Network attack scene reconstruction method and device based on alarm log correlation
By extracting and analyzing the properties of the network attack log, reconstructing the network attack path using sliding time windows and probabilistic models, the problem of IDS generating false positives and lack of correlation in complex network environments is solved, and efficient threat detection and security protection is achieved.
Patent Information
- Application Number
- CN202510160719.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-13
AI Technical Summary
The existing intrusion detection system (IDS) generates massive false alarms in complex network environments, lacking appropriate alarm priority classification and sorting, resulting in fatigue of security operators and being unable to effectively correlate multi-stage attack behaviors. The existing alarm association technology relies on prior knowledge or statistical features, making it difficult to accurately identify low-frequency key alarms.
By extracting the six attributes of the current alarm log, the super alarm log is determined, the attack scenario is divided using the sliding time window and risk level attributes, the network attack path is reconstructed in combination with the probability model, the dependence on prior knowledge is reduced, and the low-frequency but serious hazardous key alarms are accurately captured.
It improves the accuracy and comprehensiveness of threat detection, reduces system maintenance costs, and provides more reliable network security guarantees.
Smart Images

Figure CN120017362A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method and device for reconstructing a network attack scenario based on alarm log correlation. Background Art
[0002] In recent years, the Internet industry has developed rapidly, the complexity and risks of cyberspace have continued to increase, and cyber attack methods have emerged in an endless stream. Intrusion detection systems (IDS) have become an important line of defense for protecting privacy data and maintaining network security, but there are many problems. In order to detect malicious activities as much as possible, IDS will mark suspicious events in complex network environments, generating massive alarms and most of them are false alarms. At the same time, IDS lacks appropriate alarm priority classification and sorting, so that all alarms are regarded as equally important, causing security operators to experience alarm fatigue and ignore real security events and critical alarms. In addition, IDS lacks correlation analysis of the entire attack chain. Specifically, while advanced attackers are prevalent in adopting multi-stage attack behaviors, the alarm logs presented by IDS are still based on single events, and isolated data makes it difficult to discover multi-dimensional attack behaviors. Existing alarm correlation technologies are mainly divided into two categories: alarm log correlation technology based on prior knowledge and alarm log correlation technology based on statistical features.
[0003] However, the alarm log association technology based on prior knowledge needs to rely on a lot of expert experience to build a causal relationship knowledge base, and also needs to manually screen prior rules. Not only is the workload large and maintenance difficult, but the effect is overly dependent on existing experience, making it difficult to mine new attack patterns; the alarm log association technology based on statistical features relies on frequent item sets to establish association rules, and does not distinguish the risk levels of alarms of different attack behaviors, resulting in low association accuracy and the inability to associate alarms with low frequency, resulting in the lack of key nodes in the reconstructed attack scenario. Therefore, how to quickly identify the attacker's intentions from massive alarms and restore the complete attack scenario has become an urgent problem to be solved. Summary of the invention
[0004] In view of this, the embodiment of the present application provides a method and device for reconstructing network attack scenarios based on the correlation of alarm logs. The present application reduces the reliance on prior knowledge, avoids the additional workload of security operators due to data labeling, and effectively reduces the manual maintenance cost of the system; at the same time, it can accurately capture and deeply correlate and analyze those critical alarms that have a low frequency of occurrence but are seriously harmful, thereby reconstructing attack scenarios from massive alarm logs, which not only improves the accuracy of threat detection, but also enhances the comprehensiveness of detection, providing a more reliable guarantee for system security. The present application mainly includes the following aspects:
[0005] In a first aspect, an embodiment of the present application provides a method for reconstructing a network attack scenario based on alarm log correlation, the reconstruction method comprising:
[0006] Extract the target attribute in the current alarm log generated in the process of detecting network attacks, and obtain the attribute six-tuple of the current alarm log;
[0007] Determine a super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple;
[0008] The log set formed by the arrangement of super alarm logs and historical super alarm logs is divided by using a sliding time window to obtain multiple super alarm log sets associated with network attack scenarios, and each super alarm log set is determined as a corresponding initial candidate attack scenario sequence;
[0009] Compare the timestamp attributes of each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence;
[0010] Taking the super alarm log with the highest risk level attribute as the segmentation point, segment each candidate attack scenario sequence to obtain candidate attack scenario subsequences;
[0011] For each candidate attack scenario subsequence, extract the attack type attribute and the destination port attribute from the attribute septuple of each super alarm log included in the candidate attack scenario subsequence and combine them to obtain multiple key alarm logs, and arrange the multiple key alarm logs in the order of each super alarm log of the corresponding candidate attack scenario subsequence to obtain a candidate attack scenario key sequence;
[0012] Input all candidate attack scenario key sequences into a preset probability model, so that the preset probability model takes the key alarm log with the highest risk level in each candidate attack scenario key sequence as the initial attack state, outputs the attack scenario sequence corresponding to each key alarm log with the highest risk level, and determines the attack scenario sequence corresponding to the key alarm log with the highest risk level as a network attack path, and constructs a network attack path model based on the network attack path;
[0013] The network attack paths with the same last key alarm log in the network attack path model are merged to obtain multiple reconstructed network attack scenarios.
[0014] Further, the step of determining the super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple includes:
[0015] (A) based on the attack type attribute in the attribute sextuple of the current alarm log, obtaining the risk level attribute of the current alarm log, and adding the risk level attribute to the attribute sextuple of the current alarm log to obtain the attribute sextuple of the current alarm log;
[0016] (B) performing a similarity comparison between the target attribute in the attribute septuple of the current alarm log and the corresponding target attribute in the historical super alarm log, and using the similarity of each target attribute to obtain the log similarity between the current alarm log and the historical super alarm log;
[0017] (C) if the log similarity is greater than the log similarity threshold, aggregating the current alarm log and the historical super alarm log for which similarity comparison was last performed to obtain a super alarm log;
[0018] (D) If the log similarity is less than or equal to the log similarity threshold and the historical super alarm log for which the similarity comparison was last performed is not the last historical super alarm log, then the current alarm log is compared with the corresponding target attributes in the previous historical super alarm log of the historical super alarm log for similarity, and the log similarity between the current alarm log and the previous historical super alarm log is obtained by using the similarity of each target attribute, and the execution of step (C) is returned;
[0019] (E) If the log similarity is less than the log similarity threshold and the historical super alarm log for which similarity comparison is last performed is the last historical super alarm log, the current alarm log is determined as the super alarm log.
