Network security penetration detection method and system based on artificial intelligence
By extracting and analyzing the multi-dimensional characteristics of network traffic data, combining multi-modal threat prediction models and threat knowledge bases, adaptive defense strategies are generated, which solves the problem that traditional detection methods cannot effectively capture network behavior complexity and processing time dimension correlation, and achieves efficient detection and defense of complex network attacks.
Patent Information
- Application Number
- CN202510180838.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-27
AI Technical Summary
Traditional network security penetration detection methods cannot effectively capture the complexity of network behavior, and there are shortcomings in dealing with behavioral correlations in the time dimension, making it difficult to accurately discover potential attack patterns hidden in the time series.
By obtaining real-time network traffic data of the target network system, multi-dimensional communication behavior records and protocol metadata are extracted, behavior feature extraction is performed, and network behavior sequence features are generated. These features are input into the pre-trained multimodal threat prediction model, generate potential attack vector prediction results, and dynamically verify based on the threat knowledge base to generate penetration threat detection results. Generate and deploy adaptive defense policies based on the detection results.
It realizes efficient detection of complex cyber attack scenarios, can discover potential attack behavior chains and rules, identify new attack methods that exploit protocol vulnerabilities, improve the ability to discover unknown threats, and improve network security response speed and efficiency through adaptive defense strategies.
Smart Images

Figure CN120050079A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and in particular to an artificial intelligence-based network security penetration detection method and system. Background Art
[0002] With the rapid development of information technology, network security issues have become increasingly prominent, and the means and methods of network attacks have become increasingly complex and diverse, which has put higher requirements on network security penetration detection technology.
[0003] Traditional network security penetration detection methods mostly rely on static rule matching or simple feature analysis. On the one hand, these methods can only obtain single-dimensional network traffic data and cannot fully capture the complexity of network behavior. For example, they only focus on the size of traffic or the access to a specific port, while ignoring the inherent connection between communication behaviors and the subtle changes in the protocol interaction process, resulting in limited detection capabilities for complex attack scenarios.
[0004] On the other hand, existing technologies have obvious deficiencies in dealing with behavioral correlation in the time dimension. They usually treat network behaviors as isolated events, without fully considering that attack behaviors often have temporal continuity and correlation, making it difficult to accurately discover potential attack patterns hidden in time series.
[0005] In terms of threat prediction, traditional models are mostly single-mode, based on a single type of data for analysis, unable to integrate information from multiple sources, making the prediction results incomplete and inaccurate. The judgment of attack intent, the speculation of penetration paths, and the assessment of threat levels are often not detailed enough to meet the actual needs of network security protection. Summary of the invention
[0006] In view of the above-mentioned problems, in combination with the first aspect of the present invention, an embodiment of the present invention provides a network security penetration detection method based on artificial intelligence, the method comprising:
[0007] Obtaining real-time network traffic data of the target network system, wherein the network traffic data includes multi-dimensional communication behavior records and corresponding protocol metadata;
[0008] Extracting behavior features from the network traffic data to obtain network behavior sequence features, where the network behavior sequence features are used to describe the relevance of communication behaviors in the time dimension and protocol interaction patterns;
[0009] Inputting the network behavior sequence features into a pre-trained multimodal threat prediction model to generate a potential attack vector prediction result, wherein the potential attack vector prediction result includes an attack intention label, a penetration path probability distribution, and a threat level score;
[0010] Dynamically verifying the potential attack vector prediction result based on the threat knowledge base to generate a penetration threat detection result, wherein the penetration threat detection result includes a verified attack path topology and a matching vulnerability identifier;
[0011] An adaptive defense strategy is generated according to the penetration threat detection result, and the defense interface of the target network system is triggered to execute the strategy deployment, while the attack pattern characteristics and defense rule set in the threat knowledge base are updated.
[0012] On the other hand, an embodiment of the present invention also provides an artificial intelligence-based network security penetration detection system, including a processor and a machine-readable storage medium, wherein the machine-readable storage medium is connected to the processor, the machine-readable storage medium is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the machine-readable storage medium to implement the above method.
