A method and apparatus for identifying multi-layered semantic advanced threat knowledge

By building a multi-layer semantic advanced threat knowledge model and combining it with the STIX and ATT&CK frameworks, we address the ambiguity and incompleteness of existing threat modeling methods, achieve a standardized and comprehensive description of network threat intelligence, and make it applicable to diverse network threat scenarios.

CN120017341BActive Publication Date: 2025-10-21NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510108294.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-10-21
Estimated Expiration
2045-01-23

AI Technical Summary

Technical Problem

Existing threat modeling methods are ambiguous, heterogeneous, and incomplete in terms of multi-domain knowledge sharing, standardization, and comprehensive description of threat intelligence domain knowledge information, making it difficult to cope with ever-changing network threat scenarios.

Method used

A multi-layer semantic advanced threat knowledge identification method is adopted, combined with the STIX threat data element standard and the ATT&CK tactics knowledge framework. By performing information identification and analysis, knowledge extraction and semantic expansion on the original data, high-level and low-level semantic entity models are constructed, and semantic technology is used to build a universal and practical network threat ontology knowledge model.

Benefits of technology

It achieves a comprehensive description of complex and changeable network threat scenarios in the context of multi-domain knowledge sharing, provides a unified behavioral model architecture, and can better identify network attack behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017341B_ABST
    Figure CN120017341B_ABST
Patent Text Reader

Abstract

The application discloses a method and device for identifying multilayer semantic advanced threat knowledge, namely, the application proposes a multilayer semantic advanced threat knowledge description framework, the method combines STIX threat data element standards and ATT&CK technique and tactics knowledge framework, utilizes semantic technology to construct a perfect advanced threat knowledge framework, establishes a set of relatively universal network threat ontology knowledge model which has practicability and expansibility, provides a unified behavior model architecture for complex and changeable attack behaviors such as APT attacks, and thus can comprehensively describe the knowledge model of threat intelligence field knowledge information in a multiregion knowledge sharing and standardized scene to cope with changeable network threat scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a method and device for identifying multi-layer semantic advanced threat knowledge. Background Art

[0002] With the continuous development of network and computer technology, cyberspace has expanded on a massive scale, and various cybersecurity incidents have emerged one after another with significant impact. At the same time, cybersecurity information is experiencing explosive growth. How to leverage this multi-source, heterogeneous information to provide support for cybersecurity has become a research hotspot. With the demand for big data analysis, semantic technology is being used to mine correlations between multi-source data. Knowledge graphs, as semantic networks, clearly display the logical relationships between various information entities in cyberspace and are widely used in threat event analysis. However, in the process of constructing knowledge graphs, traditional threat modeling methods suffer from ambiguity, heterogeneity, and incompleteness due to technical or modeling issues. Therefore, they are unable to address the ever-changing cyber threat scenarios through standardized knowledge models that share knowledge across multiple domains and can describe threat intelligence knowledge as comprehensively as possible. Summary of the Invention

[0003] The present invention provides a method and device for identifying multi-layer semantic advanced threat knowledge to solve the problem that the existing knowledge model cannot be shared in multiple fields, standardized, and can describe the knowledge information in the threat intelligence field as comprehensively as possible to cope with the changing network threat scenarios.

[0004] In a first aspect, the present invention provides a method for identifying multi-layer semantic high-level threat knowledge, the method comprising:

[0005] Perform information identification and analysis on the raw data, and perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes, and associations of threat knowledge;

[0006] A multi-layer semantic advanced threat knowledge representation model is constructed based on the entities, attributes, and associations of the identified threat knowledge. The multi-layer semantic advanced threat knowledge representation model is a general, practical, and extensible network threat ontology knowledge model constructed using semantic technology in combination with the STIX threat data element standard and the ATT&CK knowledge framework. The multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model. The high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity, which cannot be directly extracted from the original data, such as threat subjects, attack activities, attack events, attack patterns, response measures, and victims. The low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity, which can be directly identified or extracted from the original data, such as malware, infrastructure, tools, compromise indicators, observable data, and vulnerabilities.