[0020] Furthermore, based on the attack type attribute in the attribute sextuple of the current alarm log, the risk level attribute of the current alarm log is obtained, including:
[0021] Based on the mapping relationship between the attack type attribute in the attribute sextuple of the alarm log and the network attack severity corresponding to the alarm log, the attack type attribute in the attribute sextuple of the current alarm log is mapped to the network attack severity corresponding to the current alarm log;
[0022] Based on the mapping relationship between the severity of the network attack corresponding to the alarm log and the risk level of the alarm log, the severity of the network attack corresponding to the current alarm log is mapped to the risk level attribute of the current alarm log.
[0023] Further, the log similarity between the current alarm log and the historical super alarm log is obtained by using the similarity of each target attribute, including:
[0024] The similarities of all target attributes are averagely weighted to obtain the log similarity between the current alarm log and the historical super alarm log.
[0025] Furthermore, the log set formed by arranging the super alarm log and the historical super alarm log is divided by using the sliding time window to obtain multiple super alarm log sets associated with the network attack scenario, including:
[0026] Based on the timestamp attribute in the attribute septuple of the super alarm log and the timestamp attribute in the attribute septuple of the historical super alarm log, the super alarm log and the historical super alarm log are arranged in chronological order to obtain a log set formed by the arranged multiple super alarm logs, and based on the timestamp attribute in the attribute septuple of the multiple super alarm logs, the multiple super alarm logs are divided using a sliding time window to obtain multiple super alarm log sets associated with network attack scenarios.
[0027] Furthermore, the timestamp attribute comparison is performed on each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence, including:
[0028] (a) for each initial candidate attack scenario sequence, comparing the time difference between the timestamp attribute in the attribute septuple of the last super alarm log included in the initial candidate attack scenario sequence and the timestamp attribute in the attribute septuple of the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence;
[0029] (b) if the time difference is less than a preset interval threshold, the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence is divided into the last position in the initial candidate attack scenario sequence, and the process returns to step (a);
[0030] (c) If the time difference is greater than or equal to a preset interval threshold, the initial candidate attack scenario sequence is determined as a candidate attack scenario sequence.
[0031] Furthermore, the super alarm log with the highest risk level attribute is used as a segmentation point to segment each candidate attack scenario sequence to obtain a candidate attack scenario subsequence, including:
[0032] Taking the super alarm log with the highest risk level attribute as the segmentation point, each candidate attack scenario sequence is segmented to obtain multiple segmented candidate attack scenario sequences, and the extracted segmented candidate attack scenario sequence containing all types of risk level attributes is determined as a candidate attack scenario subsequence.
[0033] In a second aspect, an embodiment of the present application further provides a device for reconstructing a network attack scenario based on alarm log correlation, the device comprising:
[0034] The extraction module extracts the target attribute in the current alarm log generated in the process of detecting network attacks, and obtains the attribute six-tuple of the current alarm log.
[0035] The log determination module determines the super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple;
[0036] The initial partitioning module uses a sliding time window to partition a log set formed by the arrangement of super alarm logs and historical super alarm logs to obtain multiple super alarm log sets associated with network attack scenarios, and determines each super alarm log set as a corresponding initial candidate attack scenario sequence;
[0037] The dynamic partitioning module compares the timestamp attributes of each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence;
[0038] The segmentation module uses the super alarm log with the highest risk level attribute as the segmentation point to segment each candidate attack scenario sequence to obtain candidate attack scenario subsequences;
[0039] A generation module, for each candidate attack scenario subsequence, extracts the attack type attribute and the destination port attribute from the attribute septuple of each super alarm log included in the candidate attack scenario subsequence, combines them, obtains multiple key alarm logs, and arranges the multiple key alarm logs in the order of each super alarm log of the corresponding candidate attack scenario subsequence, to obtain a candidate attack scenario key sequence;
[0040] A construction module is provided to input all candidate attack scenario key sequences into a preset probability model, so that the preset probability model takes the key alarm log with the highest risk level in each candidate attack scenario key sequence as the initial attack state, outputs the attack scenario sequence corresponding to each key alarm log with the highest risk level, and determines the attack scenario sequence corresponding to the key alarm log with the highest risk level as a network attack path, and constructs a network attack path model based on the network attack path;
[0041] The reconstruction module merges the network attack paths with the same last key alarm log in the network attack path model to obtain multiple reconstructed network attack scenarios.
[0042] In a third aspect, an embodiment of the present application further provides an electronic device, comprising: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and the machine-readable instructions are executed by the processor when running to perform the steps of the method for reconstructing a network attack scenario based on alarm log correlation described in the first aspect or any possible implementation scheme of the first aspect.
[0043] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the step X described in the first aspect or any possible implementation of the first aspect is executed.
[0044] The embodiment of the present application provides a method and device for reconstructing a network attack scenario based on the correlation of alarm logs. First, target attributes are extracted from the current alarm log generated by detecting a network attack to form an attribute sextuple, and a super alarm log is determined in combination with the risk level attribute; then, a set consisting of super alarm logs and historical super alarm logs is divided by a sliding time window to obtain an initial candidate attack scenario sequence, and then the candidate attack scenario sequence is screened out by timestamp comparison; thereafter, a candidate attack scenario subsequence is obtained by taking the super alarm log with the highest risk level as a dividing point, and the attack type and destination port attributes are extracted from the super alarm log attribute septuple of the subsequence to form a key alarm log and sorted to form a key sequence of candidate attack scenarios; then, these key sequences are input into a preset probability model, and an attack scenario sequence is output with the key alarm log with the highest risk level as the initial state, which is determined as a network attack path and a network attack path model is constructed; finally, the network attack path with the same last key alarm log in the model is merged to reconstruct multiple network attack scenarios.
