Method and device for identifying multi-layer semantic advanced threat knowledge
By building a multi-layer semantic advanced threat knowledge representation model, combining STIX and ATT&CK knowledge frameworks, the problem that the existing technology cannot effectively describe the changing network threat scenarios is solved, and the effect of comprehensively describing the knowledge information in the threat intelligence field is achieved in a multi-domain knowledge sharing and standardized scenario.
Patent Information
- Application Number
- CN202510108294.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The prior art cannot effectively respond to changeable cyber threat scenarios in a multi-domain knowledge-sharing, standardized, and knowledge model that can describe knowledge information in the threat intelligence field as comprehensive as possible.
By performing information identification and analysis processing, knowledge extraction and semantic expansion on the original data, a multi-layer semantic advanced threat knowledge representation model is built, combined with the STIX threat data element standard and the ATT&CK technology and tactical knowledge framework, a universal and practical and extensible network threat ontology knowledge model is used to build a common and practical and extensible network threat ontology knowledge model.
It has realized that in a multi-domain knowledge sharing and standardized scenario, it can describe the knowledge information in the threat intelligence field as comprehensive as possible, effectively identify cyber attack behaviors, and is suitable for complex and changeable cybersecurity fields.
Smart Images

Figure CN120017341A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular to a method and device for identifying multi-layer semantic high-level threat knowledge. Background Art
[0002] With the continuous development of network and computer technology, cyberspace has expanded on a large scale, and various network security incidents have emerged one after another with huge impacts. At the same time, network security information is showing an explosive growth trend. How to use these multi-source heterogeneous information to provide assistance for network security has become a research hotspot. With the demand for big data analysis, semantic technology is used to mine the correlation between multi-source data. Knowledge graphs, as a semantic network, clearly show the logical relationship between various information subjects in cyberspace and are widely used in threat event analysis. However, in the process of constructing knowledge graphs, traditional threat modeling methods are ambiguous, heterogeneous, and incomplete due to problems with technology or modeling ideas. Therefore, they cannot cope with the changing network threat scenarios in a knowledge model that is shared in multiple fields, standardized, and can describe the knowledge information in the threat intelligence field as comprehensively as possible. Summary of the invention
[0003] The present invention provides a method and device for identifying multi-layer semantic advanced threat knowledge to solve the problem that the existing knowledge model that cannot share knowledge in multiple fields, is standardized, and can describe knowledge information in the threat intelligence field as comprehensively as possible to cope with changing network threat scenarios.
[0004] In a first aspect, the present invention provides a method for identifying multi-layer semantic advanced threat knowledge, the method comprising:
[0005] Perform information identification and analysis on the original data, and perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes, and associations of threat knowledge;
[0006] A multi-layer semantic advanced threat knowledge representation model is constructed based on the entities, attributes and associations of the identified threat knowledge, wherein the multi-layer semantic advanced threat knowledge representation model is a general and practical and extensible network threat ontology knowledge model constructed by using semantic technology in combination with the STIX threat data element standard of the exponential smoothing index and the ATT&CK technical and tactical knowledge framework, and the multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model, and the high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity by taking the threat subject, attack activity, attack event, attack mode, response measure and victim that cannot be directly extracted from the original data as high-level semantic entities, and the low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity by taking the malware, infrastructure, tools, attack indicators, observable data and vulnerability that can be directly identified or extracted from the original data as low-level semantic entities;
[0007] Network attack behaviors are identified based on the constructed multi-layer semantic advanced threat knowledge representation model.
[0008] Optionally, the performing information identification and analysis processing on the original data includes: performing information identification and analysis processing on the original data to obtain threat subject information, threat event information, time information, threat intent information and tool information.
[0009] Optionally, the information identification and analysis processing of the original data further includes: information identification and analysis processing of the original data through information extraction, knowledge organization, analytical reasoning and semantic enhancement.
[0010] Optionally, the method further comprises: performing threat knowledge representation on the data processed by information identification and analysis, and performing knowledge extraction and semantic expansion based on the data represented by threat knowledge;
[0011] The threat knowledge representation is to identify the types, entity relationships and entity attributes of threat knowledge entities through a preset threat semantic model, and perform data mining, natural language processing, knowledge representation and semantic organization, semantic query, semantic expansion based on entity linking and semantic enhancement based on time series.