[0007] Network attack behaviors are identified based on the constructed multi-layer semantic advanced threat knowledge representation model.

[0008] Optionally, the performing information identification and analysis processing on the original data includes: performing information identification and analysis processing on the original data to obtain threat subject information, threat event information, time information, threat intent information and tool information.

[0009] Optionally, the information identification and analysis processing of the original data further includes: information identification and analysis processing of the original data through information extraction, knowledge organization, analytical reasoning and semantic enhancement.

[0010] Optionally, the method further comprises: performing threat knowledge representation on the data after information identification and analysis processing, and performing knowledge extraction and semantic expansion based on the data represented by the threat knowledge;

[0011] The threat knowledge representation is to identify the types, entity relationships and entity attributes of threat knowledge entities through a preset threat semantic model, and perform data mining, natural language processing, knowledge representation and semantic organization, semantic query, semantic expansion based on entity linking and semantic enhancement based on time series.

[0012] Optionally, the processed data is subjected to knowledge extraction and semantic expansion to identify entities, attributes, and associations of threat knowledge, including: performing entity recognition, relationship extraction, and semantic enhancement processing of threat knowledge on the processed data through data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning, and semantic query to identify entities, attributes, and associations of threat knowledge.

[0013] Optionally, the constructing of a multi-layer semantic high-level threat knowledge representation model includes: constructing the multi-layer semantic high-level threat knowledge representation model through entity relationship modeling, entity formalization modeling, and entity relationship formalization modeling, wherein:

[0014] The entity relationship modeling is to conduct conceptual modeling analysis on the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities;

[0015] The entity formal modeling is to design corresponding label identification for entity categories and attributes to realize the formal language description of knowledge ontology;

[0016] Establish a mapping relationship between entity relationship predicates and entity relationship labels to achieve a formal language description of ontology relationships.

[0017] Optionally, the original data includes security report data, threat intelligence data, vulnerability data, malicious sample data and APT organization data.

[0018] In a second aspect, the present invention provides a device for identifying multi-layer semantic high-level threat knowledge, the device comprising:

[0019] The parsing unit is used to perform information identification and parsing on the raw data, and to extract knowledge and semantically expand the processed data to identify entities, attributes, and associations of threat knowledge;

[0020] A processing unit configured to construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes, and associations of the identified threat knowledge. The multi-layer semantic advanced threat knowledge representation model is a general, practical, and extensible network threat ontology knowledge model constructed using semantic technology in combination with the STIX threat data element standard and the ATT&CK knowledge framework. The multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model. The high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity, including threat subjects, attack activities, attack events, attack patterns, response measures, and victims that cannot be directly extracted from the original data, as high-level semantic entities. The low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity, including malware, infrastructure, tools, compromise indicators, observable data, and vulnerabilities that can be directly identified or extracted from the original data, as low-level semantic entities.

[0021] The identification unit is used to identify network attack behaviors based on the constructed multi-layer semantic advanced threat knowledge representation model.

[0022] Optionally, the processing unit is also used to construct the multi-layer semantic advanced threat knowledge representation model through entity relationship modeling, entity formal modeling and entity relationship formal modeling, wherein the entity relationship modeling is to conceptualize and analyze the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formal modeling is to design corresponding label identifiers for entity categories and attributes to realize the formal language description of the knowledge ontology; and establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of the ontology relationship.

[0023] In a third aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described methods for identifying multi-layer semantic advanced threat knowledge.

[0024] In general, the present invention proposes a multi-layer semantic advanced threat knowledge description framework. This method combines the STIX threat data element standard and the ATT&CK tactics knowledge framework, uses semantic technology to construct a complete advanced threat knowledge framework, and establishes a relatively general, practical and extensible network threat ontology knowledge model. It provides a unified behavior model architecture for complex and changeable attack behaviors such as APT attacks, so that in a standardized scenario with multi-domain knowledge sharing, it can describe the knowledge model of threat intelligence field knowledge information as comprehensively as possible to cope with changeable network threat scenarios.