[0045] In this way, the reliance on prior knowledge is reduced, and the additional workload for security operators due to data labeling is avoided, thereby effectively reducing the manual maintenance costs of the system; at the same time, it can accurately capture and deeply correlate and analyze those critical alarms that occur less frequently but have serious hazards, thereby reconstructing attack scenarios from massive alarm logs, which not only improves the accuracy of threat detection, but also enhances the comprehensiveness of detection, providing more reliable protection for system security.
[0046] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0048] Figure 1One of the flowcharts of a method for reconstructing a network attack scenario based on alarm log correlation provided by an embodiment of the present application is shown;
[0049] Figure 2 A second flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided by an embodiment of the present application is shown;
[0050] Figure 3 A third flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided by an embodiment of the present application is shown;
[0051] Figure 4 A fourth flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided by an embodiment of the present application is shown;
[0052] Figure 5 A fifth flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided in an embodiment of the present application is shown;
[0053] Figure 6 The process of a method for reconstructing a network attack scenario based on the correlation of alarm logs provided in an embodiment of the present application is shown. Figure 6 ;
[0054] Figure 7 A schematic diagram of the structure of a device for reconstructing a network attack scenario based on alarm log correlation provided by an embodiment of the present application is shown;
[0055] Figure 8 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0056] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of explanation and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in this application shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can be implemented out of sequence, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art, under the guidance of the content of the present application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart.
[0057] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.
[0058] The following methods, devices, electronic devices or computer-readable storage media of the embodiments of the present application can be applied to any scenario where alarm log association is required. The embodiments of the present application are not limited to specific application scenarios. Any scheme using the alarm log reconstruction method and device provided by the embodiments of the present application is within the protection scope of the present application.
[0059] It is worth noting that in recent years, the Internet industry has developed rapidly, the complexity and risks of cyberspace have continued to increase, and network attack methods have emerged in an endless stream. Intrusion detection systems (IDS) have become an important line of defense for protecting privacy data and maintaining network security, but there are many problems. In order to detect malicious activities as much as possible, IDS will mark suspicious events in complex network environments, generating massive alarms and most of them are false alarms. At the same time, IDS lacks appropriate alarm priority classification and sorting, so that all alarms are regarded as equally important, resulting in alarm fatigue for security operators and ignoring real security events and critical alarms. In addition, IDS lacks correlation analysis of the entire attack chain. Specifically, while advanced attackers are prevalent in adopting multi-stage attack behaviors, the alarm logs presented by IDS are still based on single events, and it is difficult to discover multi-dimensional attack behaviors in isolated data. Existing alarm correlation technologies are mainly divided into two categories: alarm log correlation technology based on prior knowledge and alarm log correlation technology based on statistical features. However, the alarm log association technology based on prior knowledge needs to rely on a lot of expert experience to build a causal relationship knowledge base, and also needs to manually screen prior rules. Not only is the workload large and maintenance difficult, but the effect is overly dependent on existing experience, making it difficult to mine new attack patterns; the alarm log association technology based on statistical features relies on frequent item sets to establish association rules, and does not distinguish the risk levels of alarms of different attack behaviors, resulting in low association accuracy and the inability to associate alarms with low frequency, resulting in the lack of key nodes in the reconstructed attack scenario. Therefore, how to quickly identify the attacker's intentions from massive alarms and restore the complete attack scenario has become an urgent problem to be solved.
[0060] In response to the above problems, the embodiments of the present application propose a method and device for reconstructing network attack scenarios based on alarm log correlation, which reduces the reliance on prior knowledge, avoids the additional workload of security operators due to data labeling, and effectively reduces the manual maintenance cost of the system; at the same time, it can accurately capture and deeply correlate and analyze those critical alarms that occur less frequently but have serious hazards, thereby reconstructing attack scenarios from massive alarm logs, which not only improves the accuracy of threat detection, but also enhances the comprehensiveness of detection, providing more reliable protection for system security.
[0061] To facilitate the understanding of the present application, the technical solution provided by the present application is described in detail below in conjunction with specific embodiments.
[0062] See also Figure 1 , Figure 1 One of the flowcharts of a method for reconstructing a network attack scenario based on alarm log correlation provided in an embodiment of the present application.
[0063] like Figure 1 As shown in , the alarm log reconstruction method provided in the embodiment of the present application includes the following steps:
[0064] Step S101, extracting target attributes in the current alarm log generated during the process of detecting network attacks, and obtaining the attribute sextuple of the current alarm log.
[0065] In the embodiment of the present application, the alarm log is the information recorded when malicious activities are found during the network detection process. The target attribute includes at least one of the following items: timestamp, source IP address, destination IP address, source port, destination port and attack type. In the present application, the network is detected by an intrusion detection system.
[0066] Here, the current alarm logs can be standardized through the Intrusion Detection Message Exchange Format (IDMEF) standard to comprehensively analyze the massive alarm logs generated by multiple security devices.
[0067] After step S101, the attribute six-tuple of the current alarm log is redundancy eliminated. Specifically, if the attributes in the attribute six-tuple of the current alarm log are incomplete, the current alarm log is filtered out; if the attributes in the attribute six-tuple of the current alarm log are complete, the alarm logs with the same source IP address, destination IP address, source port, destination port, and attack signature attributes within 1 second of the current alarm log are initially aggregated into one alarm log as the current alarm log.
[0068] Step S102: determining a super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple.
[0069] Here, the risk level attribute is added as an extended attribute to the existing attribute sextuple. By marking the risk levels of different attack behaviors, high-risk alarm logs can be processed first, avoiding a large number of insignificant alarm logs from drowning out security events that are truly worth paying attention to.
[0070] Combine the following Figure 2 To illustrate how to determine a super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple.
[0071] See also Figure 2 , Figure 2 The present invention provides a flowchart of a method for reconstructing a network attack scenario based on the correlation of alarm logs in an embodiment of the present application.