[0012] Optionally, the processed data is subjected to knowledge extraction and semantic expansion to identify entities, attributes and associations of threat knowledge, including: performing entity recognition, relationship extraction and semantic enhancement processing of threat knowledge on the processed data through data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning and semantic query to identify entities, attributes and associations of threat knowledge.
[0013] Optionally, constructing a multi-layer semantic high-level threat knowledge representation model includes: constructing the multi-layer semantic high-level threat knowledge representation model through entity relationship modeling, entity formalization modeling, and entity relationship formalization modeling, wherein:
[0014] The entity relationship modeling is to conduct conceptual modeling analysis on the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities;
[0015] The entity formal modeling is to design corresponding label identification for entity categories and attributes to realize the formal language description of knowledge ontology;
[0016] Establish a mapping relationship between entity relationship predicates and entity relationship labels to achieve a formal language description of ontology relationships.
[0017] Optionally, the original data includes security report data, threat intelligence data, vulnerability data, malicious sample data and APT organization data.
[0018] In a second aspect, the present invention provides a device for identifying multi-layer semantic high-level threat knowledge, the device comprising:
[0019] The parsing unit is used to perform information identification and parsing processing on the original data, and to perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes and associations of threat knowledge;
[0020] A processing unit, configured to construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes and associations of the identified threat knowledge, wherein the multi-layer semantic advanced threat knowledge representation model is a general and practical and extensible network threat ontology knowledge model constructed by using semantic technology in combination with the STIX threat data element standard of exponential smoothing index and the ATT&CK knowledge framework of tactics and techniques, and the multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model, and the high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity by taking the threat subject, attack activity, attack event, attack mode, response measure and victim that cannot be directly extracted from the original data as high-level semantic entities, and the low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity by taking the malware, infrastructure, tools, compromise indicators, observable data and vulnerability that can be directly identified or extracted from the original data as low-level semantic entities;
[0021] The identification unit is used to identify network attack behaviors based on the constructed multi-layer semantic advanced threat knowledge representation model.
[0022] Optionally, the processing unit is also used to construct the multi-layer semantic advanced threat knowledge representation model through entity relationship modeling, entity formal modeling and entity relationship formal modeling, wherein the entity relationship modeling is to conceptualize and model the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formal modeling is to design corresponding label identifiers for entity categories and attributes to realize the formal language description of the knowledge ontology; and to establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of ontology relationships.
[0023] In a third aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described methods for identifying multi-layer semantic advanced threat knowledge.
[0024] In general, the present invention proposes a multi-layer semantic advanced threat knowledge description framework. This method combines the STIX threat data element standard and the ATT&CK tactics knowledge framework, and uses semantic technology to construct a complete advanced threat knowledge framework. It establishes a relatively general network threat ontology knowledge model that is both practical and extensible, and provides a unified behavior model architecture for complex and changeable attack behaviors such as APT attacks. In this way, in a multi-domain knowledge sharing and standardized scenario, it can describe the knowledge model of threat intelligence field knowledge information as comprehensively as possible to cope with changeable network threat scenarios.
[0025] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:
[0027] Figure 1 It is a multi-layer semantic advanced threat knowledge description framework provided by an embodiment of the present invention;
[0028] Figure 2 This is the knowledge extraction and semantic expansion process provided by the embodiment of the present invention;
[0029] Figure 3 It is a multi-layer semantic advanced threat knowledge representation model provided by an embodiment of the present invention;
[0030] Figure 4 is a high-level semantic entity model provided by an embodiment of the present invention;
[0031] Figure 5 It is a low-level semantic entity model provided by an embodiment of the present invention;
[0032] Figure 6 It is a structural schematic diagram of a device for identifying multi-layer semantic advanced threat knowledge provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0033] The present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and do not limit the present invention.
[0034] In view of the fuzziness, heterogeneity and incompleteness of traditional threat knowledge modeling methods, an embodiment of the present invention provides a method for identifying multi-layer semantic high-level threat knowledge, the method comprising:
[0035] Perform information identification and analysis on the original data, and perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes, and associations of threat knowledge;
[0036] That is, the embodiment of the present invention performs information identification and analysis on the original data to obtain threat subject information, threat event information, time information, threat intent information and tool information. The original data is subjected to information identification and analysis through information extraction, knowledge organization, analytical reasoning and semantic enhancement.