[0025] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0027] Figure 1 It is a multi-layer semantic advanced threat knowledge description framework provided by an embodiment of the present invention;

[0028] Figure 2 This is the knowledge extraction and semantic expansion process provided by the embodiment of the present invention;

[0029] Figure 3 It is a multi-layer semantic advanced threat knowledge representation model provided by an embodiment of the present invention;

[0030] Figure 4 It is a high-level semantic entity model provided by an embodiment of the present invention;

[0031] Figure 5 It is a low-level semantic entity model provided by an embodiment of the present invention;

[0032] Figure 6 This is a structural diagram of a device for identifying multi-layer semantic advanced threat knowledge provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0033] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0034] To address the fuzziness, heterogeneity, and incompleteness of traditional threat knowledge modeling methods, an embodiment of the present invention provides a method for identifying multi-layer semantic high-level threat knowledge, the method comprising:

[0035] Perform information identification and analysis on the raw data, and perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes, and associations of threat knowledge;

[0036] Specifically, the present invention performs information identification and analysis on raw data to obtain threat subject information, threat event information, time information, threat intent information, and tool information. This information identification and analysis is performed on the raw data through information extraction, knowledge organization, analytical reasoning, and semantic enhancement.

[0037] In specific implementation, the method described in the embodiment of the present invention also includes: performing threat knowledge representation on the data after information identification and analysis processing, and performing knowledge extraction and semantic expansion based on the data of threat knowledge representation; the threat knowledge representation is to identify the type, entity relationship and entity attribute of threat knowledge entities through a preset threat semantic model, and perform data mining, natural language processing, knowledge representation and semantic organization, semantic query, semantic expansion based on entity linking and semantic enhancement based on time series.

[0038] Construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes and associations of the identified threat knowledge;

[0039] Among them, the multi-layer semantic advanced threat knowledge representation model described in the embodiment of the present invention is a universal, practical and extensible network threat ontology knowledge model constructed using semantic technology in combination with the STIX threat data element standard of exponential smoothing indicators and the ATT&CK technical and tactical knowledge framework. The multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model. The high-level semantic entity class model is formed by analyzing the attributes and association relationships of threat subjects, attack activities, attack events, attack patterns, response measures and victims that cannot be directly extracted from the original data as high-level semantic entities. The low-level semantic entity class model is formed by analyzing the attributes and association relationships of each low-level semantic entity as malware, infrastructure, tools, compromise indicators, observable data and vulnerabilities that can be directly identified or extracted from the original data.

[0040] In specific implementation, the embodiment of the present invention constructs a multi-layer semantic advanced threat knowledge representation model, including: constructing the multi-layer semantic advanced threat knowledge representation model through entity relationship modeling, entity formal modeling, and entity relationship formal modeling, wherein the entity relationship modeling is to conceptualize and model the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formal modeling is to design corresponding label identifications for entity categories and attributes to realize the formal language description of the knowledge ontology; and establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of the ontology relationship.

[0041] Finally, network attack behaviors are identified based on the constructed multi-layer semantic advanced threat knowledge representation model.

[0042] In other words, the embodiment of the present invention provides a multi-layer semantic advanced threat knowledge description framework. By adopting the modeling idea of ​​high- and low-layer semantic separation, the present invention constructs a relatively general, practical, and extensible network threat ontology knowledge model, which is of great help in the abstract identification and extraction of attack behaviors from multi-source threat information and can be better applied to the complex and changeable field of network security.

[0043] It should be noted that the original data described in the embodiment of the present invention includes security report data, threat intelligence data, vulnerability data, malicious sample data, APT organization data, etc. Those skilled in the art can make any settings according to actual needs, and the present invention does not make any detailed limitations on this.