[0072] like Figure 2 As shown in FIG. 1 , regarding step S102, in a specific implementation, as an example, the following steps may be included:
[0073] Step S1021, based on the attack type attribute in the attribute sextuple of the current alarm log, obtain the risk level attribute of the current alarm log, and add the risk level attribute to the attribute sextuple of the current alarm log to obtain the attribute sextuple of the current alarm log.
[0074] Combine the following Figure 3 This illustrates how to obtain the risk level attribute of the current alarm log based on the attack type attribute in the attribute sextuple of the current alarm log.
[0075] See also Figure 3 , Figure 3 The third flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided in an embodiment of the present application.
[0076] like Figure 3 As shown in , regarding the attack type attribute in the attribute 6-tuple of the current alarm log in step S1021, obtaining the risk level attribute of the current alarm log, in specific implementation, as an example, may include the following steps:
[0077] Regarding step S10211, based on the mapping relationship between the attack type attribute in the attribute sextuple of the alarm log and the network attack severity corresponding to the alarm log, the mapping relationship between the attack type attribute in the attribute sextuple of the current alarm log and the network attack severity corresponding to the current alarm log is established.
[0078] In this step, the attack type attribute in the attribute sextuple of the alarm log is mapped to the network attack severity corresponding to the alarm log in the Common Attack Pattern Enumeration and Classification (CAPEC) framework. Here, the CAPEC framework divides the severity of network attacks into three risk levels: low risk, medium risk and high risk.
[0079] As an example, the attack type attribute "Host Discovery" in the attribute sextuple of the alarm log is mapped to the network attack severity "CAPEC-292" corresponding to the alarm log in the CAPEC framework.
[0080] Step S10212, based on the mapping relationship between the severity of the network attack corresponding to the alarm log and the risk level of the alarm log, the severity of the network attack corresponding to the current alarm log is mapped to the risk level attribute of the current alarm log.
[0081] Continuing with the above example, the network attack severity "CAPEC-292" corresponding to the current alarm log is mapped to the risk level attribute low risk "Low" of the current alarm log.
[0082] See again Figure 2 , step S1022, respectively compare the target attribute in the attribute septuple of the current alarm log with the corresponding target attribute in the historical super alarm log, and use the similarity of each target attribute to obtain the log similarity between the current alarm log and the historical super alarm log.
[0083] Here, the target attribute in the attribute seven-tuple of the current alarm log is compared with the corresponding target attribute in the historical super alarm log for similarity, and the IP address similarity, source port similarity, destination port similarity, attack type similarity and time similarity are obtained.
[0084] In an embodiment of the present application, the specific calculation method of the attack type similarity is defined as follows: if the source IP address and the destination IP address in the attribute seven-tuple in the current alarm log and the historical super alarm log are the same, then the IP address similarity between the current alarm log and the historical super alarm log is 1, and the current alarm log and the historical super alarm log may be aggregated into a super alarm; if the source IP address and the destination IP address in the attribute seven-tuple in the current alarm log and the historical super alarm log are the same, then the IP address similarity between the current alarm log and the historical super alarm log is 0, and the current alarm log and the historical super alarm log cannot be aggregated into a super alarm.
[0085] In the embodiment of the present application, the specific calculation method of the source port similarity is defined as follows: the ports are divided into three categories: general service ports, common ports and other ports, and a port similarity tree is constructed. As an example, the source port similarity and the destination port similarity can be calculated by formula (1).
[0086]
[0087] Among them, S port is the similarity between the port of the current alarm log and the port of the historical super alarm log, i.port Indicates the port of the current alarm log, ra j.port Indicates the port of the historical super alarm log. i.port ,ra j.port ) indicates the step length of the ports of the current alarm log and the historical super alarm log from the common parent node on the port similarity tree. For example, the step length of the ports with port numbers between 1 and 80 from the common parent node is 1, and the step length of the ports with port numbers between 1 and 1024 from the common parent node is 2. Among them, the source port similarity is inversely proportional to the distance from the source port to the parent node, and the destination port similarity is inversely proportional to the distance from the destination port to the parent node.
[0088] In an embodiment of the present application, the specific calculation method of the attack type similarity is defined as follows: if the attack types in the attribute seven-tuple in the current alarm log and the historical super alarm log are the same, then the attack type similarity between the current alarm log and the historical super alarm log is 1, and the current alarm log and the historical super alarm may be aggregated into a super alarm log; if the attack types in the attribute seven-tuple in the current alarm log and the historical super alarm log are different, then the attack type similarity between the current alarm log and the historical super alarm log is 0, and the current alarm log and the initial super alarm log cannot be aggregated into a super alarm log.
[0089] In an embodiment of the present application, the specific calculation method of time similarity is defined as follows: if the difference between the timestamp in the attribute septuple of the current alarm log and the timestamp in the attribute septuple of the historical super alarm log is within a preset time range, then the time similarity between the current alarm log and the historical super alarm log is 1, and the current alarm log and the historical super alarm log may be aggregated into a super alarm log; if the difference between the timestamp in the attribute septuple of the current alarm log and the timestamp in the attribute septuple of the historical super alarm log is not within the preset time range, then the time similarity between the current alarm log and the historical super alarm log is 0, and the current alarm log and the historical super alarm log cannot be aggregated into a super alarm log.
[0090] In the embodiment of the present application, the similarities of all target attributes are averaged and weighted to obtain the log similarity between the current alarm log and the historical super alarm log. As an example, the log similarity between the current alarm log and the historical super alarm log can be calculated by formula (2).
[0091]
[0092] Among them, i Indicates the current alarm log, ra j Indicates the historical super alarm log, S(ra i ,ra j ) indicates the log similarity between the current alarm log and the historical super alarm log, s(ra ik ,ra jk ) represents the similarity between the current alarm log and the kth attribute in the historical super alarm log, w k Indicates the weight of the kth attribute in the overall similarity. Here, since the source IP address, destination IP address, attack type, and timestamp cannot be aggregated if they are different, only the destination port and source port need to be weighted. According to actual experience, the weights of the source port similarity and the destination port similarity are assigned. As an example, the weight of the source port similarity is 0.4, and the weight of the destination port similarity is 0.6. Weights can also be assigned based on other actual experience. The assigned weights are not limited here.
