identified as the attack source, and its behavioral data includes a large number of request packets sent to the internal server. The target port of the packet is 3389 (Remote Desktop Protocol port), the communication frequency suddenly increases in a short period of time, and the traffic contains abnormal encrypted data characteristics.
[0064] After obtaining the behavior data of the attack source, the behavior features of the attack source are extracted from it through the feature extraction algorithm. Behavioral features refer to key attributes that can reflect the attack behavior of the node, such as abnormal communication frequency, specific port number, abnormal traffic pattern, abnormal packet header information or content characteristics of the data packet. These features are usually significant signs of attack behavior and can be matched with known attack patterns. Feature extraction can use methods such as statistical analysis, machine learning or deep learning.
[0065] The behavior matching algorithm is used to match the extracted attack source behavior features with the preset attack pattern library, and the matching value is calculated. The attack pattern library is a pre-built collection of known attack behavior features, such as the behavior patterns of DDoS attacks, lateral movement, data leakage, etc. The behavior matching algorithm can adopt a variety of methods, including rule-based matching algorithms (such as regular expression matching), similarity algorithms (such as cosine similarity, Euclidean distance), or machine learning classification algorithms. The matching value is a quantitative score of the similarity between the attack source behavior and a pattern in the attack pattern library. The higher the matching value, the closer the attack source behavior is to the attack pattern.
[0066] The authenticity of the attack source is determined by comparing the match value with the preset match threshold. If the match value is greater than or equal to the preset match threshold (such as 0.9), the attack source is determined to be a real attack source; if the match value is less than the preset match threshold, it indicates that the currently determined attack source may be misjudged, and the attack path needs to be re-analyzed to locate the new attack source. Through this judgment mechanism, misjudgments can be effectively reduced and the accuracy of attack source location can be improved.
[0067] When the matching value is less than the preset matching threshold, it indicates that the current attack source may be misjudged. In this case, it is necessary to re-analyze the attack path and re-determine the attack source based on the credibility score. The re-analysis process includes re-evaluating the node priority score, timing characteristics, and association weights in the associated propagation network, generating new candidate attack paths, and calculating new credibility scores to determine new attack paths and attack sources. This process can dynamically adjust the attack source location results to ensure the accuracy of the final results. For example, if the matching value of node D is 0.7, after recalculating the credibility score, it is found that another candidate attack path E→C→A has a higher credibility score, and the priority score and behavior characteristics of node E have a matching value of 0.92 (greater than the matching threshold) with the attack pattern library. Therefore, the attack path is re-determined to be E→C→A, and node E is determined as the new attack source.
[0068] See also Figure 2 , is a schematic diagram of the structure of a network attack tracing system based on internal and external network topology node analysis provided in an embodiment of the present application. The network attack tracing system based on internal and external network topology node analysis 200 specifically includes: An acquisition module 201 is used to acquire a connection relationship and behavior characteristics between an internal network node and an external network node, wherein the internal network topology diagram includes the internal network nodes, and the external network topology diagram includes the external network nodes; An association module 202 is used to associate the internal network topology map with the external network topology map according to the connection relationship and the behavior characteristics to obtain a topology structure model; A construction module 203 is used to calculate the association weights of the network nodes based on the topological structure model and the behavior characteristics, and to construct a behavior association network of the network nodes based on the association weights, wherein the behavior association network is used to characterize the behavior relationships between the network nodes; The inversion module 204 is used to reversely deduce the attack path from the target node based on the association weight to determine the attack source, and the target node is the attacked network node.
[0069] Optionally, the association module 202 is specifically configured to: Based on the connection relationship and the behavior characteristics, a time-series-based dependency matrix is constructed to analyze the dependency relationship between the internal network nodes and the external network nodes, wherein the dependency relationship includes direct connection dependency and multi-hop connection dependency; an association topology graph of the network nodes is generated according to the dependency relationship; based on the association topology graph, the topology structure model is constructed through a preset multi-level modeling method.
