Attack path prediction method and system based on behavior gene recognition
Through the attack path prediction method based on behavioral gene recognition, deep learning models are used to combine general gene databases and malicious behavioral gene databases, and the problem that existing malware detection methods are difficult to adapt to the evolving malware threats is solved, and malware detection with high accuracy and timeliness is achieved.
Patent Information
- Application Number
- CN202510171623.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-23
AI Technical Summary
Existing malware detection methods are difficult to adapt to the ever-evolving malware threats, especially when faced with new malware, signature-based detection methods are difficult to deal with unknown or mutant malware, and behavior-based detection methods are susceptible to false positives and missed reports.
The attack path prediction method based on behavioral gene recognition is adopted to predict the attack path of malware by monitoring and collecting the behavioral gene characteristics of malware, and using deep learning models to combine general gene banks and malicious behavioral gene banks to predict the attack path of malware.
It improves the accuracy and timeliness of malware detection, can more effectively identify malware and predict its attack path, and has the characteristics of high detection accuracy, good timeliness and strong adaptability.
Smart Images

Figure CN120030539A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and in particular relates to an attack path prediction method and system based on behavior gene recognition. Background Art
[0002] In recent years, with the rapid development of information technology and the widespread popularity of network applications, the number of malware has shown an explosive growth trend. These malware not only pose a serious threat to the privacy and data security of individual users, but also pose a huge challenge to the safe and stable operation of key information infrastructure such as financial institutions and large enterprises.
[0003] In the field of network security, the competition between defenders and attackers is becoming increasingly fierce. Attackers continue to use new technical means and vulnerabilities to develop more hidden, complex and difficult-to-detect malware to bypass existing security defense systems. In particular, the widespread use of shell and obfuscation technologies has made the code structure and behavioral characteristics of malware more difficult to identify and analyze, further increasing the difficulty of malware detection.
[0004] Traditional malware detection methods, such as signature-based detection and behavior-based detection, are powerless against these new malware. Signature-based detection methods rely on known malware samples and are difficult to deal with the threats of unknown or variant malware; while behavior-based detection methods can detect the behavioral characteristics of malware, but are susceptible to false positives and false negatives, and are difficult to adapt to the rapid changes in malware behavior.
[0005] Therefore, how to improve the efficiency of malware detection under existing conditions has become a technical problem that needs to be solved urgently. In order to improve the accuracy and timeliness of malware detection, it is necessary to develop more intelligent, efficient and adaptable malware detection technology to cope with the evolving malware threats. Summary of the invention
[0006] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide an attack path prediction method and system based on behavioral gene recognition to solve the problem in the prior art that malware is difficult to adapt to the evolving malware threats.
[0007] In order to achieve the above object, the present invention adopts the following technical solutions: A method for predicting attack paths based on behavioral gene recognition comprises the following steps: Monitor and collect behavioral genetic characteristics of various actions; Inputting the behavioral gene features into a prediction model to determine the attack path of the malware; The prediction model is obtained by training a deep learning model through a general gene library and a malicious behavior gene library; the acquisition process of the malicious behavior gene library is: running the malware in a system environment container to obtain the behavioral gene characteristics of the malware; after cleaning the behavioral gene characteristics, looping through the genes in the same malware family gene library, performing feature comparison, and obtaining new gene characteristics; comparing the family genes in different malware family gene libraries to obtain a general gene library; based on the general gene library, deleting the common genes between the family genes to obtain the malicious behavior gene library; and associating the genes in the malicious behavior gene library with the attack path.
[0008] A further improvement of the present invention is: Preferably, the behavioral gene characteristics are:
[0009] in, It is the timestamp of a node in the malware running process. is the hash of the malware, Perform actions for malware, The target of the malware. To execute the action evolution path, For the operating environment.
[0010] Preferably, the cleaning of behavioral gene features comprises the following steps: (1) Construct a sample library of malware behaviors based on malware families; (2) Traverse the gene data in the gene sample library and delete genes containing invalid information; (3) Sort the gene data in the gene sample library obtained in step (2) by timestamp, and measure the similarity of the features of any two data after removing the timestamp information. If the similarity is 1, delete the data with the larger timestamp.