[0093] Step S1023: If the log similarity is greater than the log similarity threshold, the current alarm log and the historical super alarm log for which similarity comparison was last performed are aggregated to obtain a super alarm log.
[0094] Step S1024, if the log similarity is less than or equal to the log similarity threshold and the historical super alarm log for the last similarity comparison is not the last historical super alarm log, then the current alarm log and the corresponding target attributes in the previous historical super alarm log of the historical super alarm log are compared for similarity respectively, and the similarity of each target attribute is used to obtain the log similarity between the current alarm log and the previous historical super alarm log, and then return to execute step S1023.
[0095] Step S1025: If the log similarity is less than the log similarity threshold and the historical super alarm log for which similarity comparison is last performed is the last historical super alarm log, the current alarm log is determined as a super alarm log.
[0096] See again Figure 1, step S103, using a sliding time window to divide the log set formed by the super alarm log and the historical super alarm log, to obtain multiple super alarm log sets associated with network attack scenarios, and determine each super alarm log set as a corresponding initial candidate attack scenario sequence.
[0097] Combine the following Figure 4 To illustrate the use of a sliding time window to divide a log set formed by the arrangement of super alarm logs and historical super alarm logs to obtain multiple super alarm log sets associated with network attack scenarios.
[0098] See also Figure 4 , Figure 4 This is a fourth flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided in an embodiment of the present application.
[0099] like Figure 4 As shown in FIG. 1 , regarding step S103, in a specific implementation, as an example, the following steps may be included:
[0100] Step S1031, based on the timestamp attribute in the attribute septuple of the super alarm log and the timestamp attribute in the attribute septuple of the historical super alarm log, the super alarm log and the historical super alarm log are arranged in chronological order to obtain a log set formed by the arranged multiple super alarm logs.
[0101] Step S1032: Based on the timestamp attribute in the attribute septuple of the multiple super alarm logs, the multiple super alarm logs are divided using a sliding time window to obtain multiple super alarm log sets associated with the network attack scenarios.
[0102] Here, as an example, the sliding time window is 1 hour.
[0103] See again Figure 1 , step S104, performing timestamp attribute comparison on each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence.
[0104] Combine the following Figure 5 To illustrate the comparison of timestamp attributes for each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence.
[0105] See also Figure 5 , Figure 5 This is a fifth flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided in an embodiment of the present application.
[0106] like Figure 5 As shown in FIG. 1 , regarding step S104, in a specific implementation, as an example, the following steps may be included:
[0107] Step S1041, for each initial candidate attack scenario sequence, compare the time difference between the timestamp attribute in the attribute seven-tuple of the last super alarm log included in the initial candidate attack scenario sequence and the timestamp attribute in the attribute seven-tuple of the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence.
[0108] Step S1042: If the time difference is less than the preset interval threshold, the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence is divided into the last position in the initial candidate attack scenario sequence, and the process returns to step S1041.
[0109] Here, as an example, the preset interval threshold is 1 minute.
[0110] If the time difference is less than the preset interval threshold, it is considered that the last super alarm log included in the initial candidate attack scenario sequence may belong to the same attack scenario sequence, and the initial candidate attack scenario sequence is expanded, and the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence is divided into the initial candidate attack scenario sequence, so as to achieve the effect of dynamically adapting the alarm log flow rate of the sliding time window, and avoid the problem of attack chain break caused by the inability of the sliding time window to adapt to the suddenness of the super alarm log.
[0111] Step S1043: If the time difference is greater than or equal to a preset interval threshold, the initial candidate attack scenario sequence is determined as a candidate attack scenario sequence.
[0112] See again Figure 1 , step S105, taking the super alarm log with the highest risk level attribute as a segmentation point, segmenting each candidate attack scenario sequence to obtain a candidate attack scenario subsequence.
[0113] Combine the following Figure 6 To illustrate that each candidate attack scenario sequence is segmented by taking the super alarm log with the highest risk level attribute as the segmentation point to obtain the candidate attack scenario subsequences.
[0114] See also Figure 6 , Figure 6 This is a flowchart of a method for reconstructing a network attack scenario based on alarm log correlation provided in an embodiment of the present application.
[0115] like Figure 6 As shown in FIG. 1 , regarding step S105, in a specific implementation, as an example, the following steps may be included:
[0116] Step S1051, taking the super alarm log with the highest risk level attribute as a segmentation point, segmenting each candidate attack scenario sequence to obtain a plurality of segmented candidate attack scenario sequences.
[0117] Here, the super alarm log with the highest risk level attribute is marked to segment each candidate attack scenario sequence.
[0118] Step S1052: Determine the extracted segmented candidate attack scenario sequence containing all types of risk level attributes as a candidate attack scenario subsequence.
[0119] Here, if a segmented candidate attack scenario sequence meets the following conditions: first, the preceding super alarm log of the segmented candidate attack scenario sequence is a log of a low or medium risk level; second, the super alarm log at the end of the segmented candidate attack scenario sequence is a log of a high risk level, then this segmented candidate attack scenario sequence is divided into a candidate attack scenario subsequence.
[0120] In the candidate attack scenario sequence that has been divided, the attack scenario subsequences are further divided. In order to highlight the super alarm logs with low frequency but high harm, the subsequences are divided based on this basis, and the candidate attack scenarios are traversed. If a high-risk super alarm log appears, the candidate attack scenario sequence is divided based on this point. This processing method can effectively avoid the alarm fatigue problem caused by a large number of insignificant alarm logs. At the same time, without discarding the low-risk super alarm logs, the high-risk super alarm logs are focused on to help reconstruct the complete attack scenario.