[0070] Optionally, the construction module 203 is specifically used for: Extract the association features of the network nodes from the topological structure model; based on the association features, obtain the behavior pattern of the network nodes through a preset analysis model, and the behavior pattern at least includes normal communication behavior, abnormal communication behavior and dependency behavior; calculate the association weight according to the association features and the behavior pattern, and the association weight includes direct association weight, indirect association weight and dynamic adjustment weight; construct a behavior association network based on the association weight, in which the node represents the network node, the edge represents the connection relationship, and the weight of the edge represents the association strength of the connection relationship.
[0071] Optionally, the construction module 203 is further specifically used for: The association weight is calculated using a first calculation formula; the first formula is: Among them, W final (i, j, t) is the association weight between network node i and network node j at time t, W d (i,j) is the direct association weight between network node i and network node j, is the indirect association weight between network node i and network node j, P(i,j) is the set of intermediate network nodes in all possible paths between network node i and network node j, and W d (i,k) and W d (k,j) is the direct association weight of each intermediate node k, L(i,j) is the path length between network node i and network node j, ΔB k (k) is the observed behavior characteristic value of the intermediate network node k, ΔB(i,j,t) is the dynamic behavior deviation between network nodes i and network nodes j at time t, (1+δ·ΔB(i,j,t) is the dynamic behavior adjustment factor, λ1 is the fusion coefficient of the direct association weight, λ2 is the fusion coefficient of the indirect association weight, and δ is the dynamic adjustment factor.
[0072] Optionally, the inversion module 204 is specifically used for: In the behavior association network, a first network node directly associated with the target node and a second network node indirectly associated with the target node are determined according to the association weight; the timing characteristics of the target node, the first network node and the second network node are obtained; in the behavior association network, the upstream propagation relationship between the first network node and the second network node is identified based on the timing characteristics, and an association propagation network of the target node is constructed; in the association propagation network, the priority score of each of the first network node and each of the second network node is calculated by a preset priority scoring algorithm; based on the priority score, multiple candidate attack paths are generated by a preset heuristic search strategy; the credibility scores of all the candidate attack paths are calculated, and the candidate attack path with the highest credibility score is determined as the attack path to determine the attack source.
[0073] Optionally, the inversion module 204 is further specifically configured to: Based on the timing characteristics, determine the first timing relationship between the target node and the first network node, and the second timing relationship between the first network node and the second network node; determine the upstream propagation relationship of the target node according to the first timing relationship and the second timing relationship; based on the upstream propagation relationship and the association weight, construct an associated propagation network of the target node.
[0074] Optionally, the system further includes a verification module 205, which is specifically used to: The behavior data of the attack source is obtained, and the behavior characteristics of the attack source are extracted from the behavior data; the behavior characteristics of the attack source are matched with a preset attack pattern library through a behavior matching algorithm to obtain a matching value; if the matching value is greater than or equal to a preset matching threshold, the attack source is determined to be a real attack source; if the matching value is less than the preset matching threshold, the attack path is redetermined based on the credibility score to redetermine the attack source.
[0075] It should be noted that: when the device provided in the above embodiment realizes its function, only the division of the above functional modules is used as an example. In actual application, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0076] This embodiment also discloses an electronic device, referring to Figure 3 The electronic device may include: at least one processor 301 , at least one communication bus 302 , a user interface 303 , a network interface 304 , and at least one memory 305 .
[0077] The communication bus 302 is used to realize the connection and communication between these components.
[0078] The user interface 303 may include a display screen (Display) and a camera (Camera). The optional user interface 303 may also include a standard wired interface and a wireless interface.
[0079] The network interface 304 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).
[0080] Among them, the processor 301 may include one or more processing cores. The processor 301 uses various interfaces and lines to connect various parts in the entire server, and executes various functions of the server and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 305, and calling data stored in the memory 305. Optionally, the processor 301 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 301 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 301, and it can be implemented separately through a chip.