[0011] Preferably, the process of looping through the genes in the gene library of the same malware family, performing feature comparison, and obtaining new gene features is as follows: (1) When the malware execution actions and operating environments of two genes are different, the two genes are considered not to contain duplicate genes; (2) When the malware execution actions and operating environments of two genes are the same, but the malware targets are different, they are considered to be different execution stages of the same malicious behavior; (3) When the malware execution actions, operating environment, and execution phase of two genes are the same, the similarity of the execution action evolution path is measured. If the measurement result is lower than the set threshold, the common data of the two genes is extracted, the difference data is merged, and a new gene feature is obtained; if the measurement result is higher than the set threshold, the two genes are independent of each other.
[0012] Preferably, when associating the genes in the malicious behavior gene library with the attack paths, the order is based on the timestamp of a certain node during the operation of the malware.
[0013] Preferably, when malware is running in a system environment container, when it is detected that the malware's execution action, action object, or action evolution path has changed, a behavioral gene feature of the malware is generated based on a behavioral gene feature data format.
[0014] An attack path prediction system based on behavioral gene recognition, comprising: Action monitoring unit, used to monitor and collect behavioral genetic characteristics of various actions; The detection unit is used to input the gene feature into the prediction model to determine the attack path of the malware; the prediction model is obtained by training a deep learning model through a general gene library and a malicious behavior gene library; the acquisition process of the malicious behavior gene library is: running the malware in a system environment container to obtain the behavioral gene features of the malware; after cleaning the behavioral gene features, looping through the genes in the same malware family gene library, performing feature comparison, and obtaining new gene features; comparing family genes in different malware family gene libraries to obtain a general gene library; based on the general gene library, deleting the common genes between each family gene to obtain a malicious behavior gene library; and associating the genes in the malicious behavior gene library with the attack path.
[0015] Preferably, it also includes: System environment container, used to provide an isolated operating environment; Database, used to store data of various actions and genetic sample data.
[0016] Preferably, the action monitoring unit, the detection unit, the system environment container and the database all belong to a security detection engine, and the security detection engine is connected to a monitoring and analysis terminal; The monitoring and analysis terminal is used to receive and display data transmitted by the security detection engine in real time, and to issue instructions to the security detection engine.
[0017] Preferably, the security detection engine also includes a scheduling unit for managing processes in the security detection engine.
[0018] Compared with the prior art, the present invention has the following beneficial effects: The present invention discloses an attack path prediction method based on behavior gene recognition. The method constructs an attack path prediction model, which is a deep learning neural network obtained by training a general gene library and a malicious behavior gene library. The malicious behavior gene library is obtained by running multiple malware in a container in a system environment. During the running process, on the one hand, data on malware execution actions, action objects and path changes are captured; on the other hand, new behavior gene features can be obtained based on all gene data in a gene database, so that the method analyzes and detects the execution path of an unknown program, thereby identifying malware, and has the characteristics of high detection accuracy, good timeliness and strong adaptability. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a flow chart of the attack path prediction method based on behavioral gene identification of the present invention; Figure 2 A structural diagram of an attack path prediction system based on behavioral gene recognition provided by an embodiment of the present invention; Figure 3 The figure shows a unit functional structure diagram of an attack path prediction system based on behavioral gene identification provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0020] In the following, the terms "first", "second", "third", and "fourth" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, a feature defined as "first", "second", "third", and "fourth" may explicitly or implicitly include one or more of the features.
[0021] The co-shooting method provided in the embodiment of the present application can be applied to terminal devices such as mobile phones, tablet computers, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptop computers, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), etc. The embodiment of the present application does not impose any restrictions on the specific type of the terminal device.
[0022] It should be noted that the terms "first", "second", etc. in the specification and drawings of the present invention are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0023] See also Figure 1 The first aspect of the present invention discloses an attack path prediction method based on behavioral gene identification, comprising the following steps: Step 1: monitor and collect behavioral genetic characteristics of various actions; Step 2, inputting the gene features into a prediction model to determine the attack path of the malware; The prediction model is obtained by training a deep learning model through a general gene library and a malicious behavior gene library; the acquisition process of the malicious behavior gene library is: running the malware in a system environment container to obtain the behavioral gene characteristics of the malware; after cleaning the behavioral gene characteristics, looping through the genes in the same malware family gene library, performing feature comparison, and obtaining new gene characteristics; comparing the family genes in different malware family gene libraries to obtain a general gene library; based on the general gene library, deleting the common genes between the family genes to obtain the malicious behavior gene library; and associating the genes in the malicious behavior gene library with the attack path.