[0121] See again Figure 1 , step S106, for each candidate attack scenario subsequence, extract the attack type attribute and the destination port attribute from the attribute seven-tuple of each super alarm log included in the candidate attack scenario subsequence and combine them to obtain multiple key alarm logs, and arrange the multiple key alarm logs in the order of each super alarm log of the corresponding candidate attack scenario subsequence to obtain the candidate attack scenario key sequence.
[0122] Step S107, input all candidate attack scenario key sequences into a preset probability model, so that the preset probability model takes the key alarm log with the highest risk level in each candidate attack scenario key sequence as the initial attack state, outputs the attack scenario sequence corresponding to each key alarm log with the highest risk level, and determines the attack scenario sequence corresponding to the key alarm log with the highest risk level as a network attack path, and constructs a network attack path model based on the network attack path.
[0123] Here, in this application, as an example, the preset probability model is a probabilistic deterministic finite automaton model. The probabilistic deterministic finite automaton is used to associate the scattered and isolated key alarm logs, restore the attacker's network attack path, reconstruct the complete network attack scenario, and help security operators analyze the attacker's true intentions.
[0124] Before inputting all candidate attack scenario key sequences into the preset probability model, the number of symbols and the number of states of the probabilistic deterministic finite automaton are both set to 5, and all candidate attack scenario key sequences are input into the initial preset probability model for unsupervised training to obtain a trained preset probability model and a corresponding state transfer matrix. All candidate attack scenario key sequences are input into the trained preset probability model, and the preset probability model predicts and outputs the state transfer sequence with the highest probability from the initial attack state to the target attack state, and the state transfer sequence with the highest probability from the initial attack state to the target attack state is determined as the attack scenario sequence corresponding to each key alarm log of the highest risk level, and a key alarm log related to the key alarm log of the highest risk level is obtained.
[0125] Step S107, merging the network attack paths with the same last key alarm log in the network attack path model to obtain multiple reconstructed network attack scenarios.
[0126] Here, the common entities in the network attack path are integrated to achieve attack scenario reconstruction and restoration.
[0127] The embodiment of the present application provides a method for reconstructing network attack scenarios based on alarm log correlation. Through the method, the additional workload of security operators due to data labeling is avoided, thereby effectively reducing the manual maintenance cost of the system; at the same time, it can accurately capture and deeply correlate and analyze those critical alarms that have a low frequency of occurrence but are seriously harmful, thereby realizing the reconstruction of attack scenarios from massive alarm logs, which not only improves the accuracy of threat detection, but also enhances the comprehensiveness of detection, providing more reliable protection for system security.
[0128] Based on the same application concept, the embodiments of the present application also provide a device for reconstructing a network attack scenario based on alarm log correlation that corresponds to the method for reconstructing a network attack scenario based on alarm log correlation provided in the above embodiments. Since the principle of solving the problem by the device in the embodiments of the present application is similar to the method for reconstructing a network attack scenario based on alarm log correlation in the above embodiments of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0129] See also Figure 7 , Figure 7A schematic diagram of the structure of a device for reconstructing a network attack scenario based on alarm log correlation provided in an embodiment of the present application.
[0130] like Figure 7 As shown in , the network attack scenario reconstruction device 210 based on the alarm log correlation provided by the embodiment of the present application includes:
[0131] The extraction module 211 extracts the target attributes in the current alarm log generated during the process of detecting network attacks, and obtains the attribute sextuple of the current alarm log.
[0132] The log determination module 212 determines a super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple;
[0133] The initial partitioning module 213 partitions the log set formed by the super alarm log and the historical super alarm log using a sliding time window to obtain multiple super alarm log sets associated with network attack scenarios, and determines each super alarm log set as a corresponding initial candidate attack scenario sequence;
[0134] The dynamic partitioning module 214 compares the timestamp attributes of each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence;
[0135] The segmentation module 215 segments each candidate attack scenario sequence using the super alarm log with the highest risk level attribute as a segmentation point to obtain a candidate attack scenario subsequence;
[0136] The generating module 216 extracts the attack type attribute and the destination port attribute from the attribute septuple of each super alarm log included in the candidate attack scenario subsequence for each candidate attack scenario subsequence, combines them, obtains a plurality of key alarm logs, and arranges the plurality of key alarm logs in the order of each super alarm log of the corresponding candidate attack scenario subsequence, obtains a candidate attack scenario key sequence;
[0137] Construction module 217, inputs all candidate attack scenario key sequences into a preset probability model, so that the preset probability model takes the key alarm log of the highest risk level in each candidate attack scenario key sequence as the initial attack state, outputs the attack scenario sequence corresponding to each key alarm log of the highest risk level, and determines the attack scenario sequence corresponding to the key alarm log of the highest risk level as a network attack path, and constructs a network attack path model based on the network attack path;
[0138] The reconstruction module 218 merges the network attack paths with the same last key alarm log in the network attack path model to obtain multiple reconstructed network attack scenarios.
[0139] Preferably, the log determination module 212 is specifically used for:
[0140] (A) based on the attack type attribute in the attribute sextuple of the current alarm log, obtaining the risk level attribute of the current alarm log, and adding the risk level attribute to the attribute sextuple of the current alarm log to obtain the attribute sextuple of the current alarm log;
[0141] (B) performing a similarity comparison between the target attribute in the attribute septuple of the current alarm log and the corresponding target attribute in the historical super alarm log, and using the similarity of each target attribute to obtain the log similarity between the current alarm log and the historical super alarm log;
[0142] (C) if the log similarity is greater than the log similarity threshold, aggregating the current alarm log and the historical super alarm log for which similarity comparison was last performed to obtain a super alarm log;
[0143] (D) If the log similarity is less than or equal to the log similarity threshold and the historical super alarm log for which the similarity comparison was last performed is not the last historical super alarm log, then the current alarm log is compared with the corresponding target attributes in the previous historical super alarm log of the historical super alarm log for similarity, and the log similarity between the current alarm log and the previous historical super alarm log is obtained by using the similarity of each target attribute, and the execution of step (C) is returned;
[0144] (E) If the log similarity is less than the log similarity threshold and the historical super alarm log for which similarity comparison is last performed is the last historical super alarm log, the current alarm log is determined as the super alarm log.
