Vulnerability and attack technique and tactics association analysis large model training method, device and equipment
Through network security knowledge graph analysis and large-scale model training, the problem of relying on human experience in network vulnerability analysis in the existing technology is solved, and accurate analysis of network vulnerabilities and efficient prevention of security incidents is achieved.
Patent Information
- Application Number
- CN202510512026.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-04-23
AI Technical Summary
The existing technology relies on human experience in preventing network security incidents, which makes it difficult to accurately analyze and repair network vulnerabilities, which in turn causes network security accidents such as software damage and hardware damage to computer equipment.
Through the network security knowledge graph, multiple different levels of associated entities of each network vulnerability are determined, network vulnerability features and entity features are obtained, aggregated features generate aggregated network vulnerability features, and similar aggregated network vulnerability features are generated through similarity analysis. Finally, feature text is input into the vulnerability and attack technology and tactical correlation analysis large model, the predicted security analysis results are output, and the model is trained through differential training.
It realizes accurate analysis of network vulnerabilities and outputs of security analysis results, improves the automation level and analysis accuracy of network security prevention, reduces human errors, and enhances the protection capabilities of network security.
Smart Images

Figure CN120046758A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly relates to a method, device, and equipment for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics. Background Art
[0002] With the development of network technology, network security is becoming increasingly important at present. Network security incidents in the network may occur at any time. If vulnerability analysis of network security incidents is not carried out in a timely manner, network security accidents will occur, such as network intrusion, network attack, data theft and other network security accidents. Therefore, it is necessary to prevent network security incidents to ensure network security.
[0003] In related technologies, for the prevention of network security incidents, it is often based on human experience. For example, a security database is set up, and the network vulnerabilities corresponding to network security incidents are found through the security database, and then the network vulnerabilities are analyzed and repaired. However, due to limited human experience, it will lead to inaccurate analysis of the network vulnerabilities corresponding to network security incidents, so that the network vulnerabilities cannot be repaired, and ultimately network security accidents such as software damage and hardware damage of computer devices will occur. Summary of the Invention
[0004] An embodiment of this application provides a method, device, and equipment for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics. The trained large model for analyzing the association between vulnerabilities and attack techniques and tactics can accurately analyze the network vulnerabilities to be processed and output the target security analysis results.
[0005] To achieve the above object, an embodiment of this application on the one hand provides a method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics, including: Determine multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity; Determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features; Determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; Determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the large model for analyzing the association between vulnerabilities and attack techniques and tactics, and output the predicted security analysis results corresponding to each network vulnerability, where the predicted security analysis results include the techniques and tactics corresponding to each network vulnerability; Determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the large model for vulnerability and attack technique - tactic association analysis according to the difference to obtain the trained large model for vulnerability and attack technique - tactic association analysis.
[0006] To achieve the above object, on the one hand, an embodiment of the present application provides a training device for a large model for vulnerability and attack technique - tactic association analysis, including: The first determination module is used to determine multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity; The second determination module is used to determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features; The third determination module is used to determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; The input module is used to determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the large model for vulnerability and attack technique - tactic association analysis to output the predicted security analysis result corresponding to each network vulnerability, where the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability; The training module is used to determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the large model for vulnerability and attack technique - tactic association analysis according to the difference to obtain the trained large model for vulnerability and attack technique - tactic association analysis.
[0007] In some embodiments, the second determination module includes a first processing sub - module, a first fusion sub - module, a second processing sub - module, a second fusion sub - module, and a determination sub - module; The first processing sub - module is used to determine the to - be - processed associated entity at the current level in the associated entities and the to - be - processed associated entity features corresponding to the to - be - processed associated entity; The first fusion sub - module is used to perform feature fusion processing on the to - be - processed associated entity features and the network vulnerability features to generate the updated network vulnerability features corresponding to each network vulnerability; The second processing sub - module is used to determine the to - be - processed associated entity at the next level of the current level in the associated entities and the to - be - processed associated entity features corresponding to the to - be - processed associated entity; A second fusion sub-module, configured to perform feature fusion processing on the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate the target updated network vulnerability features corresponding to each network vulnerability; A determination sub-module, configured to determine the target updated network vulnerability features as the updated network vulnerability features, determine the next level as the current level, and return to execute the to-be-processed associated entities at the next level determined in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities, until the current level is the highest level, and determine the updated network vulnerability features corresponding to the highest level as the aggregated network vulnerability features corresponding to each network vulnerability.
[0008] In some embodiments, the first fusion sub-module is configured to: Sum up each of the to-be-processed associated entity features and then calculate the average value to obtain a first entity feature; Perform weighted summation on the first entity feature and the network vulnerability features to obtain the updated network vulnerability features corresponding to each network vulnerability.
[0009] In some embodiments, the first fusion sub-module is configured to: Obtain a first weight value corresponding to the first entity feature and a second weight value corresponding to the network vulnerability features; Multiply the first weight value by the first entity feature to obtain a first feature; Multiply the second weight value by the network vulnerability features to obtain a second feature; Add the first feature and the second feature to obtain the updated network vulnerability features corresponding to each network vulnerability.
[0010] In some embodiments, the second fusion sub-module is configured to: Sum up each of the to-be-processed associated entity features corresponding to the next level and then calculate the average value to obtain a second entity feature; Perform weighted summation on the second entity feature and the updated network vulnerability features to obtain the target updated network vulnerability features corresponding to each network vulnerability.
[0011] In some embodiments, the first determination module is configured to: Obtain a first description text corresponding to each network vulnerability and a second description text corresponding to each associated entity; Input the first description text into a pre-trained text processing model, and output the network vulnerability features corresponding to each network vulnerability; Input the second description text into a pre-trained text processing model, and output the entity features corresponding to each associated entity.
[0012] In some embodiments, a third determination module is configured to: Determine the similarity between the aggregated network vulnerability features corresponding to each network vulnerability and other aggregated network vulnerability features; Determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than a preset similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.
[0013] In some embodiments, the vulnerability and attack technique - tactic association analysis large - model training device further includes a graph generation module, which is configured to: Before determining multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, determine multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability; Determine the entity relationships between each network vulnerability, the vulnerability weakness instances, the vulnerability attack instances, the techniques, and the tactics; Construct a network security knowledge graph corresponding to the multiple network vulnerabilities according to the entity relationships, each network vulnerability, the vulnerability weakness instances, the vulnerability attack instances, the techniques, and the tactics.
[0014] In some embodiments, an input module is configured to: Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability according to the aggregated network vulnerability features; Generate a first associated path text and a first vulnerability description text according to the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability; Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability according to the similar aggregated network vulnerability features; Generate a second associated path text and a second vulnerability description text according to the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities; Generate a prompt text corresponding to each network vulnerability according to the first associated path text, the first vulnerability description text, the second associated path text, and the second vulnerability description text.
[0015] To achieve the above object, an embodiment of the present application provides a network security analysis method on the one hand, including: Determine multiple target associated entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity; Determine the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature; Determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features; Determine the target prompt text corresponding to the network vulnerability to be processed according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature; Input the target prompt text into the trained vulnerability and attack technique and tactic correlation analysis large model, and output the target security analysis result corresponding to the network vulnerability to be processed, where the target security analysis result includes the techniques and tactics corresponding to the network vulnerability to be processed. Among them, the trained vulnerability and attack technique and tactic correlation analysis large model is trained based on the vulnerability and attack technique and tactic correlation analysis large model training method provided in the embodiments of the present application.
[0016] To achieve the above object, on the one hand, an embodiment of the present application provides a network security analysis device, including: An entity determination module, configured to determine multiple different-level target associated entities corresponding to the network vulnerability to be processed according to a network security knowledge graph, and determine the target network vulnerability feature corresponding to the network vulnerability to be processed and the target entity feature corresponding to each target associated entity; A feature determination module, configured to determine the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature; A similarity determination module, configured to determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features; A text generation module, configured to determine the target prompt text corresponding to the network vulnerability to be processed according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature; A prediction module, configured to input the target prompt text into the trained vulnerability and attack technique and tactic correlation analysis large model, and output the target security analysis result corresponding to the network vulnerability to be processed, where the target security analysis result includes the techniques and tactics corresponding to the network vulnerability to be processed. Among them, the trained vulnerability and attack technique and tactic correlation analysis large model is trained based on the vulnerability and attack technique and tactic correlation analysis large model training method provided in the embodiments of the present application.
[0017] To achieve the above object, on the one hand, an embodiment of the present application provides a computer-readable storage medium storing multiple instructions adapted to be loaded by a processor to execute the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by an embodiment of the present application or the network security analysis method provided by an embodiment of the present application.
[0018] To achieve the above object, on the one hand, an embodiment of the present application provides a computer device including a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor executes the computer program, it implements the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by an embodiment of the present application or the network security analysis method provided by an embodiment of the present application.
[0019] In an embodiment of the present application, multiple association entities at different levels corresponding to each network vulnerability are determined according to a network security knowledge graph, and a network vulnerability feature corresponding to each network vulnerability and an entity feature corresponding to each association entity are determined; an aggregated network vulnerability feature corresponding to each network vulnerability is determined according to the network vulnerability feature and the entity feature; a similar aggregated network vulnerability feature corresponding to each network vulnerability is determined according to the similarity between different aggregated network vulnerability features; a prompt text corresponding to each network vulnerability is determined according to the aggregated network vulnerability feature and the similar aggregated network vulnerability feature, and the prompt text is input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics to output a predicted security analysis result corresponding to each network vulnerability; the difference between the label security analysis result and the predicted security analysis result corresponding to each network vulnerability is determined, and the large model for analyzing the association between vulnerabilities and attack techniques and tactics is trained according to the difference to obtain a trained large model for analyzing the association between vulnerabilities and attack techniques and tactics.