[0044] The following will be combined Figure 1-Figure 5 The method described in the embodiment of the present invention is explained and illustrated in detail by taking a specific example:

[0045] The present invention constructs a network threat knowledge representation model based on knowledge extraction and semantic expansion of raw data, forming a multi-layer semantic advanced threat knowledge description framework, which mainly includes the following steps:

[0046] Step 1: Perform knowledge extraction and semantic expansion. This involves processing raw data through information extraction, knowledge organization, analytical reasoning, and semantic enhancement technologies. By leveraging data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning, and semantic query, entity recognition, relationship extraction, and semantic enhancement of threat knowledge are achieved.

[0047] Step 2: Construct a multi-layer semantic advanced threat knowledge representation model: By combining the STIX standard's classification of network threat intelligence entities, and referring to the difficulty of acquiring knowledge, the level of abstraction, and stability over a long time and space span, the threat ontology is conceptualized and formalized. This results in a complete knowledge representation model of high-level semantic entities, low-level semantic entities, and the relationships between entities. The model can also formally analyze the attribute settings of each entity, ensuring that the attributes of each entity category are consistent with actual attack and defense scenarios.

[0048] In specific implementation, the construction of a multi-layer semantic advanced threat knowledge representation model specifically includes:

[0049] Step 1: Modeling high-level semantic entity classes;

[0050] That is, the threat subjects, attack activities, attack events, attack modes, response measures and victims with a higher level of abstraction that are difficult to extract directly from the original data knowledge are taken as high-level semantic entities, and the attributes of each high-level semantic entity are analyzed to form a high-level semantic entity class model.

[0051] Step 2: Low-level semantic entity class modeling:

[0052] Specifically, an embodiment of the present invention treats malware, infrastructure, tools, compromise indicators, observable data, and vulnerabilities that have a lower level of abstraction and can be directly identified or extracted from the acquired raw data or knowledge as low-level semantic entities, analyzes the attributes of each low-level semantic entity, and forms a low-level semantic entity class model.

[0053] Step 3: Entity relationship modeling:

[0054] Specifically, conceptual modeling and analysis are conducted on the relationships between high-level semantic entities, the relationships between low-level semantic entities, and the relationships between high-level semantic entities and low-level semantic entities.

[0055] Step 4: Formal entity modeling: Design unique label identifiers for entity categories and attributes to implement a formal language description of the advanced threat knowledge ontology.

[0056] Step 5: Formal modeling of entity relationships: Considering the automated analysis and ambiguity elimination in entity relationship extraction, a mapping relationship between entity relationship predicates and entity relationship labels is established to achieve a formal language description of ontology relationships.

[0057] See also Figure 1 , which is a multi-layer semantic advanced threat knowledge description framework constructed by the present invention. The multi-layer semantic advanced threat knowledge description framework in the embodiment of the present invention is based on the STIX standard and the ATT&CK knowledge framework. It extracts knowledge and semantics from raw data such as security reports, threat intelligence, vulnerability data, and malicious samples, identifies threat knowledge ontology, attributes, and relationships, and constructs a multi-layer semantic advanced threat knowledge representation model to achieve semantic value-added and standardized modeling of raw data.

[0058] See also Figure 2 , is a flow chart of knowledge extraction and semantic expansion in an embodiment of the present invention. That is, after acquiring the original security data, the embodiment of the present invention understands and parses threat text information based on threat subjects, threat events, threat intentions, etc., to facilitate the subsequent establishment of a threat knowledge semantic model. Then, based on the predefined threat semantic model and threat knowledge entities, threat knowledge content is extracted using technical methods such as data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning, and semantic expansion based on entity linking, thereby realizing association mining and semantic enhancement of threat knowledge entities, relationships, and attributes.