[0081] Among them, the memory 305 may include a random access memory (Random Access Memory, RAM) and may also include a read-only memory (Read-Only Memory). Optionally, the memory 305 includes a non-transitory computer-readable storage medium. The memory 305 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 305 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 305 may also be optionally at least one storage device located away from the aforementioned processor 301. As Figure 3 As shown, the memory 305 as a computer storage medium may include an operating system, a network communication module, a user interface module, and an application program of a network attack tracing method based on internal and external network topology node analysis.
[0082] exist Figure 3 In the electronic device shown, the user interface 303 is mainly used to provide an input interface for the user and obtain data input by the user; and the processor 301 can be used to call the application program of the network attack tracing method based on internal and external network topology node analysis stored in the memory 305. When executed by one or more processors 301, the electronic device executes one or more methods such as those in the above-mentioned embodiments.
[0083] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all described as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the order of the actions described, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required for the present application.
[0084] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0085] In the several embodiments provided in this application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are only schematic, such as the division of units, which is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some service interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.
[0086] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0087] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0088] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory 305. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory 305 and includes several instructions for a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the various embodiments of the present application. The aforementioned memory 305 includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk.
[0089] The above are only exemplary embodiments of the present disclosure and cannot be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. After considering the disclosure of the specification, those skilled in the art will easily think of other embodiments of the present disclosure. This application is intended to cover any modification, use or adaptive change of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the technical field that are not recorded in the present disclosure. The description and examples are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.
Claims
1. A network attack tracing method based on internal and external network topology node analysis, characterized in that: Applied in a server, the method comprises: Acquire a connection relationship and behavior characteristics between an internal network node and an external network node, wherein the internal network topology diagram includes the internal network node, and the external network topology diagram includes the external network node; According to the connection relationship and the behavior characteristics, the internal network topology map is associated with the external network topology map to obtain a topology structure model; Calculating association weights of the network nodes based on the topological structure model and the behavior characteristics, and constructing a behavior association network of the network nodes based on the association weights, wherein the behavior association network is used to characterize the behavior relationships between the network nodes; Based on the association weight, the attack path is reversely deduced from the target node to determine the attack source, and the target node is the attacked network node.
2. The method according to claim 1, characterized in that The associating the internal network topology map with the external network topology map according to the connection relationship and the behavior characteristics to obtain a topology structure model specifically includes: Based on the connection relationship and the behavior characteristics, a time-series-based dependency matrix is constructed to analyze the dependency relationship between the internal network node and the external network node, wherein the dependency relationship includes direct connection dependency and multi-hop connection dependency; Generate a correlation topology graph of the network nodes according to the dependency relationship; Based on the association topology graph, the topology structure model is constructed by a preset multi-level modeling method.
3. The method according to claim 1, characterized in that: The calculating the association weights of the network nodes based on the topological structure model and the behavior characteristics, and constructing a behavior association network of the network nodes based on the association weights, specifically includes: Extracting the associated features of the network nodes from the topology structure model; Based on the association characteristics, a behavior pattern of the network node is obtained through a preset analysis model, wherein the behavior pattern at least includes normal communication behavior, abnormal communication behavior and dependency behavior; Calculating the association weight according to the association feature and the behavior pattern, wherein the association weight includes a direct association weight, an indirect association weight, and a dynamic adjustment weight; A behavior association network is constructed based on the association weights, in which nodes represent network nodes, edges represent connection relationships, and edge weights represent association strengths of the connection relationships.
4. The method according to claim 3, characterized in that: The calculating the association weight according to the association feature and the behavior pattern specifically includes: Calculate the association weight using a first calculation formula; The first formula is: Among them, W final (i, j, t) is the association weight between network node i and network node j at time t, W d (i,j) is the direct association weight between network node i and network node j, is the indirect association weight between network node i and network node j, P(i,j) is the set of intermediate network nodes in all possible paths between network node i and network node j, and W d (i,k) and W d (k,j) is the direct association weight of each intermediate node k, L(i,j) is the path length between network node i and network node j, ΔB k (k) is the observed behavior characteristic value of the intermediate network node k, ΔB(i,j,t) is the dynamic behavior deviation between network nodes i and network nodes j at time t, (1+δ·ΔB(i,j,t) is the dynamic behavior adjustment factor, λ1 is the fusion coefficient of the direct association weight, λ2 is the fusion coefficient of the indirect association weight, and δ is the dynamic adjustment factor.