[0020] Therefore, multiple associated entities at different levels corresponding to each network vulnerability are determined through the network security knowledge graph. Then, the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained. Next, based on the network vulnerability features of each network vulnerability combined with the entity features of the corresponding associated entities, the aggregated network vulnerability features corresponding to each network vulnerability are obtained, realizing that each network vulnerability is combined with the multi-level associated entities, enabling the aggregated network vulnerability features to represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined through the similarity between different aggregated network vulnerability features. The prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The prompt text determined in this way can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, thereby making the prompt text input into the vulnerability and attack technique and tactic association analysis large model more comprehensive, enabling the vulnerability and attack technique and tactic association analysis large model to learn more network security knowledge, and thus realizing the efficient training of the vulnerability and attack technique and tactic association analysis large model. Compared with the solution in the related art of determining the security analysis result corresponding to the network vulnerability based on human experience, the vulnerability and attack technique and tactic association analysis large model trained in this application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the techniques and tactics for attacking the network vulnerability to be processed.
[0021] Other features and advantages of the present application will be described in the subsequent description, and in part, will be obvious from the description, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the description, the claims, and the drawings. Brief Description of the Drawings
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.
[0023] Figure 1 It is a schematic diagram of the system framework corresponding to the vulnerability and attack technique and tactic association analysis large model training method and the network security analysis method provided by the embodiments of the present application; Figure 2 It is a schematic diagram of the processing process corresponding to the network security analysis method provided by the embodiments of the present application; Figure 3It is a schematic flowchart of the method for training the vulnerability and attack technique and tactics association analysis large model provided by the embodiments of the present application; Figure 4 It is a schematic diagram of the network security knowledge graph provided by the embodiments of the present application; Figure 5 It is a schematic flowchart included in step 220 provided by the embodiments of the present application; Figure 6 It is another schematic flowchart of the method for training the vulnerability and attack technique and tactics association analysis large model provided by the embodiments of the present application; Figure 7 It is a schematic flowchart of the network security analysis method provided by the present application; Figure 8 It is a schematic structural diagram of the vulnerability and attack technique and tactics association analysis large model training device provided by the embodiments of the present application; Figure 9 It is a schematic structural diagram of the network security analysis device provided by the embodiments of the present application; Figure 10 It is a schematic structural diagram of the computer device provided by the embodiments of the present application. Detailed implementation manners
[0024] In order to enable the personnel in the technical field of the present application to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts belong to the scope of protection of the present application.
[0025] It should be noted that in each specific implementation manner of the present application, when it comes to the need to perform relevant processing according to the data related to network security information, the permission or consent of the object will be obtained first, and moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of the present application need to obtain the sensitive personal information of the object, the separate permission or separate consent of the object will be obtained through methods such as pop-up windows or jumping to the confirmation page. After clearly obtaining the separate permission or separate consent of the object, the necessary object-related data for the normal operation of the embodiments of the present application will be obtained.
[0026] It should be noted that in some processes described in the specification, claims, and the above-mentioned drawings, multiple steps appear in a specific order. However, it should be clearly understood that these steps can be executed not in the order in which they appear in this document or in parallel. The step numbers are only used to distinguish different steps, and the numbers themselves do not represent any execution order. In addition, descriptions such as "first", "second", or "target" in this document are used to distinguish similar objects and do not necessarily describe a specific order or sequence.
[0027] The method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method provided by the embodiments of the present application relate to the field of artificial intelligence technology. The method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method provided by the embodiments of the present application can be applied to terminals, can also be applied to the server side, or can be software running on the terminal or the server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, can also be configured as a server cluster or a distributed system composed of multiple physical servers, or can be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method, but is not limited to the above forms.
[0028] Before further elaborating on the embodiments of the present application, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are applicable to the following explanations: Network vulnerability: A network vulnerability refers to a security flaw or weakness existing in the design, implementation, configuration, or maintenance process of a computer network system (including hardware, software, network protocols, etc.). These vulnerabilities make the network system vulnerable to exploitation by attackers, resulting in security incidents such as information leakage, system damage, and service interruption. For example, a buffer overflow vulnerability in software code may give an attacker the opportunity to execute malicious code on the target system. In the present application, a network vulnerability can be a Common Vulnerabilities and Exposures (CVE). CVE is used to assign a unique identifier to information security vulnerabilities and exposures. It is like a unified "ID card" system that numbers and records various software, hardware, system, etc. security issues.
[0029] Vulnerability and Weakness Example: Specifically, it can be the Common Weakness Enumeration (CWE), which is used to classify and describe security weaknesses in software and hardware systems. A CVE vulnerability can usually be mapped to one or more CWE weakness categories.
[0030] Vulnerability Attack Example: Specifically, it can be the Common Attack Pattern Enumeration and Classification (CAPEC). CAPEC is a comprehensive knowledge base of attack patterns, used to classify and enumerate network attack patterns. It is like a "tactical manual" for attackers, describing how to exploit vulnerabilities and weaknesses for attacks. CWE defines the weaknesses in the system, while CAPEC shows how to exploit these weaknesses for attacks. The association between them helps security defenders think from the perspective of attackers, thus better formulating defense measures. CAPEC is the basis of Tactic and Technique. Tactic guides the use of Technique, and Technique is the specific means to implement the attack patterns in CAPEC.
[0031] Technique: That is, attack technique, which refers to the specific technical means adopted by attackers during the implementation of attacks, such as using specific tools, scripts, or codes to achieve the attack purpose.
[0032] Tactic: That is, attack tactic, which is a higher-level plan. It is a series of strategic actions taken by attackers to achieve goals (such as obtaining data, destroying the system, etc.), including selecting attack targets, timing, and combining the use of multiple attack techniques, etc.
[0033] Knowledge Graph: A knowledge graph is a semantic network with extremely strong expressive power and modeling flexibility. Essentially, it is a semantic knowledge base that depicts various concepts in the real world and their relationships with each other in symbolic form. The basic unit is the triple of "entity-relationship-entity". A knowledge graph can be regarded as a graph composed of nodes and edges. Nodes represent entities or concepts in the physical world, and edges represent various semantic relationships between entities or concepts. Through such a graph structure, the complex associations between various entities can be clearly shown, integrating fragmented knowledge into an organic whole.
[0034] The above are the noun explanations of the relevant professional terms involved in this application. If there are other professional terms involved in the following text, they will be explained later.
[0035] First, describe the technical problems existing in the related technologies: With the development of network technology, network security is becoming increasingly important at present. Network security incidents in the network may occur at any time. If vulnerability analysis of network security incidents is not carried out in a timely manner, network security accidents will occur, such as network intrusion, network attack, data theft and other network security accidents. Therefore, it is necessary to prevent network security incidents to ensure network security.
[0036] In related technologies, for the prevention of network security incidents, it is often based on human experience. For example, a security database is set up to find out the network vulnerabilities corresponding to network security incidents through the security database, and then the network vulnerabilities are analyzed and repaired. However, due to limited human experience, it will lead to inaccurate analysis of the network vulnerabilities corresponding to network security incidents, making the network vulnerabilities unable to be repaired, and ultimately causing network security accidents such as software damage and hardware damage of computer devices.
[0037] To solve the above technical problems, the embodiments of the present application provide a method for training a large model for associating vulnerabilities with attack techniques and tactics, a network security analysis method, a device, a computer device and a storage medium. Among them, a plurality of associated entities at different levels corresponding to each network vulnerability are determined through a network security knowledge graph, and then the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained. Then, according to the network vulnerability features of each network vulnerability combined with the entity features of the corresponding associated entity, the aggregated network vulnerability features corresponding to each network vulnerability are obtained, realizing that each network vulnerability is combined with the associated multi-level associated entities, so that the aggregated network vulnerability features can represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined through the similarity between different aggregated network vulnerability features. The prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The prompt text determined in this way can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, so that the prompt text input into the large model for associating vulnerabilities with attack techniques and tactics is more comprehensive, enabling the large model for associating vulnerabilities with attack techniques and tactics to learn more network security knowledge, thereby realizing the efficient training of the large model for associating vulnerabilities with attack techniques and tactics. Compared with the solution of determining the security analysis result corresponding to the network vulnerability based on human experience in the related technology, the trained large model for associating vulnerabilities with attack techniques and tactics of the present application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the techniques and tactics for attacking the network vulnerability to be processed.
[0038] A method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics, as well as a network security analysis method, device, computer equipment, and storage medium provided by an embodiment of the present application will be described in detail hereinafter.
[0039] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the system framework corresponding to the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics, as well as the network security analysis method provided by an embodiment of the present application. The method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics, as well as the network security analysis method provided by an embodiment of the present application can be applied to this system framework.
[0040] It includes a terminal 140, the Internet 130, a gateway 120, a server 110, etc.
[0041] The terminal 140 or the server 110 can be a device that executes the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics or the network security analysis method.
[0042] The terminal 140 includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. Embodiments of the present application can be applied to various scenarios, including but not limited to network security, network defense, etc. Additionally, it can be a single device or a collection of multiple devices combined. For example, multiple desktop computers are interconnected through a local area network and share a single display, etc. to work collaboratively, jointly constituting a terminal 140. The terminal 140 can communicate with the Internet 130 in a wired or wireless manner to exchange data.
[0043] The server 110 refers to a computer system that can provide certain services to the terminal 140. Compared with ordinary terminals 140, the server 110 has higher requirements in terms of stability, security, performance, etc. The server 110 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms.