[0145] Preferably, when the log determination module 212 is used to obtain the risk level attribute of the current alarm log based on the attack type attribute in the attribute sextuple of the current alarm log, it is also specifically used to:
[0146] Based on the mapping relationship between the attack type attribute in the attribute sextuple of the alarm log and the network attack severity corresponding to the alarm log, the attack type attribute in the attribute sextuple of the current alarm log is mapped to the network attack severity corresponding to the current alarm log;
[0147] Based on the mapping relationship between the severity of the network attack corresponding to the alarm log and the risk level of the alarm log, the severity of the network attack corresponding to the current alarm log is mapped to the risk level attribute of the current alarm log.
[0148] Preferably, when the log determination module 212 is used to obtain the log similarity between the current alarm log and the historical super alarm log based on the similarity of each target attribute, it is also specifically used to:
[0149] The similarities of all target attributes are averagely weighted to obtain the log similarity between the current alarm log and the historical super alarm log.
[0150] Preferably, the initial partitioning module 213 is used to partition the log set formed by the arrangement of the super alarm log and the historical super alarm log using the sliding time window to obtain multiple super alarm log sets associated with the network attack scenario, and is also specifically used to:
[0151] Based on the timestamp attribute in the attribute septuple of the super alarm log and the timestamp attribute in the attribute septuple of the historical super alarm log, the super alarm log and the historical super alarm log are arranged in chronological order to obtain a log set formed by the arranged multiple super alarm logs, and based on the timestamp attribute in the attribute septuple of the multiple super alarm logs, the multiple super alarm logs are divided using a sliding time window to obtain multiple super alarm log sets associated with network attack scenarios.
[0152] Preferably, the dynamic division module 214 is specifically used for:
[0153] (a) for each initial candidate attack scenario sequence, comparing the time difference between the timestamp attribute in the attribute septuple of the last super alarm log included in the initial candidate attack scenario sequence and the timestamp attribute in the attribute septuple of the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence;
[0154] (b) if the time difference is less than a preset interval threshold, the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence is divided into the last position in the initial candidate attack scenario sequence, and the process returns to step (a);
[0155] (c) If the time difference is greater than or equal to a preset interval threshold, the initial candidate attack scenario sequence is determined as a candidate attack scenario sequence.
[0156] Preferably, the segmentation module 215 is specifically used for:
[0157] The super alarm log with the highest risk level attribute is used as a segmentation point to segment each candidate attack scenario sequence to obtain a candidate attack scenario subsequence, including:
[0158] Taking the super alarm log with the highest risk level attribute as the segmentation point, each candidate attack scenario sequence is segmented to obtain multiple segmented candidate attack scenario sequences, and the extracted segmented candidate attack scenario sequence containing all types of risk level attributes is determined as a candidate attack scenario subsequence.
[0159] An embodiment of the present application provides a network attack scenario reconstruction device based on alarm log correlation. Through the device, the additional workload of security operators due to data labeling is avoided, thereby effectively reducing the manual maintenance cost of the system; at the same time, it can accurately capture and deeply correlate and analyze those critical alarms that occur less frequently but have serious hazards, thereby realizing the reconstruction of attack scenarios from massive alarm logs, which not only improves the accuracy of threat detection, but also enhances the comprehensiveness of detection, providing more reliable protection for system security.
[0160] See also Figure 8 , Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
[0161] like Figure 8 As shown in , the electronic device 300 includes a processor 310 , a memory 320 and a bus 330 .
[0162] The memory 320 stores machine-readable instructions executable by the processor 310. When the electronic device 300 is running, the processor 310 communicates with the memory 320 via the bus 330. When the machine-readable instructions are executed by the processor 310, the above-mentioned Figure 1-Figure 6 The steps of the method for reconstructing a network attack scenario based on the correlation of alarm logs in the method embodiment shown are specifically implemented in the method embodiment and will not be described in detail here.
[0163] The present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the computer program can execute the above-mentioned Figure 1-Figure 6 The steps of the method for reconstructing a network attack scenario based on the correlation of alarm logs in the method embodiment shown are specifically implemented in the method embodiment and will not be described in detail here.
[0164] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the system and device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here. In the several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0165] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0166] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0167] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., various media that can store program codes.
[0168] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A method for reconstructing a network attack scenario based on alarm log correlation, characterized in that: The reconstruction method comprises: Extract the target attribute in the current alarm log generated in the process of detecting network attacks, and obtain the attribute six-tuple of the current alarm log; Determine a super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple; The log set formed by the arrangement of super alarm logs and historical super alarm logs is divided by using a sliding time window to obtain multiple super alarm log sets associated with network attack scenarios, and each super alarm log set is determined as a corresponding initial candidate attack scenario sequence; Compare the timestamp attributes of each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence; Taking the super alarm log with the highest risk level attribute as the segmentation point, segment each candidate attack scenario sequence to obtain candidate attack scenario subsequences; For each candidate attack scenario subsequence, extract the attack type attribute and the destination port attribute from the attribute septuple of each super alarm log included in the candidate attack scenario subsequence and combine them to obtain multiple key alarm logs, and arrange the multiple key alarm logs in the order of each super alarm log of the corresponding candidate attack scenario subsequence to obtain a candidate attack scenario key sequence; Input all candidate attack scenario key sequences into a preset probability model, so that the preset probability model takes the key alarm log with the highest risk level in each candidate attack scenario key sequence as the initial attack state, outputs the attack scenario sequence corresponding to each key alarm log with the highest risk level, and determines the attack scenario sequence corresponding to the key alarm log with the highest risk level as a network attack path, and constructs a network attack path model based on the network attack path; The network attack paths with the same last key alarm log in the network attack path model are merged to obtain multiple reconstructed network attack scenarios.