5. The method according to claim 1, characterized in that The step of reversely deducing the attack path from the target node based on the association weight to determine the attack source specifically includes: Determining, in the behavior association network, a first network node directly associated with the target node and a second network node indirectly associated with the target node according to the association weight; Acquire timing characteristics of the target node, the first network node, and the second network node; In the behavior association network, the upstream propagation relationship between the first network node and the second network node is identified based on the time series feature, and the association propagation network of the target node is constructed; In the associated propagation network, calculating the priority score of each of the first network nodes and each of the second network nodes by a preset priority scoring algorithm; Based on the priority scores, generating multiple candidate attack paths through a preset heuristic search strategy; The credibility scores of all the candidate attack paths are calculated, and the candidate attack path with the highest credibility score is determined as the attack path to determine the attack source.
6. The method according to claim 5, characterized in that In the behavior association network, identifying the upstream propagation relationship between the first network node and the second network node based on the time series feature, and constructing the association propagation network of the target node specifically includes: Based on the timing characteristics, determining a first timing relationship between the target node and the first network node, and a second timing relationship between the first network node and the second network node; Determine the upstream propagation relationship of the target node according to the first timing relationship and the second timing relationship; Based on the upstream propagation relationship and the association weight, an association propagation network of the target node is constructed.
7. The method according to claim 1, characterized in that After the attack path is obtained by reverse deduction from the target node based on the association weights in the behavior association network to determine the attack source, the method further includes: Acquire behavior data of the attack source, and extract behavior features of the attack source from the behavior data; Matching the attack source behavior characteristics with a preset attack pattern library through a behavior matching algorithm to obtain a matching value; If the matching value is greater than or equal to a preset matching threshold, the attack source is determined to be a real attack source; If the matching value is less than the preset matching threshold, the attack path is redetermined based on the credibility score to redetermine the attack source.
8. A network attack tracing system based on internal and external network topology node analysis, characterized in that: include: An acquisition module, used to acquire a connection relationship and behavior characteristics between an internal network node and an external network node, wherein the internal network topology diagram includes the internal network nodes, and the external network topology diagram includes the external network nodes; An association module, used to associate the internal network topology map with the external network topology map according to the connection relationship and the behavior characteristics to obtain a topology structure model; A construction module, used to calculate the association weights of the network nodes based on the topological structure model and the behavior characteristics, and to construct a behavior association network of the network nodes based on the association weights, wherein the behavior association network is used to characterize the behavior relationships between the network nodes; The inversion module is used to reversely deduce the attack path from the target node based on the association weight to determine the attack source, and the target node is the attacked network node.
9. A network attack source tracing device based on internal and external network topology node analysis, characterized in that: include: one or more processors and memory; The memory is coupled to the one or more processors, and the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the network attack tracing device based on internal and external network topology node analysis to execute the method described in any one of claims 1-7.
10. A computer-readable storage medium comprising instructions, characterized in that: When the instruction is executed on a network attack source tracing device based on internal and external network topology node analysis, the network attack source tracing device based on internal and external network topology node analysis executes the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Attack path restoration method and apparatus
CN108696473A
Association analysis discovery method for springboard nodes
CN116743437A
APT attack detection and tracing method based on graph attention sequential network
CN117749437A
Network security threat tracing method and system based on correlation analysis
CN119324817A
Apparatus Detecting Target Node in Network Using Topology Matrix and Method thereof
KR101847965B1
Cited By
Graph storage method, device and equipment based on network target range and readable storage medium
CN120692169A