[0044] The gateway 120 is also known as an inter-network connector and protocol converter. The gateway realizes network interconnection at the transport layer and is a computer system or device that acts as a converter. Between two systems that use different communication protocols, data formats, or languages, and even have completely different architectures, the gateway is a translator. At the same time, the gateway can also provide filtering and security functions. Messages sent from the terminal 140 to the server 110 need to be sent to the corresponding server 110 through the gateway 120. Messages sent from the server 110 to the terminal 140 also need to be sent to the corresponding terminal 140 through the gateway 120.
[0045] The method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method in the embodiments of the present application can be applied to various scenarios, such as cloud services, network security, etc. The scenarios to which the method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method in the present application are applied are not limited herein.
[0046] Please refer to Figure 2 , Figure 2 which is a schematic diagram of the processing process corresponding to the network security analysis method provided by the embodiments of the present application.
[0047] In the present application, network security analysis is mainly based on the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics. When a network vulnerability to be processed is found in the network, multiple target associated entities at different levels corresponding to the network vulnerability to be processed are determined according to the network security knowledge graph.
[0048] For example, network knowledge related to the network vulnerability to be processed can be obtained from the network security knowledge graph, such as obtaining vulnerability weakness instances, vulnerability attack instances, tactics, and technologies corresponding to the network vulnerability to be processed. These entities can be used as target associated entities corresponding to the network vulnerability to be processed. These target associated entities can be neighbor entities corresponding to the network vulnerability to be processed, or other entities associated with the neighbor entities corresponding to the network vulnerability to be processed. Therefore, multiple target associated entities correspond to multiple levels. The target associated entity closer to the network vulnerability to be processed corresponds to a lower level, and the target associated entity farther from the network vulnerability to be processed corresponds to a higher level.
[0049] Then, the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity are determined. For example, the description texts corresponding to the network vulnerability to be processed and each target associated entity can be obtained, and then the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity are generated according to the respectively corresponding description texts.
[0050] Furthermore, the target aggregated network vulnerability features corresponding to the network vulnerability to be processed are determined according to the target network vulnerability features and the target entity features. The target similar aggregated network vulnerability features corresponding to the network vulnerability to be processed are determined according to the similarity between different target aggregated network vulnerability features.
[0051] Among them, the target similar aggregated network vulnerability features specifically correspond to the target similar network vulnerabilities similar to the network vulnerability to be processed. And the target aggregated network vulnerability features correspond to the network vulnerability to be processed.
[0052] Finally, determine the target prompt text corresponding to the network vulnerability to be processed based on the target aggregated network vulnerability features and the target similar aggregated network vulnerability features, and input the target prompt text into the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the target security analysis result corresponding to the network vulnerability to be processed.
[0053] For example, the target aggregated network vulnerability features and the target similar aggregated network vulnerability features can be respectively input into a pre-trained text generation model to output the target prompt text. Finally, input the target prompt text into the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the target security analysis result corresponding to the network vulnerability to be processed. For example, output the association analysis result of the technology and tactics corresponding to the network vulnerability to be processed, including the technologies and tactics that the network vulnerability to be processed may be exploited, as well as relevant explanations and defense deployment suggestions. For example, for the network vulnerability to be processed, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics can not only give the associated technology (such as "Command and Scripting Interpreter") and tactics (such as "Execution"), but also provide specific defense measures (such as "Implement input validation" or "Enable log monitoring").
[0054] As can be seen from the above, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics in this application can accurately analyze the network vulnerability to be processed, so as to obtain the target network security analysis result. Compared with the solution in the related technology that can only perform security analysis on the network vulnerability to be processed based on human experience, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics in this application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the technologies and tactics for the network vulnerability to be processed to be attacked.
[0055] To more clearly understand the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of this application, please refer to Figure 3 , Figure 3 which is a schematic flowchart of the method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of this application. The method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics may include the following steps: Step 210: Determine multiple different-level associated entities corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity; Step 220: Determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features; Step 230: Determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; Step 240: Determine the hint text corresponding to each network vulnerability based on the aggregated network vulnerability characteristics and similar aggregated network vulnerability characteristics, and input the hint text into the large model for correlation analysis of vulnerabilities and attack techniques and tactics to output the predicted security analysis results corresponding to each network vulnerability. The predicted security analysis results include the techniques and tactics corresponding to each network vulnerability. Step 250: Determine the differences between the label security analysis results and the predicted security analysis results corresponding to each network vulnerability, and train the large model for correlation analysis of vulnerabilities and attack techniques and tactics based on the differences to obtain the trained large model for correlation analysis of vulnerabilities and attack techniques and tactics.
[0056] Before describing Steps 210 to 250 in detail, first explain the generation process of the network security knowledge graph.
[0057] Before determining the multiple associated entities at different levels corresponding to each network vulnerability based on the network security knowledge graph, it also includes: (1.1) Determine multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability. (1.2) Determine the entity relationships between each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic. (1.3) Construct the network security knowledge graph corresponding to multiple network vulnerabilities based on the entity relationships, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic.
[0058] Among them, network security knowledge data in the network security knowledge base can be obtained, and then these network security knowledge data are analyzed and sorted to obtain multiple entities and the entity relationships between entities. For example, the entities include network vulnerabilities, vulnerability weakness instances corresponding to network vulnerabilities, vulnerability attack instances, techniques, and tactics. Among them, the network vulnerability can be the Common Vulnerabilities and Exposures (CVE), the vulnerability weakness instance can be the Common Weakness Enumeration (CWE), the vulnerability attack instance can be the Attack Pattern Enumeration and Classification (CAPEC), the technique can be the Attack Technique, and the tactic can be the Attack Tactic.
[0059] Then determine the entity relationships between each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic in the network security knowledge database. For example, a certain network vulnerability has a certain vulnerability weakness instance, a certain vulnerability weakness instance has a certain vulnerability attack instance, a certain vulnerability attack instance is based on a certain technique, and a certain technique corresponds to a certain tactic.
[0060] Finally, multiple cybersecurity knowledge graphs corresponding to network vulnerabilities are constructed based on entity relationships, each network vulnerability, vulnerability weakness instances, vulnerability attack instances, technologies, and tactics. For example, each entity can be used as a node, that is, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technology, and tactic can be used as nodes, and the entity relationships between entities are used as edges, thereby constructing multiple cybersecurity knowledge graphs corresponding to network vulnerabilities.
[0061] It should be noted that other types of entities can also be included in the constructed cybersecurity knowledge graph, and the entities described above do not constitute a limitation on the cybersecurity knowledge graph.
[0062] For details, please refer to Figure 4 , Figure 4 which is a schematic diagram of the cybersecurity knowledge graph of the embodiments of this application.
[0063] Among them, the cybersecurity knowledge graph contains multiple nodes, such as nodes cve1, cwe1, cwe2, capec1, capec2, capec3, capec4, Technique1, Tactic3, Tactic5, Tactic6, Tactic8, etc. For the Chinese and English explanations of these nodes, please refer to the above text. Each node can be understood as an entity. For example, cve1 represents a network vulnerability with the number 1. The edges between different nodes are determined by the entity relationships between entities.
[0064] After generating the cybersecurity knowledge graph, each entity and its associated entities can be quickly found through the cybersecurity knowledge graph. It should be noted that Figure 4 the cybersecurity knowledge graph shown in Figure 4 is only for illustration, and the content shown in
[0065] The following will describe steps 210 to 250 in detail.
[0066] In step 210, multiple associated entities at different levels corresponding to each network vulnerability are determined according to the cybersecurity knowledge graph, and the network vulnerability characteristics corresponding to each network vulnerability and the entity characteristics corresponding to each associated entity are determined.
[0067] Among them, for each network vulnerability, multiple associated entities at different levels corresponding to each network vulnerability can be determined in the cybersecurity knowledge graph. The level can be understood as the degree of closeness of the relationship between the associated entity and the network vulnerability. Taking Figure 4For example, where cve1 is a network vulnerability and cwe1 is a neighbor entity of cve1, then cwe1 has the lowest level, while the relationships between cwe2, capec2, and capec3 and cve1 are indirect respectively, so the levels corresponding to cwe2, capec2, and capec3 are higher than the level of cve1.
[0068] Then, determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity. Among them, each network vulnerability corresponds to corresponding description text for describing the relevant information of each network vulnerability. Each associated entity also has corresponding description text. For example, cwe1 corresponds to relevant weakness descriptions, scoring details of the CVSS (Common Vulnerability Scoring System) matrix (such as attack complexity, scope of impact, etc.), the name of the Vendor (i.e., the company or organization that provides software products or hardware devices) and its relevant product information, etc. The features corresponding to each entity can be generated based on the description text corresponding to each entity.
[0069] In some embodiments, determining the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity includes: (1.1) Obtain the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity; (1.2) Input the first description text into a pre-trained text processing model to output the network vulnerability features corresponding to each network vulnerability; (1.3) Input the second description text into a pre-trained text processing model to output the entity features corresponding to each associated entity.
[0070] Among them, the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity can be obtained. For example, the first description text describes the exposure allocation identification number of the network vulnerability and can also describe specific content: "There is a memory corruption vulnerability in the document processing module of a certain well-known office software suite (versions X.Y and below).".
[0071] For example, the second description text describes the content of the vulnerability weakness instance corresponding to the network vulnerability, and the specific content is: "This is a security weakness in a Web application where a malicious attacker injects scripts into the web pages browsed by legitimate users to obtain user information or perform other malicious operations." The first description text can be input into a pre-trained text processing model to output the network vulnerability features corresponding to each network vulnerability. The second description text is input into the pre-trained text processing model to output the entity features corresponding to each associated entity. Among them, the pre-trained text processing model can be a BERT model, a Sentence-BERT model, etc., which can encode the first description text and the second description text to generate vectors corresponding to the first description text and the second description text respectively, that is, network vulnerability features and entity features.