[0024] Specifically, in step 1, the behavioral gene characteristics are:
[0025] in, It is the timestamp of a node in the malware running process. is the hash of the malware, Perform actions for malware, The target of the malware. To execute the action evolution path, For the operating environment.
[0026] In step 2, the collected behavioral gene features of various actions are input into the prediction model, and the prediction model predicts the attack path of the malware based on the above behavioral gene features.
[0027] The prediction model is a deep learning model, which is obtained through training of a general gene library and a malicious behavior gene library. Specifically, the database construction process of the prediction model includes the following steps: Step 21 establishes a malware sample set based on malware families. The malware samples are put into the system environment container to run, and 21 action changes of the host machine are monitored during the operation of the malware. The behavioral gene characteristics of the malware are defined as follows based on the actions of the host machine:
[0028] in, It is the timestamp of a node in the malware running process. is the hash of the malware, The malware performs an action, specifically one of the 21 actions above. The target of the malware. To execute the action evolution path, For the operating environment.
[0029] The malware behavior gene library is a collection of temporal features of behavior genes, defined as:
[0030] in, It is a timing feature.
[0031] Step 22, for the malware behavior gene features, perform gene feature optimization, including gene data cleaning, gene merging, forming a malicious behavior gene library, and associating malicious behavior and attack behavior paths; the specific process is: (1) Gene data cleaning: removing redundant data in the sample set and clearing gene data containing invalid information. The specific process is as follows: 1) Construct a malware behavior gene sample library based on malware families.
[0032] 2) Traverse the gene data in the gene sample library and delete the gene data containing invalid information.
[0033] 3) Sort the data in the database by timestamp, and measure the similarity of any two features in the database after removing the timestamp information. , :
[0034] If there is a similarity of 1, the data with a larger timestamp will be deleted.
[0035] (2) Gene merging is performed on a family basis, specifically: 1) Since hash values can only be used to trace the malware family and cannot provide more supplementary information for malicious behavior, once the malware family has been determined, the hash information in the gene features in the gene sample library is deleted.
[0036] 2) Loop through the genes in the same malware family gene library and compare the feature information. and If they are different, the two genes are considered not to contain duplicate genes; and same, When they are different, they are considered to be different execution stages of the same behavior; when , and If they are the same, then If the similarity is lower than the set threshold, it is considered that the two genes have a high information duplication rate, and the common data is extracted, the difference data is merged, and a new gene feature is formed. If the similarity is higher than the set threshold, the two features are considered independent of each other.
[0037] (3) Compare the malware family genes, extract similar genes between families to form a common gene library, and then delete the common genes from each family gene to form a malicious behavior gene library.
[0038] (4) For each malicious behavior gene pool, In order, the malicious behavior genes are associated to form the attack behavior path.
[0039] See also Figure 3 The second aspect of the present invention discloses an attack path prediction system based on behavioral gene recognition. It includes two parts: security detection engine and monitoring and analysis terminal; Specifically, the security detection engine is connected to the monitoring and analysis terminal, and the hardware device is a general-purpose rack-mounted server device with GPU acceleration function. The monitoring and analysis terminal is an independent terminal device that can receive data obtained from the security detection engine in real time and display its actions; at the same time, it can issue instructions to the security detection engine for the action management of the security detection engine.
[0040] For further information, see Figure 3 The security detection engine and monitoring and analysis terminal include system environment container, action monitoring unit, scheduling unit, detection unit and database unit, among which: The system environment container runs on the security detection engine. It is a virtualized software system that can provide an isolated operating environment to ensure the normal operation of the software, including the operating system, services, components, tools, and dependent libraries. The system environment container has the following characteristics: (1) Network and hardware isolation to avoid the risk of malicious programs escaping; (2) It has software execution conditions in both running and debugging states and is not easily identified as an isolated test environment by malware detection mechanisms; (3) The process is controllable, supporting functions such as blocking, one-key restoration, process monitoring, and environment generation; (4) Have relevant security features that can bypass malware detection mechanisms.