[0037] In specific implementation, the method described in the embodiment of the present invention also includes: performing threat knowledge representation on the data after information identification and analysis processing, and performing knowledge extraction and semantic expansion based on the data represented by the threat knowledge; the threat knowledge representation is to identify the type, entity relationship and entity attribute of the threat knowledge entity through a preset threat semantic model, and perform data mining, natural language processing, knowledge representation and semantic organization, semantic query, semantic expansion based on entity linking and semantic enhancement based on time series.
[0038] Construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes and associations of the identified threat knowledge;
[0039] Among them, the multi-layer semantic advanced threat knowledge representation model described in the embodiment of the present invention is a universal and practical and extensible network threat ontology knowledge model constructed by using semantic technology in combination with the STIX threat data element standard of the exponential smoothing index and the ATT&CK technical and tactical knowledge framework. The multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model, and the high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity by taking the threat subject, attack activity, attack event, attack mode, response measure and victim that cannot be directly extracted from the original data as high-level semantic entities, and the low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity by taking the malware, infrastructure, tools, attack indicators, observable data and vulnerability that can be directly identified or extracted from the original data as low-level semantic entities;
[0040] In specific implementation, the construction of a multi-layer semantic high-level threat knowledge representation model in an embodiment of the present invention includes: constructing the multi-layer semantic high-level threat knowledge representation model through entity relationship modeling, entity formalization modeling, and entity relationship formalization modeling, wherein the entity relationship modeling is to conceptualize and model the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formalization modeling is to design corresponding label identifications for entity categories and attributes to realize the formal language description of the knowledge ontology; and establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of the ontology relationship.
[0041] Finally, network attack behaviors are identified based on the constructed multi-layer semantic advanced threat knowledge representation model.
[0042] That is to say, the embodiment of the present invention provides a multi-layer semantic advanced threat knowledge description framework. The present invention constructs a relatively general network threat ontology knowledge model that is both practical and extensible by adopting the modeling idea of high- and low-layer semantic separation. It is of great help in the abstract identification and extraction of attack behaviors from multi-source threat information, and can be better applied to the complex and changeable field of network security.
[0043] It should be noted that the original data described in the embodiment of the present invention includes security report data, threat intelligence data, vulnerability data, malicious sample data, APT organization data, etc. Those skilled in the art can make any settings according to actual needs, and the present invention does not make any detailed limitations on this.
[0044] The following will be combined Figure 1-Figure 5 The method described in the embodiment of the present invention is explained and illustrated in detail by a specific example:
[0045] The present invention constructs a network threat knowledge representation model based on knowledge extraction and semantic expansion of raw data, forming a multi-layer semantic advanced threat knowledge description framework, which mainly includes the following steps:
[0046] Step 1: Perform knowledge extraction and semantic expansion. Knowledge extraction and semantic expansion process the original data through information extraction technology, knowledge organization technology, analytical reasoning technology, and semantic enhancement technology, and use data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning, semantic query and other technical means to achieve entity recognition, relationship extraction and semantic enhancement of threat knowledge.
[0047] Step 2: Construct a multi-layer semantic advanced threat knowledge representation model: By combining the STIX standard for the division of network threat intelligence entities, referring to the difficulty of acquiring knowledge, the level of abstraction, and the stability over a long time and space span, the threat ontology is conceptualized and formalized to obtain a complete knowledge representation model of high-level semantic entities, low-level semantic entities, and the relationship between entities. It can also formally analyze the attribute settings of each entity so that the attributes of each entity category can meet the actual attack and defense scenarios.
[0048] In specific implementation, the construction of the multi-layer semantic advanced threat knowledge representation model specifically includes:
[0049] Step 1: Modeling high-level semantic entity classes;
[0050] That is, the threat subjects, attack activities, attack events, attack modes, response measures and victims with a higher level of abstraction that are difficult to extract directly from the original data knowledge are taken as high-level semantic entities, and the attributes of each high-level semantic entity are analyzed to form a high-level semantic entity class model.
[0051] Step 2: Modeling low-level semantic entity classes:
[0052] Specifically, an embodiment of the present invention takes malware, infrastructure, tools, attack indicators, observable data and vulnerabilities with a lower level of abstraction that can be directly identified or extracted from the acquired raw data or knowledge as low-level semantic entities, analyzes the attributes of each low-level semantic entity, and forms a low-level semantic entity class model.