[0072] In step 220, the aggregated network vulnerability features corresponding to each network vulnerability are determined according to the network vulnerability features and the entity features.
[0073] Among them, the network vulnerability features can be used to characterize the characteristics of the network vulnerabilities described in the first description text corresponding to the network vulnerabilities. However, in the process of security analysis of network vulnerabilities, other information related to the network vulnerabilities also needs to be considered so as to achieve a more comprehensive, objective and accurate security analysis of the network vulnerabilities.
[0074] Taking this into account, in this application, the network vulnerability features and the entity features of each associated entity are aggregated to combine the semantic information of the network vulnerabilities and the semantic information of the associated entities corresponding to the network vulnerabilities, so as to obtain the aggregated network vulnerability features. The aggregated network vulnerability features are used to characterize the context information of the network vulnerabilities and each associated entity in the network security knowledge graph. Therefore, the aggregated network vulnerability features can express network knowledge related to network vulnerabilities more accurately.
[0075] Please refer to Figure 5 , Figure 5 which is a schematic flowchart included in step 220 provided by an embodiment of this application. In some embodiments, determining the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features includes: Step 301, determining the to-be-processed associated entity at the current level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity among the associated entities; Step 302, performing feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate updated network vulnerability features corresponding to each network vulnerability; Step 303, determining the to-be-processed associated entity at the next level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity among the associated entities; Step 304, performing feature fusion processing according to the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate target updated network vulnerability features corresponding to each network vulnerability; Step 305: Determine the target updated network vulnerability feature as the updated network vulnerability feature, determine the next lower level as the current level, and return to execute the to-be-processed associated entities determined at the next lower level of the current level in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities until the current level is the highest level, and determine the updated network vulnerability feature corresponding to the highest level as the aggregated network vulnerability feature corresponding to each network vulnerability.
[0076] The following will describe Steps 301 to 305 in detail.
[0077] In Step 301, determine the to-be-processed associated entities at the current level in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities.
[0078] Among them, in the associated entities, the first determined level is the first level, that is, the level corresponding to the neighbor entity most closely associated with the network vulnerability. Determine the first level as the current level, and then determine the to-be-processed associated entities at the current level and the to-be-processed associated entity features corresponding to the to-be-processed associated entities.
[0079] For example, please combine Figure 4 , cve1 is a network vulnerability, and cwe1 is a neighbor entity of cve1, then the level corresponding to cwe1 is the first level, that is, the current level. cwe1 can be determined as the to-be-processed associated entity at the current level, and the entity feature of cwe1 can be determined as the to-be-processed associated entity feature.
[0080] In Step 302, perform feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate the updated network vulnerability feature corresponding to each network vulnerability.
[0081] The to-be-processed associated entities at the current level and the network vulnerability features can be subjected to feature fusion processing to generate the updated network vulnerability feature corresponding to each network vulnerability. For example, the to-be-processed associated entity features and the network vulnerability features are actually vectors, and these vectors can be added and fused to obtain the updated network vulnerability feature corresponding to each network vulnerability.
[0082] In some embodiments, performing feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate the updated network vulnerability feature corresponding to each network vulnerability includes: (1.1) Calculate the mean value after adding each to-be-processed associated entity feature to obtain the first entity feature; (1.2) Perform weighted summation on the first entity feature and the network vulnerability feature to obtain the updated network vulnerability feature corresponding to each network vulnerability.
[0083] Among them, each associated entity feature to be processed can be added to obtain an addition result, then the total quantity corresponding to the associated entity feature to be processed is determined, and then the addition result is divided by the total quantity to obtain the first entity feature, and the first entity feature is also a vector.
[0084] Then, the first entity feature and the network vulnerability feature are weighted and summed to obtain the updated network vulnerability feature corresponding to each network vulnerability. The updated network vulnerability feature realizes the aggregation of the context information of the associated entities at the current level corresponding to each network vulnerability, so as to more accurately represent the corresponding semantic features of each network vulnerability in the network security knowledge graph.
[0085] In some embodiments, the weighted sum of the first entity feature and the network vulnerability feature to obtain the updated network vulnerability feature corresponding to each network vulnerability includes: (1.2.1) Obtain the first weight value corresponding to the first entity feature and the second weight value corresponding to the network vulnerability feature; (1.2.2) Multiply the first weight value by the first entity feature to obtain the first feature; (1.2.3) Multiply the second weight value by the network vulnerability feature to obtain the second feature; (1.2.4) Add the first feature and the second feature to obtain the updated network vulnerability feature corresponding to each network vulnerability.
[0086] Among them, the relationship between different levels and the first weight value can be pre-set. When the level is higher, the first weight value is lower, and the sum of the first weight value and the second weight value is equal to 1. The reason for this is that in the network security knowledge graph, the nearest neighbor entities of the network vulnerability have the most direct impact on it, while the neighbor entities' neighbor entities corresponding to the network vulnerability have an indirect impact on it. Therefore, the mapping relationship between different levels and the first weight value can be set, that is, the higher the level, the lower the first weight value.
[0087] The advantage of doing this is that it can ensure the influence of the associated entities closer to the network vulnerability on the network vulnerability, while weakening the influence of the associated entities farther away from the network vulnerability on the network vulnerability, so that when calculating the updated network vulnerability feature of the network vulnerability later, both the context information of the associated entities corresponding to the network vulnerability is retained, and the influence of the context information of the associated entities at different levels on the network vulnerability is ensured.
[0088] Therefore, the value of the current level can be obtained first, and then the first weight value corresponding to the associated entity to be processed at the current level is determined according to this value in the above preset mapping relationship. Then, the second weight value corresponding to the network vulnerability feature is obtained by subtracting the first weight value from 1.
[0089] Multiply the first weight value by the first entity feature to obtain a first feature, and multiply the second weight value by the network vulnerability feature to obtain a second feature. Both the first feature and the second feature are vectors.
[0090] Finally, add the first feature and the second feature to obtain the updated network vulnerability feature corresponding to each network vulnerability. This updated network vulnerability feature aggregates the network vulnerability feature and the context information of the to-be-processed associated entity at the current level, so as to more accurately and comprehensively represent the features of the network vulnerability, such as features in terms of network security knowledge.
[0091] In step 303, determine the to-be-processed associated entity at the next level of the current level and the to-be-processed associated entity feature corresponding to the to-be-processed associated entity among the associated entities.
[0092] For example, if the current level is the first level, the next level of the first level is the second level. In the network security knowledge graph, it is the entity adjacent to the neighbor entity corresponding to the network vulnerability entity. Combining Figure 4 , assuming the network vulnerability is cve1 and the entity at the current level is cwe1, then the entities at the next level of the current level are cwe2 and capec2, that is, the to-be-processed associated entities at the next level of the current level, and then obtain the to-be-processed associated entity features corresponding to cwe2 and capec2 respectively.
[0093] In step 304, perform feature fusion processing based on the to-be-processed associated entity feature corresponding to the next level and the updated network vulnerability feature to generate the target updated network vulnerability feature corresponding to each network vulnerability.
[0094] Among them, after determining the to-be-processed associated entity at the next level of the current level and the to-be-processed associated entity feature corresponding to the to-be-processed associated entity, the to-be-processed associated entity feature at the next level and the updated network vulnerability feature obtained above can be subjected to feature fusion processing, so as to generate the target updated network vulnerability feature corresponding to each network vulnerability.
[0095] In this way, the aggregation of the context information of the to-be-processed associated entity at the next level is realized, so as to obtain the target updated network vulnerability feature with richer feature information. The target updated network vulnerability feature can more accurately represent the context information between the network vulnerability and the associated entity, and can more accurately represent the network security knowledge about the network vulnerability in the network security knowledge graph.
[0096] In some embodiments, performing feature fusion processing based on the to-be-processed associated entity feature corresponding to the next level and the updated network vulnerability feature to generate the target updated network vulnerability feature corresponding to each network vulnerability includes: (1.1) Add up each to-be-processed associated entity feature corresponding to the next level and then calculate the average to obtain the second entity feature. (1.2) Perform weighted summation on the second entity feature and the updated network vulnerability feature to obtain the target updated network vulnerability feature corresponding to each network vulnerability.
[0097] Among them, each to-be-processed associated entity feature corresponding to the next level can be obtained, and then each to-be-processed associated entity feature at this level is added up to obtain the target addition result. Then, determine the quantity of each to-be-processed associated entity feature at this level, and finally divide the target addition result by the quantity to obtain the second entity feature.
[0098] Then, determine the value at this level, and then determine the first weight value corresponding to the to-be-processed associated entity at this level according to this value in the above preset mapping relationship. Since the level at this level is higher, the first weight value corresponding to this level is smaller than the first weight value corresponding to the previous level. Then, subtract the first weight value from 1 to obtain the second weight value corresponding to the updated network vulnerability feature.
[0099] Multiply the first weight value by the first entity feature, multiply the second weight value by the updated network vulnerability feature, and add the results of the two multiplications to obtain the target updated network vulnerability feature corresponding to each network vulnerability.
[0100] The target updated network vulnerability feature aggregates the context information of the previous updated network vulnerability feature and the to-be-processed associated entities at this level, so as to be able to represent the features of network vulnerabilities more accurately and comprehensively, such as the features in terms of network security knowledge.
[0101] In step 305, determine the target updated network vulnerability feature as the updated network vulnerability feature, determine the next level as the current level, and return to execute to determine the to-be-processed associated entities at the next level of the current level in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities until the current level is the highest level. Determine the updated network vulnerability feature corresponding to the highest level as the aggregated network vulnerability feature corresponding to each network vulnerability.