[0041] The action monitoring unit is a software system with a C / S architecture. The server runs on the monitoring and analysis terminal, and the client runs on the security detection engine. The client collects various action data on the security detection engine in real time and sends it to the server in real time. The server receives the action data in real time and can issue instructions to complete the management of the system container environment.
[0042] The scheduling unit manages the security detection engine process, including the generation of the system container environment, the allocation of resources, the real-time detection of the detection unit, the transmission of the action monitoring unit data, and real-time operation.
[0043] The database unit is used to store various action data and sample data.
[0044] The detection unit builds a deep learning detection model to detect malware and predict attack paths. The detection unit builds a deep learning prediction model based on the TCN algorithm, and uses the general gene library and the malicious behavior gene library as training samples to train the model, which can identify malware. The TCN-based deep learning model can predict the next action based on the current attack action by learning the time-series attack behavior path.
[0045] When performing software detection, the software to be tested is run in the system environment container, and its behavioral genes are recorded in real time. Through gene data cleaning and data optimization, the processed gene features are detected through a deep learning model. If the software is detected as malware, the model can predict the five most likely attack paths for the next step based on each step of its behavioral gene action.
[0046] The present invention realizes malware detection and attack path prediction by analyzing the similarity of behavior genes of malware during operation and taking this as a judgment basis.
[0047] The following is further described in conjunction with specific embodiments.
[0048] Example 1 Figure 2 The overall structure diagram of an attack path detection unit based on behavioral gene recognition provided by an embodiment of the present invention includes a security detection engine S1 and a monitoring and analysis terminal S2, specifically: The security detection engine is connected to the monitoring and analysis terminal. The hardware device is a general-purpose rack-mounted server device with a GPU acceleration function. In the embodiment of the present invention, the security detection engine has two 4090 graphics cards.
[0049] The monitoring and analysis terminal is an independent terminal device that can receive data obtained from the security detection engine in real time and display its actions. It can also send instructions to the security detection engine for the action management of the security detection engine.
[0050] like Figure 2 The figure shows a functional structure diagram of an attack path detection unit based on behavior gene recognition provided by an embodiment of the present invention, which includes a system environment container S21, an action monitoring unit S22, a scheduling unit S23, a detection unit S24, and a database S25.
[0051] The system environment container S21 is a system application deployed on the security detection engine. It is a virtualized software system similar to a honeypot in function. It can provide an isolated operating environment and ensure the normal operation of the software. The system environment container provided in the embodiment of the present invention includes the operating environment of various sub-versions of Windows and Linux, including operating systems, services, components, tools, and dependent libraries. It should be noted that the system environment types can be expanded according to actual conditions, including but not limited to Android, Unix, etc. The system environment container has the following characteristics: (1) The system environment is isolated from other production environments in terms of network and hardware to avoid the risk of escape of malicious programs during operation; (2) The system environment has the software execution conditions in the running state and the debugging state, has good security and concealment, and is not easily identified as an isolated test environment by malware detection mechanisms; (3) The system environment process is controllable, supporting functions such as blocking, one-click restoration, process monitoring, and environment generation; (4) The system environment has relevant security functions that can bypass the malware detection mechanism, thereby ensuring the normal operation of malicious programs.
[0052] The action monitoring unit S22 is a software system with a C / S architecture. The server runs on the monitoring and analysis terminal, and the client runs on the security detection engine. The client collects various action data on the security detection engine in real time and sends it to the server in real time. The server receives the action data in real time and can issue instructions to complete the management of the system container environment. The system container environment process blocking, environment restoration, process monitoring and environment generation instructions are all issued through the action monitoring unit.
[0053] The scheduling unit S23 implements the management of the security detection engine process, including the generation of the system container environment, the allocation of resources, the real-time detection of the detection unit, the transmission of the action monitoring unit data and the real-time operation.
[0054] The detection unit S24 realizes the detection of malicious software and the prediction of attack paths by establishing an intelligent detection model.
[0055] The database S25 is used to store various action data and sample data.
[0056] The attack path prediction method using the above system includes the following steps: (1) Establishing a malware sample set. The sample set provided in this embodiment is based on malware families. Each malware family refers to malware entities and variant programs with the same code, hash, behavior, or other relevant application features, including malware families such as LockBit, Hive, GandCrab, Babuk, Cerber, Matsnu, Wannacry, Congur, Locky, Teslacrypt, Rkor, Reveon, etc.