[0053] Step 3: Entity relationship modeling:
[0054] Specifically, conceptual modeling and analysis are carried out on the relationships between high-level semantic entities, the relationships between low-level semantic entities, and the relationships between high-level semantic entities and low-level semantic entities.
[0055] Step 4: Formal entity modeling: that is, design unique label identifiers for entity categories and attributes to achieve a formal language description of the advanced threat knowledge ontology.
[0056] Step 5: Formal modeling of entity relationships: Considering the automated analysis and ambiguity elimination in entity relationship extraction, a mapping relationship between entity relationship predicates and entity relationship labels is established to achieve a formal language description of ontology relationships.
[0057] See also Figure 1 , is a multi-layer semantic advanced threat knowledge description framework constructed by the present invention, wherein the multi-layer semantic advanced threat knowledge description framework in the embodiment of the present invention is based on the STIX standard and the ATT&CK knowledge framework, and through knowledge extraction and semantic expansion of raw data such as security reports, threat intelligence, vulnerability data, malicious samples, etc., it identifies threat knowledge ontology, attributes, and relationships, constructs a multi-layer semantic advanced threat knowledge representation model, and realizes semantic value-added and standardized modeling of raw data.
[0058] See also Figure 2 , is a flowchart of knowledge extraction and semantic expansion of an embodiment of the present invention, that is, after acquiring the original security data, the embodiment of the present invention understands and parses the threat text information based on threat subjects, threat events, threat intentions, etc., so as to facilitate the subsequent establishment of a threat knowledge semantic model, and then based on the predefined threat semantic model and threat knowledge entities, data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning, semantic expansion based on entity linking and other technical methods are used to extract threat knowledge content, thereby realizing the association mining and semantic enhancement of threat knowledge entities, relationships, and attributes.
[0059] See also Figure 3 , is a multi-layer semantic advanced threat knowledge representation model constructed by an embodiment of the present invention. In specific implementation, the model combines the division of network threat intelligence entities in the STIX standard, divides the threat ontology into object domain, event domain, and method domain to perform conceptual modeling and formal abstraction of the threat ontology, and forms a knowledge representation model with complete high-level semantic entities, low-level semantic entities, and relationships between entities.
[0060] Furthermore, the construction of the multi-layer semantic advanced threat knowledge representation model in the embodiment of the present invention specifically includes:
[0061] First, high-level semantic entity class modeling and low-level semantic entity class modeling are performed: high-level semantic entities include threat subjects, attack activities, attack events, attack modes, response measures, and victims. The high-level semantic entity class model constructed by the present invention is as follows: Figure 4 As shown,
[0062] Threat subject refers to individuals, organizations, or entities that can execute or manipulate cyber attacks. Threat subject categories include subject category, target list, first appearance time, last appearance time, technical capabilities, motivations, action history, organizational relationships, and activity areas.
[0063] Attack activity is a way to categorize hostile behavior, describing a series of malicious activities or attacks against a specific set of targets over a period of time. Attack activity classes include attributes such as purpose, attack activity status, first appearance time, and last appearance time.
[0064] An attack event is a specific network security event, usually a malicious behavior or attack that occurs at a certain point in time. The attack event class includes attributes such as name, description, occurrence time, and impact range.
[0065] The attack pattern is based on the ATT&CK knowledge framework and describes the attack techniques and tactics used by attackers. The attack pattern class includes attributes such as attack tactics and attack techniques.
[0066] Response measures are measures taken when facing threatening behaviors or attack events. The response measure class includes attributes such as name, description, and disposal plan.
[0067] A victim is an individual, organization, or system that is directly or indirectly affected by a threat or attack. The victim class includes attributes such as name, description, identity category, industry field, and contact information.
[0068] The low-level semantic entities in the embodiment of the present invention include malware, infrastructure, tools, compromise indicators, observable data, and vulnerabilities. The low-level semantic entity class model constructed by the present invention is as follows: Figure 5 shown.
[0069] A vulnerability is a hole or weakness in a software or system that can be exploited by threat actors to carry out attacks. Vulnerability classes include attributes such as name, description, creation time, and external reference identifiers.
[0070] Infrastructure is the hardware equipment and virtual resources in cyberspace. The infrastructure class includes attributes such as name, description, infrastructure type, and tactic list.
[0071] Malware is software with malicious design and intent to perform malicious activities. Malware categories include name, description, alias, malware type, malware family, tactical list, applicable operating system, development language, applicable CPU architecture, sample, first appearance time, last appearance time and other attributes.