[0102] Then determine the target updated network vulnerability feature as the updated network vulnerability feature, determine the next level as the current level, and then determine whether the current level corresponds to the highest level of the associated entities of the network vulnerability. If not, return to execute to determine the to-be-processed associated entities at the next level of the current level in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities until the current level is the highest level. Determine the updated network vulnerability feature corresponding to the highest level as the aggregated network vulnerability feature corresponding to each network vulnerability.
[0103] If the current level is the highest level of the associated entity corresponding to the network vulnerability, then directly determine the target updated network vulnerability feature as the aggregated network vulnerability feature corresponding to the network vulnerability.
[0104] As can be seen from steps 301 to 305, in this application, by fusing each network vulnerability feature with the entity features of the associated entities of each network vulnerability, the context information aggregation of each network vulnerability and its associated entities in the network knowledge graph is realized, and the aggregated network vulnerability feature containing context information is obtained. The aggregated network vulnerability feature will serve as the basis for subsequent association analysis and provide high-quality semantic features for the association reasoning of the technical tactics of network vulnerabilities.
[0105] In step 230, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features.
[0106] Among them, for each network vulnerability, the aggregated network vulnerability feature of each network vulnerability can be determined through the above method, and then the similarity between the aggregated network vulnerability features corresponding to every two network vulnerabilities is determined. The similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features.
[0107] In some embodiments, determining the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features includes: (1.1) Determine the similarity between the aggregated network vulnerability feature corresponding to each network vulnerability and other aggregated network vulnerability features; (1.2) Determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.
[0108] Specifically, the cosine similarity between the aggregated network vulnerability features can be determined, and this cosine similarity is determined as the similarity between the aggregated network vulnerability features corresponding to every two network vulnerabilities.
[0109] Then, the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity are determined as the similar aggregated network vulnerability features corresponding to each network vulnerability. For example, when the similarity is greater than 80%, it is determined that the two network vulnerabilities are similar.
[0110] Through this method, the similar aggregated network vulnerability features corresponding to each network vulnerability can be determined. It is also possible to determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity and the maximum similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.
[0111] In step 240, based on the aggregated network vulnerability features and similar aggregated network vulnerability features, the prompt text corresponding to each network vulnerability is determined, and the prompt text is input into the large model for correlation analysis of vulnerabilities and attack techniques and tactics to output the predicted security analysis result corresponding to each network vulnerability. The predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability.
[0112] Among them, the aggregated network vulnerability features can be input into a pre-trained text generation model, and the pre-trained text generation model outputs a first text. Each similar aggregated network vulnerability feature is respectively input into the pre-trained text generation model, and a second text corresponding to each similar aggregated network vulnerability feature is output. Finally, the first text and the second text are determined as the prompt text corresponding to each network vulnerability. Then the prompt text is input into the large model for correlation analysis of vulnerabilities and attack techniques and tactics to output the predicted security analysis result corresponding to each network vulnerability. The predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability.
[0113] Due to the large sparsity of the network security knowledge graph, it may not be possible to extract sufficient available information (such as the network vulnerability → technique / tactic path) starting from a single current network vulnerability. Therefore, by introducing a set of entities of similar network vulnerabilities, the missing entity information of the current network vulnerability is effectively supplemented. Specifically, when the current network vulnerability lacks a complete vulnerability → technique / tactic path in the knowledge graph, the network security knowledge information associated with the network vulnerability with a high similarity to it can be used for supplementation. For example, if there is no directly associated technique or tactic path for the current network vulnerability entity, the possible association relationship can be inferred through the network security knowledge information associated with its similar network vulnerability. This method not only alleviates the sparsity problem of the network security knowledge graph but also significantly improves the integrity and accuracy of the analysis of the current network vulnerability, providing more reliable data support for subsequent reasoning and early warning.
[0114] In some embodiments, determining the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and similar aggregated network vulnerability features includes: (1.1) Determining the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability according to the aggregated network vulnerability features; (1.2) Generating a first associated path text and a first vulnerability description text according to the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability; (1.3) Determining the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability according to the similar aggregated network vulnerability features; (1.4) Generate a second associated path text and a second vulnerability description text based on the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities; (1.5) Generate a hint text corresponding to each network vulnerability based on the first associated path text, the first vulnerability description text, the second associated path text, and the second vulnerability description text.
[0115] Among them, the current network vulnerability can be determined according to the aggregated network vulnerability characteristics, then the current network vulnerability can be determined in the network security knowledge graph, and the associated vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the network vulnerability can be determined.
[0116] Then, a first associated path text and a first vulnerability description text are generated according to the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability. For example, the form of the first associated path text is: network vulnerability - vulnerability weakness - vulnerability attack - technique - tactic. In a specific scenario, for example, it can be expressed as: cve-2022-30318 -> cwe-798 -> capec-70 -> T1078 -> Defense Evasion, cve-2022-30318 -> cwe-798 -> capec-70 -> T1078 -> Defense Evasion. That is to say, the first associated path text can be multiple. Among them, cve-2022-30318 is the network vulnerability numbered 2022-30318, cwe-798 is the vulnerability weakness instance numbered 798, capec-70 is the vulnerability attack instance numbered 70, T1078 is the attack technique numbered 1078, and Defense Evasion is the defense evasion measure of the technique.
[0117] The first vulnerability description text is used to describe the network security knowledge information of the network vulnerability and the associated entities of the network vulnerability. For example, the first vulnerability description text is: "cve-2022-30318 - Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH...... cwe-798 -......".
[0118] Specific meaning: CVE-2022-30318 - Honeywell ControlEdge version R151.1 uses hard-coded credentials. According to FSCT-2022-0056, there is a problem with hard-coded credentials in Honeywell ControlEdge. The characteristics of the affected components are: SSH... CWE-798...
[0119] Among them, Honeywell ControlEdge is a product name launched by Honeywell. Its specific functions and uses may vary depending on different application scenarios. It may be a control system, software, or other products related to the fields of industrial automation, control, etc.
[0120] According to the characteristics of similar aggregated network vulnerabilities, similar network vulnerabilities similar to the network vulnerability can be determined, and then the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability can be determined in the network security knowledge graph.
[0121] Then, the second associated path text and the second vulnerability description text are generated through the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities. The form of the second associated path text is: Network Vulnerability - Vulnerability Weakness - Vulnerability Attack - Technique - Tactics. The second vulnerability description text is used to describe the network security knowledge information of the similar network vulnerabilities and the associated entities of the similar network vulnerabilities.
[0122] Finally, the hint text corresponding to each network vulnerability is generated based on the first associated path text, the first vulnerability description text, the second associated path text, and the second vulnerability description text. The hint text is as follows: "Target Vulnerability: CVE-2022-30318 Target Vulnerability Path: CVE-2022-30318 -> CWE-798 -> CAPEC-70 -> T1078 -> Defense Evasion CVE-2022-30318 -> CWE-798 -> CAPEC-70 -> CAPEC-560 -> T1078 -> Defense Evasion …… Similar Vulnerabilities: CVE-xxxx-xxxx CVE-xxxx-xxxx …… Similar Vulnerability Paths: CVE-xxxx-xxxx -> CWE-xxx -> CAPEC-xx -> Txxxx -> xxxxxx …… Entity description: cve-2022-30318: Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. …… cwe-798:…… cve-xxxx-xxxx…… ……”.
[0123] Among them, capec-560 is the vulnerability attack instance numbered 560. Other English interpretations have been described above.
[0124] Input these hint texts into the large model for analyzing the association between vulnerabilities and attack techniques and tactics. The large model for analyzing the association between vulnerabilities and attack techniques and tactics can combine these hint texts to generate corresponding predicted security analysis results for each network vulnerability. The predicted security analysis results can include the techniques and tactics that the network vulnerability may be exploited, as well as relevant explanations and defense deployment suggestions, etc.
[0125] As can be seen from the above, in this application, by combining the network security knowledge of each network vulnerability and the similar network vulnerabilities of each network vulnerability, more accurate hint texts can be generated, making the content in the hint texts richer, so as to help the large model for analyzing the association between vulnerabilities and attack techniques and tactics to obtain more accurate hint information, thereby realizing the learning of network security knowledge for generating more accurate security analysis results for network security vulnerabilities subsequently.
[0126] In step 250, determine the difference between the label security analysis result and the predicted security analysis result corresponding to each network vulnerability, and train the large model for analyzing the association between vulnerabilities and attack techniques and tactics according to the difference to obtain the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics.
[0127] Among them, after obtaining the predicted security analysis result corresponding to each network vulnerability, the predicted security analysis result can be compared with the label security analysis result corresponding to each network vulnerability to determine the difference between the two.
[0128] For example, taking a certain network vulnerability as an example, the predicted security analysis result output by the security model is the techniques and tactics of the network attack that may exist in this network vulnerability. Then, the techniques and tactics of this network attack are compared with the techniques and tactics of the actual network attack corresponding to this network vulnerability, so as to determine the difference between the two. Specifically, the dissimilarity between the predicted techniques and tactics of the network attack and the techniques and tactics of the actual network attack can be determined, and this dissimilarity is used as the difference between the two. If the dissimilarity is greater than the preset difference value, it indicates that the predicted security analysis result output by the large model for the correlation analysis of vulnerabilities and attack techniques and tactics is inaccurate, and the large model for the correlation analysis of vulnerabilities and attack techniques and tactics needs to be further trained. If the dissimilarity is not greater than the preset difference value, it indicates that the predicted security analysis result output by the large model for the correlation analysis of vulnerabilities and attack techniques and tactics is relatively accurate, and other training data can be continuously input for verification. If the dissimilarity between the predicted security analysis result and the labeled security analysis result corresponding to each training data is not greater than the preset difference value, it indicates that the training of the large model for the correlation analysis of vulnerabilities and attack techniques and tactics is completed.