[0059] See also Figure 3 , is a multi-layer semantic advanced threat knowledge representation model constructed by an embodiment of the present invention. In specific implementation, the model combines the STIX standard's division of network threat intelligence entities, divides the threat ontology into object domain, event domain, and method domain for threat ontology conceptual modeling and formal abstraction, and forms a knowledge representation model with complete high-level semantic entities, low-level semantic entities, and relationships between entities.

[0060] Furthermore, in the embodiment of the present invention, the construction of a multi-layer semantic advanced threat knowledge representation model specifically includes:

[0061] First, high-level semantic entity class modeling and low-level semantic entity class modeling are performed: high-level semantic entities include threat subjects, attack activities, attack events, attack patterns, response measures, and victims. The high-level semantic entity class model constructed by the present invention is as follows: Figure 4 As shown,

[0062] A threat actor is an individual, organization, or entity capable of executing or manipulating a cyberattack. The threat actor category includes attributes such as actor category, target list, first appearance time, last appearance time, technical capabilities, motivation, action history, organizational relationships, and activity areas.

[0063] An attack activity is a way to categorize hostile behavior, describing a series of malicious activities or attacks against a specific set of targets over a period of time. An attack activity class includes attributes such as purpose, attack activity status, first occurrence time, and last occurrence time.

[0064] An attack event is a specific network security incident, typically a malicious act or attack occurring at a specific point in time. The attack event class includes attributes such as name, description, occurrence time, and impact range.

[0065] Attack patterns are based on the ATT&CK framework and describe the attack techniques and tactics used by attackers. Attack pattern classes include attributes such as attack tactics and attack techniques.

[0066] Response measures are actions taken in response to threatening behaviors or attack events. Response measures include attributes such as name, description, and resolution plan.

[0067] A victim is an individual, organization, or system directly or indirectly affected by a threat or attack. The victim class includes attributes such as name, description, identity category, industry sector, and contact information.

[0068] The low-level semantic entities in the embodiment of the present invention include malware, infrastructure, tools, compromise indicators, observable data and vulnerabilities. The low-level semantic entity class model constructed by the present invention is as follows: Figure 5 shown.

[0069] A vulnerability is a hole or weakness in software or a system that can be exploited by threat actors to launch attacks. Vulnerability classes include attributes such as name, description, creation time, and external reference identifiers.

[0070] Infrastructure refers to the hardware devices and virtual resources in cyberspace. The infrastructure class includes attributes such as name, description, infrastructure type, and tactic list.

[0071] Malware is maliciously designed and intended software used to perform malicious activities. Malware categories include name, description, alias, malware type, malware family, tactical list, compatible operating system, development language, compatible CPU architecture, sample, first appearance time, and last appearance time.

[0072] Tools are legitimate software that threat actors can use to carry out attacks. Tool attributes include name, description, alias, source, version, purpose, compatible operating system, and compatible CPU architecture.

[0073] Indicators of Compromise are a set of specific signs and characteristics used to identify possible threat activity. An indicator of compromise class includes attributes such as type, value, description, context, expiration date, and threat detection rules.

[0074] Observable data is key information used to describe and record network activities in the field of network security. Observable data classes include attributes such as data type, timestamp, data content, and data format.

[0075] Then, entity relationship modeling and entity formal modeling are carried out: Among them, entity relationship modeling is divided into high-level semantic entity relationships, low-level semantic entity relationships, and high-level semantic entity and low-level semantic entity relationships according to the entity categories connected by the entity relationship. Figure 3 The lines between entities reflect the relationship between various entities.

[0076] Entity formal modeling is to design unique label identification for entity categories and attributes to achieve the formal language description of advanced threat knowledge ontology. The entity category formal modeling is demonstrated by taking the threat subject formalization as an example, as shown in Table 1.

[0077] Table 1 Example of formal modeling of entity categories

[0078]

[0079] Finally, the entity relationship formal modeling is performed: considering the automated analysis and ambiguity elimination in entity relationship extraction, the entity relationship in entity relationship modeling is optimized, and the mapping relationship between entity relationship predicates and entity relationship labels is established to realize the formal language description of ontology relationships, as shown in Table 2.