[0072] Tools are legitimate software that threat actors can use to carry out attacks. The tool category includes properties such as name, description, alias, source, version, purpose, applicable operating system, and applicable CPU architecture.
[0073] Compromise indicators are a set of specific signs and characteristics used to identify possible threat activities. The compromise indicator class includes attributes such as type, value, description, context, validity period, threat detection rules, etc.
[0074] Observable data is key information used to describe and record network activities in the field of network security. The observable data class includes attributes such as data type, timestamp, data content, and data format.
[0075] Then, entity relationship modeling and entity formal modeling are carried out: Among them, entity relationship modeling is divided into high-level semantic entity relationships, low-level semantic entity relationships, and high-level semantic entity and low-level semantic entity relationships according to the entity categories connected by the entity relationship. Figure 3 The lines between entities reflect the relationship between various entities.
[0076] Entity formal modeling is to design unique label identification for entity categories and attributes to achieve formal language description of advanced threat knowledge ontology. The formal modeling of entity categories is demonstrated by taking threat subject formalization as an example, as shown in Table 1.
[0077] Table 1 Example of formal modeling of entity categories
[0078]
[0079] Finally, formal entity relationship modeling is performed: considering the automated analysis and ambiguity elimination in entity relationship extraction, the entity relationships in entity relationship modeling are optimized, and a mapping relationship between entity relationship predicates and entity relationship labels is established to achieve a formal language description of the ontology relationship, as shown in Table 2.
[0080] Table 2 Entity relationship predicate and label mapping table
[0081]
[0082]
[0083] Accordingly, an embodiment of the present invention also provides a device for identifying multi-layer semantic high-level threat knowledge, see Figure 6 , the device comprises:
[0084] The parsing unit is used to perform information identification and parsing processing on the original data, and to perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes and associations of threat knowledge;
[0085] A processing unit, configured to construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes and associations of the identified threat knowledge, wherein the multi-layer semantic advanced threat knowledge representation model is a general and practical and extensible network threat ontology knowledge model constructed by using semantic technology in combination with the STIX threat data element standard of exponential smoothing index and the ATT&CK knowledge framework of tactics and techniques, and the multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model, and the high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity by taking the threat subject, attack activity, attack event, attack mode, response measure and victim that cannot be directly extracted from the original data as high-level semantic entities, and the low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity by taking the malware, infrastructure, tools, compromise indicators, observable data and vulnerability that can be directly identified or extracted from the original data as low-level semantic entities;
[0086] The identification unit is used to identify network attack behaviors based on the constructed multi-layer semantic advanced threat knowledge representation model.
[0087] Furthermore, in an embodiment of the present invention, the processing unit is also used to construct the multi-layer semantic advanced threat knowledge representation model through entity relationship modeling, entity formal modeling and entity relationship formal modeling, wherein the entity relationship modeling is to conceptualize and model the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formal modeling is to design corresponding label identifiers for entity categories and attributes to realize the formal language description of the knowledge ontology; and to establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of ontology relationships.
[0088] In general, the present invention proposes a multi-layer semantic advanced threat knowledge description framework. This method combines the STIX threat data element standard and the ATT&CK tactics knowledge framework, and uses semantic technology to construct a complete advanced threat knowledge framework. It establishes a relatively general network threat ontology knowledge model that is both practical and extensible, and provides a unified behavior model architecture for complex and changeable attack behaviors such as APT attacks. In this way, in a multi-domain knowledge sharing and standardized scenario, it can describe the knowledge model of threat intelligence field knowledge information as comprehensively as possible to cope with changeable network threat scenarios.
[0089] In addition, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method for identifying multi-layer semantic advanced threat knowledge described in any one of the method embodiments of the present invention is implemented. For details, please refer to the method embodiments of the present invention for understanding, and no detailed discussion is given here.
[0090] Although the preferred embodiments of the present invention have been disclosed for illustrative purposes, those skilled in the art will appreciate that various modifications, additions and substitutions are possible, and thus, the scope of the present invention should not be limited to the above embodiments.