[0129] It should be noted that the large model for the correlation analysis of vulnerabilities and attack techniques and tactics in this application can be a large language model, and the LoRA (Low-Rank Adaptation of Large Language Models) technology can be used to fine-tune the parameters of the large language model, so that the large language model is applicable to the scenario of security analysis of network vulnerabilities in this application.
[0130] In this application, by determining network vulnerabilities and similar network vulnerabilities corresponding to the network vulnerabilities in the network security knowledge graph, and then generating prompt text based on the relevant entity description information of the network vulnerabilities and similar network vulnerabilities, this prompt text provides rich context information for the large model for the correlation analysis of vulnerabilities and attack techniques and tactics, so that the large model for the correlation analysis of vulnerabilities and attack techniques and tactics can more accurately perform security analysis on network vulnerabilities.
[0131] In an embodiment of the present application, multiple associated entities at different levels corresponding to each network vulnerability are determined according to the network security knowledge graph, and the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are determined; the aggregated network vulnerability features corresponding to each network vulnerability are determined according to the network vulnerability features and entity features; the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features; the prompt text corresponding to each network vulnerability is determined according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and the prompt text is input into the vulnerability and attack technique and tactic association analysis large model to output the predicted security analysis result corresponding to each network vulnerability, and the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability; the difference between the label security analysis result and the predicted security analysis result corresponding to each network vulnerability is determined, and the vulnerability and attack technique and tactic association analysis large model is trained according to the difference to obtain the trained vulnerability and attack technique and tactic association analysis large model.
[0132] In this way, multiple associated entities at different levels corresponding to each network vulnerability are determined through the network security knowledge graph, then the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained, and then the aggregated network vulnerability features corresponding to each network vulnerability are obtained by combining the network vulnerability features of each network vulnerability with the entity features of the corresponding associated entity, realizing the combination of each network vulnerability with the associated multi-level associated entities, enabling the aggregated network vulnerability features to represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features, and the prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The prompt text determined in this way can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, so that the prompt text input into the vulnerability and attack technique and tactic association analysis large model is more comprehensive, enabling the vulnerability and attack technique and tactic association analysis large model to learn more network security knowledge, thereby realizing the efficient training of the vulnerability and attack technique and tactic association analysis large model. Compared with the related technology that determines the security analysis result corresponding to the network vulnerability based on human experience, the trained vulnerability and attack technique and tactic association analysis large model of the present application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the techniques and tactics for the network vulnerability to be processed to be attacked.
[0133] Please refer to Figure 6 , Figure 6It is another process schematic diagram of the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by an embodiment of the present application. The method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics may include the following steps: Step 401, identify multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability; Step 402, determine the entity relationships between each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic; Step 403, construct a network security knowledge graph corresponding to multiple network vulnerabilities according to the entity relationships, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic; Step 404, obtain the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity; Step 405, input the first description text into a pre-trained text processing model, and output the network vulnerability features corresponding to each network vulnerability; Step 406, input the second description text into a pre-trained text processing model, and output the entity features corresponding to each associated entity; Step 407, identify the to-be-processed associated entities at the current level in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities; Step 408, perform feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate updated network vulnerability features corresponding to each network vulnerability; Step 409, identify the to-be-processed associated entities at the next level of the current level in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities; Step 410, perform feature fusion processing according to the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate target updated network vulnerability features corresponding to each network vulnerability; Step 411, determine the target updated network vulnerability features as the updated network vulnerability features, determine the next level as the current level, and return to execute identifying the to-be-processed associated entities at the next level of the current level in the associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities until the current level is the highest level, and determine the updated network vulnerability features corresponding to the highest level as the aggregated network vulnerability features corresponding to each network vulnerability; Step 412, determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; Step 413: Determine the hint text corresponding to each network vulnerability based on the aggregated network vulnerability features and similar aggregated network vulnerability features, and input the hint text into the large model for associated analysis of vulnerabilities and attack techniques and tactics to output the predicted security analysis results corresponding to each network vulnerability. The predicted security analysis results include the techniques and tactics corresponding to each network vulnerability. Step 414: Determine the differences between the label security analysis results and the predicted security analysis results corresponding to each network vulnerability, and train the large model for associated analysis of vulnerabilities and attack techniques and tactics based on the differences to obtain the trained large model for associated analysis of vulnerabilities and attack techniques and tactics.
[0134] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the detailed description of the above method for training the large model for associated analysis of vulnerabilities and attack techniques and tactics, which will not be elaborated here.
[0135] Please refer to Figure 7 , Figure 7 which is a schematic flowchart of the network security analysis method provided by the embodiments of the present application. The network security analysis method may include the following steps: Step 510: Determine multiple target associated entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity. Step 520: Determine the target aggregated network vulnerability features corresponding to the network vulnerability to be processed according to the target network vulnerability features and the target entity features. Step 530: Determine the target similar aggregated network vulnerability features corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features. Step 540: Determine the target hint text corresponding to the network vulnerability to be processed according to the target aggregated network vulnerability features and the target similar aggregated network vulnerability features. Step 550: Input the target hint text into the trained large model for associated analysis of vulnerabilities and attack techniques and tactics to output the target security analysis results corresponding to the network vulnerability to be processed. The target security analysis results include the techniques and tactics corresponding to the network vulnerability to be processed, where the trained large model for associated analysis of vulnerabilities and attack techniques and tactics is trained based on the method for training the large model for associated analysis of vulnerabilities and attack techniques and tactics provided by the embodiments of the present application.
[0136] The following will describe steps 510 to 550 in detail.
[0137] In step 510, multiple target associated entities at different levels corresponding to the network vulnerability to be processed are determined according to the network security knowledge graph, and the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity are determined.
[0138] For example, entities such as vulnerability weakness instances, vulnerability attack instances, technologies, and tactics corresponding to the network vulnerability to be processed can be determined according to the network security knowledge graph. Then, the target description texts corresponding to the network vulnerability to be processed and each target associated entity are determined. Then, each target description text is encoded to generate the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity.
[0139] In step 520, the target aggregated network vulnerability features corresponding to the network vulnerability to be processed are determined according to the target network vulnerability features and the target entity features.
[0140] Among them, the target associated entity to be processed at the current level and the target associated entity features corresponding to the target associated entity to be processed can be determined among the target associated entities; the target associated entity features and the target network vulnerability features are subjected to feature fusion processing to generate the first updated network vulnerability features corresponding to the network vulnerability to be processed; the target associated entity to be processed at the next level and the target associated entity features corresponding to the target associated entity to be processed at the next level are determined among the target associated entities; the target associated entity features corresponding to the next level and the first updated network vulnerability features are subjected to feature fusion processing to generate the second updated network vulnerability features corresponding to the network vulnerability to be processed; the second updated network vulnerability features are determined as the first updated network vulnerability features, the next level is determined as the current level, and the process of determining the target associated entity to be processed at the current level and the target associated entity features corresponding to the target associated entity to be processed is returned until the current level is the highest level, and the first updated network vulnerability features corresponding to the highest level are determined as the target aggregated network vulnerability features corresponding to the network vulnerability to be processed.
[0141] In step 530, the target similar aggregated network vulnerability features corresponding to the network vulnerability to be processed are determined according to the similarity between different target aggregated network vulnerability features; The target similarity between the target aggregated network vulnerability features corresponding to the network vulnerability to be processed and other target aggregated network vulnerability features is determined; the target aggregated network vulnerability features corresponding to other network vulnerabilities with the target similarity greater than the preset target similarity are determined as the target similar aggregated network vulnerability features corresponding to the network vulnerability to be processed.
[0142] In step 540, the target prompt text corresponding to the network vulnerability to be processed is determined according to the target aggregated network vulnerability features and the target similar aggregated network vulnerability features.
[0143] Among them, the vulnerability weakness instance, vulnerability attack instance, technology, and tactic corresponding to the network vulnerability to be processed can be determined according to the target aggregation network vulnerability characteristics; the target first association path text and the target first vulnerability description text are generated according to the vulnerability weakness instance, vulnerability attack instance, technology, and tactic corresponding to the network vulnerability to be processed; the vulnerability weakness instance, vulnerability attack instance, technology, and tactic corresponding to the target similar network vulnerability of the network vulnerability to be processed are determined according to the target similar aggregation network vulnerability characteristics; the target second association path text and the target second vulnerability description text are generated according to the vulnerability instance, vulnerability weakness instance, vulnerability attack instance, technology, and tactic corresponding to the target similar network vulnerability; and the prompt text corresponding to the network vulnerability to be processed is generated according to the target first association path text, the target first vulnerability description text, the target second association path text, and the target second vulnerability description text.
[0144] In step 550, the target prompt text is input into the trained vulnerability and attack technique and tactic association analysis large model, and the target security analysis result corresponding to the network vulnerability to be processed is output. The target security analysis result includes the technology and tactic corresponding to the network vulnerability to be processed, where the trained vulnerability and attack technique and tactic association analysis large model is trained based on the vulnerability and attack technique and tactic association analysis large model training method provided in the embodiments of the present application.
[0145] Finally, the target prompt text corresponding to the network vulnerability to be processed can be input into the trained vulnerability and attack technique and tactic association analysis large model, and the target security analysis result corresponding to the network vulnerability to be processed is output. The target security analysis result includes the technology and tactic that the network vulnerability to be processed may be exploited, as well as relevant explanations and defense deployment suggestions. For example, for the network vulnerability to be processed input by the user, the model can not only give the associated technology (such as "Command and Scripting Interpreter") and tactic (such as "Execution"), but also provide specific defense measures (such as "Implement input validation" or "Enable log monitoring"). In this way, the present invention realizes the accurate association analysis from the network vulnerability to be processed to the technology and tactic, and provides scientific and practical decision support for network security defense.