[0080] Table 2 Entity relationship predicate and label mapping table

[0081]

[0082]

[0083] Accordingly, an embodiment of the present invention further provides a device for identifying multi-layer semantic advanced threat knowledge, see Figure 6 , the device comprises:

[0084] The parsing unit is used to perform information identification and parsing on the raw data, and to extract knowledge and semantically expand the processed data to identify entities, attributes, and associations of threat knowledge;

[0085] A processing unit configured to construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes, and associations of the identified threat knowledge. The multi-layer semantic advanced threat knowledge representation model is a general, practical, and extensible network threat ontology knowledge model constructed using semantic technology in combination with the STIX threat data element standard and the ATT&CK knowledge framework. The multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model. The high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity, including threat subjects, attack activities, attack events, attack patterns, response measures, and victims that cannot be directly extracted from the original data, as high-level semantic entities. The low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity, including malware, infrastructure, tools, compromise indicators, observable data, and vulnerabilities that can be directly identified or extracted from the original data, as low-level semantic entities.

[0086] The identification unit is used to identify network attack behaviors based on the constructed multi-layer semantic advanced threat knowledge representation model.

[0087] Furthermore, in an embodiment of the present invention, the processing unit is also used to construct the multi-layer semantic advanced threat knowledge representation model through entity relationship modeling, entity formal modeling, and entity relationship formal modeling, wherein the entity relationship modeling is to conceptualize and analyze the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formal modeling is to design corresponding label identifications for entity categories and attributes to realize the formal language description of the knowledge ontology; and establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of the ontology relationship.

[0088] In general, the present invention proposes a multi-layer semantic advanced threat knowledge description framework. This method combines the STIX threat data element standard and the ATT&CK tactics knowledge framework, uses semantic technology to construct a complete advanced threat knowledge framework, and establishes a relatively general, practical and extensible network threat ontology knowledge model. It provides a unified behavior model architecture for complex and changeable attack behaviors such as APT attacks, so that in a standardized scenario with multi-domain knowledge sharing, it can describe the knowledge model of threat intelligence field knowledge information as comprehensively as possible to cope with changeable network threat scenarios.

[0089] In addition, embodiments of the present invention further provide a computer-readable storage medium storing a computer program. When executed by a processor, the program implements the method for identifying multi-layer semantic advanced threat knowledge described in any of the method embodiments of the present invention. For details, please refer to the method embodiments of the present invention and will not be discussed in detail here.

[0090] Although the preferred embodiments of the present invention have been disclosed for illustrative purposes, those skilled in the art will appreciate that various modifications, additions and substitutions are possible, and thus, the scope of the present invention should not be limited to the above embodiments.

Claims

1. A method for identifying multi-layer semantic advanced threat knowledge, characterized in that: include: Perform information identification and analysis on the raw data, and perform knowledge extraction and semantic expansion on the processed data to identify entities, attributes, and associations of threat knowledge; A multi-layer semantic advanced threat knowledge representation model is constructed based on the entities, attributes, and associations of the identified threat knowledge. The multi-layer semantic advanced threat knowledge representation model is a general, practical, and extensible network threat ontology knowledge model constructed using semantic technology in combination with the STIX threat data element standard and the ATT&CK knowledge framework. The multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model. The high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity, which cannot be directly extracted from the original data, such as threat subjects, attack activities, attack events, attack patterns, response measures, and victims. The low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity, which can be directly identified or extracted from the original data, such as malware, infrastructure, tools, compromise indicators, observable data, and vulnerabilities. Network attack behaviors are identified based on the constructed multi-layer semantic advanced threat knowledge representation model.

2. The method according to claim 1, characterized in that The information identification and analysis processing of the original data includes: The original data is processed for information identification and analysis to obtain threat subject information, threat event information, time information, threat intent information, and tool information.