[0057] The malware samples are put into the system environment container for execution. By monitoring the malware running process, the host machine action changes are detected in real time, including the following 21 host action changes: (1) deleting key registry information; (2) creating kernel objects; (3) creating files; (4) modifying memory permissions; (5) modifying the registry; (6) creating processes; (7) writing files; (8) sending DNS requests; (9) loading libraries; (10) sending network data packets; (11) connecting to sockets; (12) executing shellcode instructions; (13) executing heap instructions; (14) creating services; (15) writing to process memory; (16) executing ret instructions; (17) executing esp instructions; (18) creating threads; (19) listening to ports; (20) reading and writing files; and (21) abnormal network external connections.
[0058] The behavioral genetic signatures of malware are defined as:
[0059] in, It is the timestamp of a node in the malware running process. is the hash of the malware, The malware performs an action, specifically one of the 21 actions above. The target of the malware. To execute the action evolution path, For the operating environment.
[0060] The malware behavior gene library is a collection of malware behavior gene features. The monitoring process detects each action of the system environment container in real time. When it detects that the malware execution action, action object or action evolution path changes, it directly records the data and generates malware behavior gene features based on the behavior gene feature data format. The malware behavior gene library is a collection of time series features of behavior genes, which is defined as:
[0061] Optimize the genetic features of malware behavior, such as Figure 3 The figure shows a flow chart of the gene feature optimization method provided by an embodiment of the present invention, and the specific process is as follows: (1) Gene data cleaning. Gene data cleaning removes redundant data from the sample set and removes gene data containing invalid information, ensuring that each gene accurately contains valid malicious information, improving data quality, and avoiding large storage and computing costs. The data cleaning process is as follows: 1) Construct a malware behavior gene sample library based on malware families.
[0062] 2) Traverse the data in the database to check whether it contains invalid information. If it contains invalid information, delete the data.
[0063] 3) Sort the data in the database by timestamp, and measure the similarity of any two features in the database after removing the timestamp information. , :
[0064] If there is a similarity of 1, the data with a larger timestamp will be deleted.
[0065] (2) Family gene pool data optimization. Gene merging is performed based on the family as a unit. The merging steps are as follows: 1) The hash information in the gene information represents the subdivision of malware and can only be used to trace the malware family. It cannot provide more supplementary information for malicious behavior. Therefore, if the family to which the malware belongs has been determined, the hash information in the malicious behavior gene features in the library is deleted.
[0066] 2) Loop through the genes in the same malware family gene library and compare the feature information. and If they are different, the two genes are considered not to contain duplicate genes; and same, When they are different, they are considered to be different execution stages of the same behavior; when , and If they are the same, then If the similarity is lower than the set threshold, it is considered that the two genes have a higher information repetition rate, and the common part data is extracted, the difference data is merged, and a new gene feature is formed. If the similarity is higher than the set threshold, the two features are considered to be independent of each other. It should be noted that the threshold set in this embodiment is an adaptive threshold, which is continuously optimized and adjusted by the machine learning model, and the range is between 85% and 92%.
[0067] (3) Gene comparison between families. Compare the genes of malware families, extract similar genes between families to form a common gene library, and then delete the common genes from the genes of each family to form a malicious behavior gene library.
[0068] (4) Malicious behavior attack path generation. For each malicious behavior gene library, In order, the malicious behavior genes are associated to form the attack behavior path.
[0069] A deep learning prediction model is established based on the TCN algorithm, and the general gene library and malicious behavior gene library are used as training samples for model training, which can realize the identification of malware. By learning the time-series attack behavior path, the next action can be predicted based on the current attack action.
[0070] When performing software detection, the software to be tested is run in the system environment container, and its behavioral genes are recorded in real time. Through gene data cleaning and data optimization, the processed gene features are detected through a deep learning model. If the software is detected as malware, the model can predict the five most likely attack paths for the next step based on each step of its behavioral gene action.