[0146] As can be seen from the above, in the present application, the trained vulnerability and attack technique and tactic association analysis large model can accurately analyze the network vulnerability to be processed and output the target security analysis result. The target security analysis result includes the technology and tactic for the network vulnerability to be processed to be attacked.
[0147] Please refer to Figure 8 , Figure 8It is a schematic structural diagram of a vulnerability and attack technique and tactics association analysis large model training device provided by an embodiment of the present application. The vulnerability and attack technique and tactics association analysis large model training device can execute the above-mentioned vulnerability and attack technique and tactics association analysis large model training method.
[0148] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit that includes the functions of that module or unit.
[0149] The vulnerability and attack technique and tactics association analysis large model training device 600 includes: The first determination module 610 is configured to determine multiple different-level associated entities corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity; The second determination module 620 is configured to determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features; The third determination module 630 is configured to determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; The input module 640 is configured to determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the vulnerability and attack technique and tactics association analysis large model, and output the predicted security analysis result corresponding to each network vulnerability, where the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability; The training module 650 is configured to determine the difference between the labeled security analysis result and the predicted security analysis result corresponding to each network vulnerability, and train the vulnerability and attack technique and tactics association analysis large model according to the difference to obtain the trained vulnerability and attack technique and tactics association analysis large model.
[0150] In some embodiments, the second determination module 620 includes a first processing sub-module, a first fusion sub-module, a second processing sub-module, a second fusion sub-module, and a determination sub-module; The first processing sub-module is configured to determine the to-be-processed associated entity at the current level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity among the associated entities; The first fusion sub-module is used to perform feature fusion processing on the to-be-processed associated entity features and network vulnerability features to generate updated network vulnerability features corresponding to each network vulnerability; The second processing sub-module is used to determine the to-be-processed associated entities at the next level and the to-be-processed associated entity features corresponding to the to-be-processed associated entities at the next level in the associated entities; The second fusion sub-module is used to perform feature fusion processing on the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate target updated network vulnerability features corresponding to each network vulnerability; The determination sub-module is used to determine the target updated network vulnerability features as the updated network vulnerability features, determine the next level as the current level, and return to execute determining the to-be-processed associated entities at the next level and the to-be-processed associated entity features corresponding to the to-be-processed associated entities at the next level in the associated entities until the current level is the highest level, and determine the updated network vulnerability features corresponding to the highest level as the aggregated network vulnerability features corresponding to each network vulnerability.
[0151] In some embodiments, the first fusion sub-module is used to: Sum up each to-be-processed associated entity feature and then calculate the mean value to obtain the first entity feature; Perform weighted summation on the first entity feature and the network vulnerability features to obtain updated network vulnerability features corresponding to each network vulnerability.
[0152] In some embodiments, the first fusion sub-module is used to: Obtain the first weight value corresponding to the first entity feature and the second weight value corresponding to the network vulnerability features; Multiply the first weight value by the first entity feature to obtain the first feature; Multiply the second weight value by the network vulnerability features to obtain the second feature; Add the first feature and the second feature to obtain updated network vulnerability features corresponding to each network vulnerability.
[0153] In some embodiments, the second fusion sub-module is used to: Sum up each to-be-processed associated entity feature corresponding to the next level and then calculate the mean value to obtain the second entity feature; Perform weighted summation on the second entity feature and the updated network vulnerability features to obtain target updated network vulnerability features corresponding to each network vulnerability.
[0154] In some embodiments, the first determination module 610 is used to: Obtain the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity; Input the first description text into a pre-trained text processing model to output the network vulnerability features corresponding to each network vulnerability; Input the second description text into a pre-trained text processing model to output the entity features corresponding to each associated entity.
[0155] In some embodiments, the third determination module 630 is configured to: Determine the similarity between the aggregated network vulnerability features corresponding to each network vulnerability and other aggregated network vulnerability features; Determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.
[0156] In some embodiments, the vulnerability and attack technique - tactic association analysis large model training device 600 further includes a graph generation module, which is configured to: Before determining multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, determine multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability; Determine the entity relationships between each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic; Construct a network security knowledge graph corresponding to multiple network vulnerabilities according to the entity relationships, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic.
[0157] In some embodiments, the input module 640 is configured to: Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability according to the aggregated network vulnerability features; Generate a first association path text and a first vulnerability description text according to the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability; Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability according to the similar aggregated network vulnerability features; Generate a second association path text and a second vulnerability description text according to the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities; Generate a prompt text corresponding to each network vulnerability according to the first association path text, the first vulnerability description text, the second association path text, and the second vulnerability description text.
[0158] In the above - mentioned embodiments, the descriptions of each embodiment have different focuses. For the parts not detailed in a certain embodiment, reference can be made to the detailed description of the above - mentioned vulnerability and attack technique - tactic association analysis large model training method, which will not be elaborated here.
[0159] In an embodiment of the present application, the first determination module 610 determines multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, and determines the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity; the second determination module 620 determines the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features; the third determination module 630 determines the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; the input module 640 determines the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and inputs the prompt text into the vulnerability and attack technique and tactic association analysis large model to output the predicted security analysis result corresponding to each network vulnerability, and the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability; the training module 650 determines the difference between the labeled security analysis result and the predicted security analysis result corresponding to each network vulnerability, and trains the vulnerability and attack technique and tactic association analysis large model according to the difference to obtain the trained vulnerability and attack technique and tactic association analysis large model.
[0160] Therefore, multiple associated entities at different levels corresponding to each network vulnerability are determined through the network security knowledge graph, then the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained, and then the aggregated network vulnerability features corresponding to each network vulnerability are obtained by combining the network vulnerability features of each network vulnerability with the entity features of the corresponding associated entities, realizing that each network vulnerability combines the associated multi-level associated entities, so that the aggregated network vulnerability features can represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features, and the prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The determined prompt text in this way can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, so that the prompt text input into the vulnerability and attack technique and tactic association analysis large model is more comprehensive, enabling the vulnerability and attack technique and tactic association analysis large model to learn more network security knowledge, thereby realizing the efficient training of the vulnerability and attack technique and tactic association analysis large model. Compared with the related technology of determining the security analysis result corresponding to the network vulnerability based on human experience, the trained vulnerability and attack technique and tactic association analysis large model of the present application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the techniques and tactics for the network vulnerability to be processed to be attacked.
[0161] Please refer to Figure 9 , Figure 9It is a schematic structural diagram of the network security analysis device provided by an embodiment of the present application. The network security analysis device can execute the above network security analysis method.
[0162] The network security analysis device 700 includes: An entity determination module 710, configured to determine multiple target associated entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine the target network vulnerability feature corresponding to the network vulnerability to be processed and the target entity feature corresponding to each target associated entity; A feature determination module 720, configured to determine the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature; A similarity determination module 730, configured to determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features; A text generation module 740, configured to determine the target prompt text corresponding to the network vulnerability to be processed according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature; A prediction module 750, configured to input the target prompt text into the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics, and output the target security analysis result corresponding to the network vulnerability to be processed. The target security analysis result includes the techniques and tactics corresponding to the network vulnerability to be processed, where the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics is trained based on the method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by the embodiment of the present application.
[0163] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For parts not detailed in a certain embodiment, reference may be made to the detailed description of the above network security analysis method, which will not be elaborated here.
[0164] An embodiment of the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the above method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics or the network security analysis method. The computer device can be any device including a computer, a server, etc.
[0165] Please refer to Figure 10 , Figure 10 which schematically shows the hardware structure of a computer device in another embodiment. The computer device includes: The processor 901 can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application. The memory 902 can be implemented in forms such as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 902 and are called by the processor 901 to execute the vulnerability and attack technique and tactic correlation analysis large model training method or the network security analysis method in the embodiments of the present application. The input / output interface 903 is used to implement information input and output. The communication interface 904 is used to implement communication interaction between this device and other devices, and can achieve communication through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). The bus 905 transmits information between various components of the device (such as the processor 901, the memory 902, the input / output interface 903, and the communication interface 904). Among them, the processor 901, the memory 902, the input / output interface 903, and the communication interface 904 achieve communication connections with each other inside the device through the bus 905.
[0166] The embodiments of the present application also provide a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned vulnerability and attack technique and tactic correlation analysis large model training method or the network security analysis method.
[0167] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0168] The method, device and equipment for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by the embodiments of the present application determine multiple associated entities at different levels corresponding to each network vulnerability according to a network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity; determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features; determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the predicted security analysis result corresponding to each network vulnerability, where the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability; determine the difference between the labeled security analysis result and the predicted security analysis result corresponding to each network vulnerability, and train the large model for analyzing the association between vulnerabilities and attack techniques and tactics according to the difference to obtain the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics.
[0169] In this way, multiple associated entities at different levels corresponding to each network vulnerability are determined according to the network security knowledge graph, then the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained, and then the aggregated network vulnerability features corresponding to each network vulnerability are obtained by combining the network vulnerability features of each network vulnerability with the entity features of the corresponding associated entities, realizing that each network vulnerability combines the associated multi-level associated entities, so that the aggregated network vulnerability features can represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features, and the prompt text corresponding to each network vulnerability is determined by the aggregated network vulnerability features and the similar aggregated network vulnerability features. The prompt text determined in this way can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, so that the prompt text input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics is more comprehensive, enabling the large model for analyzing the association between vulnerabilities and attack techniques and tactics to learn more network security knowledge, thus realizing the efficient training of the large model for analyzing the association between vulnerabilities and attack techniques and tactics. Compared with the solution in the related art that determines the security analysis result corresponding to the network vulnerability based on human experience, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics of the present application can accurately analyze the network vulnerability to be processed and output the target security analysis result, where the target security analysis result includes the techniques and tactics for attacking the network vulnerability to be processed.