3. The method according to claim 1, characterized in that The information identification and analysis processing of the original data also includes: The raw data is processed for information identification and analysis through information extraction, knowledge organization, analytical reasoning and semantic enhancement.

4. The method according to claim 1, wherein The method further comprises: Perform threat knowledge representation on the data after information identification and analysis, and perform knowledge extraction and semantic expansion based on the data represented by threat knowledge; The threat knowledge representation is to identify the types, entity relationships and entity attributes of threat knowledge entities through a preset threat semantic model, and perform data mining, natural language processing, knowledge representation and semantic organization, semantic query, semantic expansion based on entity linking and semantic enhancement based on time series.

5. The method according to claim 1, wherein The processed data is subjected to knowledge extraction and semantic expansion to identify entities, attributes, and associations of threat knowledge, including: Through data mining, natural language processing, knowledge representation and semantic organization, ontology reasoning, and semantic query, the processed data is subjected to entity recognition, relationship extraction, and semantic enhancement of threat knowledge to identify the entities, attributes, and association relationships of threat knowledge.

6. The method according to any one of claims 1 to 5, characterized in that The construction of a multi-layer semantic advanced threat knowledge representation model includes: The multi-layer semantic advanced threat knowledge representation model is constructed by entity relationship modeling, entity formalization modeling and entity relationship formalization modeling, wherein: The entity relationship modeling is to conduct conceptual modeling analysis on the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; The entity formal modeling is to design corresponding label identification for entity categories and attributes to realize the formal language description of knowledge ontology; Establish a mapping relationship between entity relationship predicates and entity relationship labels to achieve a formal language description of ontology relationships.

7. The method according to any one of claims 1 to 5, characterized in that The raw data includes security report data, threat intelligence data, vulnerability data, malicious sample data and APT organization data.

8. A device for identifying multi-layer semantic advanced threat knowledge, characterized in that: The device comprises: The parsing unit is used to perform information identification and parsing on the raw data, and to extract knowledge and semantically expand the processed data to identify entities, attributes, and associations of threat knowledge; A processing unit configured to construct a multi-layer semantic advanced threat knowledge representation model based on the entities, attributes, and associations of the identified threat knowledge. The multi-layer semantic advanced threat knowledge representation model is a general, practical, and extensible network threat ontology knowledge model constructed using semantic technology in combination with the STIX threat data element standard and the ATT&CK knowledge framework. The multi-layer semantic advanced threat knowledge representation model includes a high-level semantic entity class model and a low-level semantic entity class model. The high-level semantic entity class model is formed by analyzing the attributes and associations of each high-level semantic entity, including threat subjects, attack activities, attack events, attack patterns, response measures, and victims that cannot be directly extracted from the original data, as high-level semantic entities. The low-level semantic entity class model is formed by analyzing the attributes and associations of each low-level semantic entity, including malware, infrastructure, tools, compromise indicators, observable data, and vulnerabilities that can be directly identified or extracted from the original data, as low-level semantic entities. The identification unit is used to identify network attack behaviors based on the constructed multi-layer semantic advanced threat knowledge representation model.

9. The device according to claim 8, characterized in that The processing unit is also used to construct the multi-layer semantic advanced threat knowledge representation model through entity relationship modeling, entity formal modeling and entity relationship formal modeling, wherein the entity relationship modeling is to perform conceptual modeling and analysis on the relationship between high-level semantic entities, the relationship between low-level semantic entities, and the relationship between high-level semantic entities and low-level semantic entities; the entity formal modeling is to design corresponding label identifications for entity categories and attributes to realize the formal language description of the knowledge ontology; and establish a mapping relationship between entity relationship predicates and entity relationship labels to realize the formal language description of the ontology relationship.

10. A computer-readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, the method for identifying multi-layer semantic advanced threat knowledge according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Text data-oriented threat intelligence knowledge graph construction method

    CN110717049A

  • Network threat knowledge graph construction method based on SecBABC

    CN119106141A