[0071] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for predicting attack paths based on behavioral gene recognition, characterized in that: The following steps are involved: Monitor and collect behavioral genetic characteristics of various actions; Inputting the behavioral gene features into a prediction model to determine the attack path of the malware; The prediction model is obtained by training a deep learning model through a general gene library and a malicious behavior gene library; the acquisition process of the malicious behavior gene library is: running the malware in a system environment container to obtain the behavioral gene characteristics of the malware; after cleaning the behavioral gene characteristics, looping through the genes in the gene library of the same malware family, performing feature comparison, and obtaining new gene characteristics; Compare the family genes in the gene libraries of different malware families to obtain a common gene library; based on the common gene library, delete the common genes between the genes of each family to obtain a malicious behavior gene library; Associate genes in the malicious behavior gene library with attack paths.
2. The attack path prediction method based on behavioral gene recognition according to claim 1 is characterized in that: The behavioral gene characteristics are: in, It is the timestamp of a node in the malware running process. is the hash of the malware, Perform actions for malware, The target of the malware. To execute the action evolution path, For the operating environment.
3. The attack path prediction method based on behavioral gene recognition according to claim 1 is characterized in that: The cleaning of the behavioral gene characteristics comprises the following steps: (1) Construct a sample library of malware behaviors based on malware families; (2) Traverse the gene data in the gene sample library and delete genes containing invalid information; (3) Sort the gene data in the gene sample library obtained in step (2) by timestamp, and measure the similarity of the features of any two data after removing the timestamp information. If the similarity is 1, delete the data with the larger timestamp.
4. The attack path prediction method based on behavioral gene recognition according to claim 1 is characterized in that: The process of looping through the genes in the gene library of the same malware family, performing feature comparison, and obtaining new gene features is as follows: (1) When the malware execution actions and operating environments of two genes are different, the two genes are considered not to contain duplicate genes; (2) When the malware execution actions and operating environments of two genes are the same, but the malware targets are different, they are considered to be different execution stages of the same malicious behavior; (3) When the malware execution actions, operating environments, and execution stages of two genes are the same, the similarity of the execution action evolution paths is measured. If the measurement result is lower than the set threshold, the common data of the two genes is extracted, the difference data is merged, and a new gene feature is obtained; If the metric result is higher than the set threshold, the two genes are independent of each other.
5. The attack path prediction method based on behavioral gene recognition according to claim 1 is characterized in that: When associating genes in the malicious behavior gene library with attack paths, the order is based on the timestamp of a certain node in the malware's running process.
6. The attack path prediction method based on behavioral gene recognition according to claim 1 is characterized in that: When malware is running in the system environment container, if changes are detected in the malware's execution action, action object, or action evolution path, the malware's behavioral gene features are generated based on the behavioral gene feature data format.
7. An attack path prediction system based on behavioral gene recognition, characterized in that: include: Action monitoring unit, used to monitor and collect behavioral genetic characteristics of various actions; The detection unit is used to input the gene feature into the prediction model to determine the attack path of the malware; the prediction model is obtained by training the deep learning model through the general gene library and the malicious behavior gene library; the acquisition process of the malicious behavior gene library is: running the malware in the system environment container to obtain the behavior gene feature of the malware; after cleaning the behavior gene feature, looping through the genes in the gene library of the same malware family, performing feature comparison, and obtaining new gene features; Compare the family genes in the gene libraries of different malware families to obtain a common gene library; based on the common gene library, delete the common genes between the genes of each family to obtain a malicious behavior gene library; Associate genes in the malicious behavior gene library with attack paths.
8. The attack path prediction system based on behavioral gene recognition according to claim 7 is characterized in that: Also includes: System environment container, used to provide an isolated operating environment; Database, used to store data of various actions and genetic sample data.
9. The attack path prediction system based on behavioral gene recognition according to claim 8 is characterized in that: The action monitoring unit, detection unit, system environment container and database all belong to a security detection engine, and the security detection engine is connected to a monitoring and analysis terminal; The monitoring and analysis terminal is used to receive and display data transmitted by the security detection engine in real time, and to issue instructions to the security detection engine.
10. The attack path prediction system based on behavioral gene recognition according to claim 9, characterized in that: The security detection engine also includes a scheduling unit for managing processes in the security detection engine.
Citation Information
Cited By
Malicious deletion traceability method of distributed file system based on block chain
CN120386768A