[0170] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0171] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0172] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0173] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations.
[0174] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0175] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item) of the following" or its similar expressions refer to any combination of these items, including any combination of single items (items) or plural items (items). For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0176] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned unit division is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0177] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0178] In addition, in each embodiment of this application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0179] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0180] The preferred embodiments of the embodiments of this application have been described above with reference to the accompanying drawings, and the scope of the rights of the embodiments of this application is not limited thereby. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of this application shall be within the scope of the rights of the embodiments of this application.
Claims
1. A large model training method for vulnerability and attack technique and tactic correlation analysis, characterized in that: include: Determine, according to the network security knowledge graph, a plurality of associated entities at different levels corresponding to each network vulnerability, and determine a network vulnerability feature corresponding to each network vulnerability and an entity feature corresponding to each associated entity; Determine, according to the network vulnerability feature and the entity feature, an aggregated network vulnerability feature corresponding to each network vulnerability; Determine the similar aggregated network vulnerability feature corresponding to each network vulnerability according to the similarity between the different aggregated network vulnerability features; Determine a prompt text corresponding to each network vulnerability according to the aggregated network vulnerability feature and the similar aggregated network vulnerability feature, input the prompt text into a large model for analyzing the association between vulnerability and attack techniques and tactics, and output a predicted security analysis result corresponding to each network vulnerability, wherein the predicted security analysis result includes techniques and tactics corresponding to each network vulnerability; Determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the vulnerability and attack technique and tactics association analysis model based on the difference to obtain the trained vulnerability and attack technique and tactics association analysis model.
2. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: The determining, according to the network vulnerability feature and the entity feature, an aggregated network vulnerability feature corresponding to each network vulnerability includes: Determining, among the associated entities, associated entities to be processed at the current level and associated entity features to be processed corresponding to the associated entities to be processed; Performing feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate updated network vulnerability features corresponding to each network vulnerability; Determining, among the associated entities, associated entities to be processed at a level below the current level and associated entity features to be processed corresponding to the associated entities to be processed; Perform feature fusion processing on the to-be-processed associated entity features and the updated network vulnerability features corresponding to the next level to generate target updated network vulnerability features corresponding to each network vulnerability; The target updated network vulnerability feature is determined as the updated network vulnerability feature, the next level is determined as the current level, and the associated entities to be processed and the associated entity features to be processed corresponding to the associated entities to be processed are returned to be executed until the current level is the highest level, and the updated network vulnerability feature corresponding to the highest level is determined as the aggregated network vulnerability feature corresponding to each network vulnerability.
3. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 2 is characterized in that: The step of performing feature fusion processing on the to-be-processed associated entity feature and the network vulnerability feature to generate an updated network vulnerability feature corresponding to each network vulnerability includes: Adding each of the associated entity features to be processed and calculating the average value to obtain a first entity feature; A weighted sum is performed on the first entity feature and the network vulnerability feature to obtain an updated network vulnerability feature corresponding to each network vulnerability.
4. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 3 is characterized in that: The step of performing weighted summation on the first entity feature and the network vulnerability feature to obtain an updated network vulnerability feature corresponding to each network vulnerability includes: Obtaining a first weight value corresponding to the first entity feature and a second weight value corresponding to the network vulnerability feature; Multiplying the first weight value by the first entity feature to obtain a first feature; Multiplying the second weight value by the network vulnerability feature to obtain a second feature; The first feature and the second feature are added together to obtain an updated network vulnerability feature corresponding to each network vulnerability.
5. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 2 is characterized in that: The step of performing feature fusion processing on the associated entity features to be processed and the updated network vulnerability features corresponding to the next level to generate the target updated network vulnerability features corresponding to each network vulnerability includes: Adding and averaging each of the to-be-processed associated entity features corresponding to the next level to obtain a second entity feature; A weighted sum is performed on the second entity feature and the updated network vulnerability feature to obtain a target updated network vulnerability feature corresponding to each network vulnerability.
6. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: The determining of the network vulnerability feature corresponding to each network vulnerability and the entity feature corresponding to each associated entity includes: Obtaining a first description text corresponding to each network vulnerability and a second description text corresponding to each associated entity; Inputting the first description text into a pre-trained text processing model, and outputting network vulnerability features corresponding to each network vulnerability; The second description text is input into a pre-trained text processing model, and entity features corresponding to each associated entity are output.
7. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: The determining, according to the similarity between the different aggregated network vulnerability features, the similar aggregated network vulnerability feature corresponding to each network vulnerability comprises: Determine the similarity between the aggregated network vulnerability feature corresponding to each network vulnerability and other aggregated network vulnerability features; The aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than a preset similarity are determined as the similar aggregated network vulnerability features corresponding to each network vulnerability.
8. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: Before determining the associated entities of different levels corresponding to each network vulnerability according to the network security knowledge graph, the method further includes: Identify multiple network vulnerabilities in the network security database and identify vulnerability instances, vulnerability attack instances, techniques and tactics corresponding to each network vulnerability; Determine the entity relationship between each of the network vulnerabilities, the vulnerability weakness instances, the vulnerability attack instances, the techniques, and the tactics; A network security knowledge graph corresponding to the multiple network vulnerabilities is constructed according to the entity relationship, each network vulnerability, the vulnerability weakness instance, the vulnerability attack instance, the technology and the tactics.
9. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 8 is characterized in that: The step of determining the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability feature and the similar aggregated network vulnerability feature includes: Determine vulnerability instances, vulnerability attack instances, techniques and tactics corresponding to each network vulnerability according to the aggregated network vulnerability characteristics; Generate a first association path text and a first vulnerability description text according to the vulnerability weakness instance, vulnerability attack instance, technique and tactics corresponding to each network vulnerability; Determine vulnerability instances, vulnerability attack instances, techniques and tactics corresponding to similar network vulnerabilities of each network vulnerability according to the similar aggregated network vulnerability features; Generate a second association path text and a second vulnerability description text according to the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques and tactics corresponding to the similar network vulnerabilities; Generate a prompt text corresponding to each network vulnerability according to the first associated path text, the first vulnerability description text, the second associated path text and the second vulnerability description text.
10. A network security analysis method, characterized in that: include: Determine a plurality of target-related entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine a target network vulnerability feature corresponding to the network vulnerability to be processed and a target entity feature corresponding to each target-related entity; Determine the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature; Determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between the different target aggregated network vulnerability features; Determine a target prompt text corresponding to the to-be-processed network vulnerability according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature; The target prompt text is input into the trained vulnerability and attack technique and tactics correlation analysis model, and the target security analysis result corresponding to the network vulnerability to be processed is output, wherein the target security analysis result includes the technology and tactics corresponding to the network vulnerability to be processed, wherein the trained vulnerability and attack technique and tactics correlation analysis model is trained based on the vulnerability and attack technique and tactics correlation analysis model training method according to any one of claims 1 to 9.
11. A large model training device for vulnerability and attack technique and tactical correlation analysis, characterized in that: include: A first determination module is used to determine, according to the network security knowledge graph, a plurality of associated entities at different levels corresponding to each network vulnerability, and determine a network vulnerability feature corresponding to each network vulnerability and an entity feature corresponding to each associated entity; A second determination module, configured to determine an aggregated network vulnerability feature corresponding to each network vulnerability according to the network vulnerability feature and the entity feature; A third determination module is used to determine the similar aggregated network vulnerability feature corresponding to each network vulnerability according to the similarity between the different aggregated network vulnerability features; An input module, used to determine a prompt text corresponding to each network vulnerability according to the aggregated network vulnerability feature and the similar aggregated network vulnerability feature, and input the prompt text into a large model for analyzing the association between vulnerability and attack techniques and tactics, and output a predicted security analysis result corresponding to each network vulnerability, wherein the predicted security analysis result includes techniques and tactics corresponding to each network vulnerability; The training module is used to determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the vulnerability and attack technique and tactics association analysis model according to the difference to obtain the trained vulnerability and attack technique and tactics association analysis model.
12. A network security analysis device, characterized in that: include: An entity determination module is used to determine a plurality of target-related entities of different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and to determine a target network vulnerability feature corresponding to the network vulnerability to be processed and a target entity feature corresponding to each target-related entity; A feature determination module, used to determine a target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature; A similarity determination module, used to determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features; A text generation module, used to determine a target prompt text corresponding to the to-be-processed network vulnerability according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature; A prediction module is used to input the target prompt text into a trained large model for analyzing the association between vulnerabilities and attack techniques and tactics, and output a target security analysis result corresponding to the network vulnerability to be processed, wherein the target security analysis result includes techniques and tactics corresponding to the network vulnerability to be processed, wherein the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics is trained based on the large model training method for analyzing the association between vulnerabilities and attack techniques and tactics described in any one of claims 1 to 9.
13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a plurality of instructions, which are suitable for loading by a processor to execute the large model training method for vulnerability and attack technique and tactics correlation analysis described in any one of claims 1 to 9 or the network security analysis method described in claim 10.
14. A computer device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor executes the computer program, it implements the large model training method for vulnerability and attack technique and tactics correlation analysis described in any one of claims 1 to 9 or the network security analysis method described in claim 10.
Citation Information
Patent Citations
Vulnerability utilization chain construction technology based on attack and defense combination
CN116405246A
Method and device for automatically mapping vulnerabilities to attack techniques and tactics based on large language model
CN118368103A
Network space vulnerability clustering method based on feature value similarity calculation
CN119203160A
Heterogeneous industrial control network intelligent protection method and system based on large model
CN119696931A
Cited By
ATTCK-based network attack intention prediction method and related equipment
CN120658431A