2. The reconstruction method according to claim 1, characterized in that: The step of determining the super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple includes: (A) based on the attack type attribute in the attribute sextuple of the current alarm log, obtaining the risk level attribute of the current alarm log, and adding the risk level attribute to the attribute sextuple of the current alarm log to obtain the attribute sextuple of the current alarm log; (B) performing a similarity comparison between the target attribute in the attribute septuple of the current alarm log and the corresponding target attribute in the historical super alarm log, and using the similarity of each target attribute to obtain the log similarity between the current alarm log and the historical super alarm log; (C) if the log similarity is greater than the log similarity threshold, aggregating the current alarm log and the historical super alarm log for which similarity comparison was last performed to obtain a super alarm log; (D) If the log similarity is less than or equal to the log similarity threshold and the historical super alarm log for which the similarity comparison was last performed is not the last historical super alarm log, then the current alarm log is compared with the corresponding target attributes in the previous historical super alarm log of the historical super alarm log for similarity, and the log similarity between the current alarm log and the previous historical super alarm log is obtained by using the similarity of each target attribute, and the execution of step (C) is returned; (E) If the log similarity is less than the log similarity threshold and the historical super alarm log for which similarity comparison is last performed is the last historical super alarm log, the current alarm log is determined as the super alarm log.
3. The reconstruction method according to claim 2, characterized in that: Based on the attack type attribute in the attribute sextuple of the current alarm log, obtain the risk level attribute of the current alarm log, including: Based on the mapping relationship between the attack type attribute in the attribute sextuple of the alarm log and the network attack severity corresponding to the alarm log, the attack type attribute in the attribute sextuple of the current alarm log is mapped to the network attack severity corresponding to the current alarm log; Based on the mapping relationship between the severity of the network attack corresponding to the alarm log and the risk level of the alarm log, the severity of the network attack corresponding to the current alarm log is mapped to the risk level attribute of the current alarm log.
4. The reconstruction method according to claim 2, characterized in that: The method of obtaining the log similarity between the current alarm log and the historical super alarm log by using the similarity of each target attribute includes: The similarities of all target attributes are averagely weighted to obtain the log similarity between the current alarm log and the historical super alarm log.
5. The reconstruction method according to claim 1, characterized in that: The log set formed by arranging the super alarm log and the historical super alarm log is divided by using the sliding time window to obtain multiple super alarm log sets associated with the network attack scenario, including: Based on the timestamp attribute in the attribute septuple of the super alarm log and the timestamp attribute in the attribute septuple of the historical super alarm log, the super alarm log and the historical super alarm log are arranged in chronological order to obtain a log set formed by the arranged multiple super alarm logs, and based on the timestamp attribute in the attribute septuple of the multiple super alarm logs, the multiple super alarm logs are divided using a sliding time window to obtain multiple super alarm log sets associated with network attack scenarios.
6. The reconstruction method according to claim 1, characterized in that: The comparing of timestamp attributes for each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence includes: (a) for each initial candidate attack scenario sequence, comparing the time difference between the timestamp attribute in the attribute septuple of the last super alarm log included in the initial candidate attack scenario sequence and the timestamp attribute in the attribute septuple of the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence; (b) if the time difference is less than a preset interval threshold, the first super alarm log included in the next initial candidate attack scenario sequence of the initial candidate attack scenario sequence is divided into the last position in the initial candidate attack scenario sequence, and the process returns to step (a); (c) If the time difference is greater than or equal to a preset interval threshold, the initial candidate attack scenario sequence is determined as a candidate attack scenario sequence.
7. The reconstruction method according to claim 1, characterized in that: The super alarm log with the highest risk level attribute is used as a segmentation point to segment each candidate attack scenario sequence to obtain a candidate attack scenario subsequence, including: Taking the super alarm log with the highest risk level attribute as the segmentation point, each candidate attack scenario sequence is segmented to obtain multiple segmented candidate attack scenario sequences, and the extracted segmented candidate attack scenario sequence containing all types of risk level attributes is determined as a candidate attack scenario subsequence.
8. A network attack scenario reconstruction device based on alarm log correlation, characterized in that: The reconstruction device comprises: The extraction module extracts the target attribute in the current alarm log generated in the process of detecting network attacks, and obtains the attribute six-tuple of the current alarm log. The log determination module determines the super alarm log based on the risk level attribute of the current alarm log and the target attribute in the attribute sextuple; The initial partitioning module uses a sliding time window to partition a log set formed by the arrangement of super alarm logs and historical super alarm logs to obtain multiple super alarm log sets associated with network attack scenarios, and determines each super alarm log set as a corresponding initial candidate attack scenario sequence; The dynamic partitioning module compares the timestamp attributes of each initial candidate attack scenario sequence to obtain a candidate attack scenario sequence; The segmentation module uses the super alarm log with the highest risk level attribute as the segmentation point to segment each candidate attack scenario sequence to obtain candidate attack scenario subsequences; A generation module, for each candidate attack scenario subsequence, extracts the attack type attribute and the destination port attribute from the attribute septuple of each super alarm log included in the candidate attack scenario subsequence, combines them, obtains multiple key alarm logs, and arranges the multiple key alarm logs in the order of each super alarm log of the corresponding candidate attack scenario subsequence, to obtain a candidate attack scenario key sequence; A construction module is provided to input all candidate attack scenario key sequences into a preset probability model, so that the preset probability model takes the key alarm log with the highest risk level in each candidate attack scenario key sequence as the initial attack state, outputs the attack scenario sequence corresponding to each key alarm log with the highest risk level, and determines the attack scenario sequence corresponding to the key alarm log with the highest risk level as a network attack path, and constructs a network attack path model based on the network attack path; The reconstruction module merges the network attack paths with the same last key alarm log in the network attack path model to obtain multiple reconstructed network attack scenarios.
9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and the machine-readable instructions are executed by the processor when running to perform the steps of a method for reconstructing a network attack scenario based on alarm log correlation as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of a method for reconstructing a network attack scenario based on alarm log correlation as described in any one of claims 1 to 7 are executed.
Citation Information
Patent Citations
Network attack scene reconstruction method and system based on risk total element identification association
CN110213226A
Neurological movement detection to rapidly draw user attention to search results
WO2021178731A1
Cited By
False alarm detection method and device for network attack alarm, equipment and medium
CN120658485A