Claims
1. A method for identifying multi-layer semantic advanced threat knowledge, characterized in that: include: Perform information identification and analysis on the original data, and perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes, and associations of threat knowledge; A multi-layer semantic advanced threat knowledge representation model is constructed based on the entities, attributes and associations of the identified threat knowledge, wherein the multi-layer semantic advanced threat knowledge representation model is a general and practical and extensible network threat ontology knowledge model constructed by using semantic technology in combination with the STIX threat data element standard of the exponential smoothing index and the ATT&CK technical and tactical knowledge framework, and the multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model, and the high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity by taking the threat subject, attack activity, attack event, attack mode, response measure and victim that cannot be directly extracted from the original data as high-level semantic entities, and the low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity by taking the malware, infrastructure, tools, attack indicators, observable data and vulnerability that can be directly identified or extracted from the original data as low-level semantic entities; Network attack behaviors are identified based on the constructed multi-layer semantic advanced threat knowledge representation model.
2. The method according to claim 1, characterized in that The information identification and analysis processing of the original data includes: The original data is processed for information identification and analysis to obtain threat subject information, threat event information, time information, threat intent information, and tool information.
3. The method according to claim 1, characterized in that The information identification and analysis processing of the original data also includes: The raw data is processed for information identification and analysis through information extraction, knowledge organization, analytical reasoning and semantic enhancement.
4. The method according to claim 1, characterized in that: The method further comprises: Perform threat knowledge representation on the data after information identification and analysis, and perform knowledge extraction and semantic expansion based on the data represented by threat knowledge; The threat knowledge representation is to identify the types, entity relationships and entity attributes of threat knowledge entities through a preset threat semantic model, and perform data mining, natural language processing, knowledge representation and semantic organization, semantic query, semantic expansion based on entity linking and semantic enhancement based on time series.
5. The method according to claim 1, characterized in that The processed data is subjected to knowledge extraction and semantic expansion to identify entities, attributes and associations of threat knowledge, including: Through data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning, and semantic query, the processed data is subjected to entity recognition, relationship extraction, and semantic enhancement of threat knowledge to identify the entities, attributes, and associations of threat knowledge.
6. The method according to any one of claims 1 to 5, characterized in that: The construction of a multi-layer semantic advanced threat knowledge representation model includes: The multi-layer semantic advanced threat knowledge representation model is constructed by entity relationship modeling, entity formalization modeling and entity relationship formalization modeling, wherein: The entity relationship modeling is to conduct conceptual modeling analysis on the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; The entity formal modeling is to design corresponding label identification for entity categories and attributes to realize the formal language description of knowledge ontology; Establish a mapping relationship between entity relationship predicates and entity relationship labels to achieve a formal language description of ontology relationships.
7. The method according to any one of claims 1 to 5, characterized in that: The raw data includes security report data, threat intelligence data, vulnerability data, malicious sample data and APT organization data.
8. A device for identifying multi-layer semantic advanced threat knowledge, characterized in that: The device comprises: The parsing unit is used to perform information identification and parsing processing on the original data, and to perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes and associations of threat knowledge; A processing unit, configured to construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes and associations of the identified threat knowledge, wherein the multi-layer semantic advanced threat knowledge representation model is a general and practical and extensible network threat ontology knowledge model constructed by using semantic technology in combination with the STIX threat data element standard of exponential smoothing index and the ATT&CK knowledge framework of tactics and techniques, and the multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model, and the high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity by taking the threat subject, attack activity, attack event, attack mode, response measure and victim that cannot be directly extracted from the original data as high-level semantic entities, and the low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity by taking the malware, infrastructure, tools, compromise indicators, observable data and vulnerability that can be directly identified or extracted from the original data as low-level semantic entities; The identification unit is used to identify network attack behaviors based on the constructed multi-layer semantic advanced threat knowledge representation model.
9. The device according to claim 8, characterized in that The processing unit is also used to construct the multi-layer semantic advanced threat knowledge representation model through entity relationship modeling, entity formal modeling and entity relationship formal modeling, wherein the entity relationship modeling is to conceptualize and model the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formal modeling is to design corresponding label identifiers for entity categories and attributes to realize the formal language description of the knowledge ontology; and to establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of the ontology relationship.
10. A computer-readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, the method for identifying multi-layer semantic advanced threat knowledge according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Text data-oriented threat intelligence knowledge graph construction method
CN110717049A
Network threat knowledge graph construction method based on SecBABC
CN119106141A
Consolidating structured and unstructured security and threat intelligence with knowledge graphs
US20180159876A1
Threat intelligence knowledge graph construction method and device based on mail data
WO2021136314A1
Cited By
Intelligent equipment security threat collaborative analysis method
CN120750582A