[0013] Based on the above aspects, the embodiment of the present application obtains network traffic data containing multi-dimensional communication behavior records and corresponding protocol metadata in real time, and then obtains the network behavior sequence characteristics in the behavior feature extraction link, which describes the correlation of communication behavior in the time dimension and the protocol interaction mode. This dynamic and temporal representation of network behavior breaks the previous limitation of focusing only on static behavior characteristics. By mining the behavioral correlation in the time dimension, potential attack behavior chains and patterns can be discovered, and the accurate grasp of the protocol interaction mode helps to identify new attack methods that exploit protocol vulnerabilities, greatly improving the ability to discover unknown threats.
[0014] The network behavior sequence features are input into the pre-trained multimodal threat prediction model to generate potential attack vector prediction results, which include attack intention labels, penetration path probability distribution and threat level scores. This innovative multimodal model combines multiple data modal information and is more comprehensive and accurate than traditional single model predictions. The attack intention label can directly locate the attacker's goals and motivations, providing a clear direction for defense decisions; the penetration path probability distribution helps security personnel understand possible attack paths in advance and take targeted precautions; the threat level score provides a quantitative basis for resource allocation and emergency response priorities, so that defense resources can be used more reasonably and efficiently.
[0015] Based on the threat knowledge base, the prediction results of potential attack vectors are dynamically verified, and the generated penetration threat detection results contain the verified attack path topology and matching vulnerability identifiers. This dynamic verification mechanism avoids the false positive problem that may be caused by relying solely on the prediction results. Through real-time comparison and verification with the threat knowledge base, the accuracy and reliability of the detection results are ensured. The verified attack path topology intuitively shows the propagation path and method of the attack, which helps security personnel quickly understand the attack process and formulate effective countermeasures; the matching vulnerability identifier is directly associated with the known vulnerability information, providing a clear target for subsequent vulnerability repair and defense reinforcement.
[0016] Generate an adaptive defense strategy based on the results of penetration threat detection, trigger the defense interface of the target network system to execute the strategy deployment, and update the attack pattern characteristics and defense rule set in the threat knowledge base. The adaptive defense strategy can automatically adjust the defense measures according to the threat situation detected in real time without manual intervention, which greatly improves the response speed and efficiency. This dynamic adaptive defense mechanism can respond to new attack threats in a timely manner and effectively reduce network security risks. At the same time, the real-time update of the threat knowledge base ensures that the system always has the latest attack pattern characteristics and defense rules, so that the entire detection and defense system can continue to evolve and improve, and continue to maintain a strong defense capability against various network threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a schematic diagram of the execution flow of the artificial intelligence-based network security penetration detection method provided in an embodiment of the present invention.
[0018] Figure 2 It is a schematic diagram of the hardware architecture of an artificial intelligence-based network security penetration detection system provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0019] The present invention will be described in detail below with reference to the accompanying drawings. Figure 1 This is a flow chart of an artificial intelligence-based network security penetration detection method provided by an embodiment of the present invention. The artificial intelligence-based network security penetration detection method is introduced in detail below.
[0020] Step S110, obtaining real-time network traffic data of the target network system, wherein the network traffic data includes multi-dimensional communication behavior records and corresponding protocol metadata.
[0021] In this embodiment, consider the internal network system of a large enterprise, which includes subnets of multiple departments, such as the R&D department subnet, the marketing department subnet, and the finance department subnet, etc. The subnets are interconnected through core switches, and the entire enterprise network is connected to the external Internet through a firewall. In this network environment, network traffic data flows continuously between network devices. For multi-dimensional communication behavior records, take a server in the R&D department subnet as an example, which has various communication interactions with other devices. For example, this server will regularly receive code upload requests from other R&D personnel's computers, which is a communication behavior record. At the same time, when this server synchronizes data with an external code hosting platform, this is also a communication behavior record. The corresponding protocol metadata contains the protocol-related information followed by these communication behaviors. When the server receives a code upload request, it may use a protocol based on HTTP or FTP (if a file transfer method is used). Under the HTTP protocol, the protocol metadata will include various fields in the request header (such as the request method (GET, POST, etc.), HTTP version number, and request headers (such as User-Agent indicates the client type of the request, etc.). If it is FTP protocol, there will be metadata information such as FTP control connection port (default port 21), data connection port, etc. Looking at the communication with the external Internet, when enterprise employees access external websites through web browsers, the firewall will record the source IP address (IP of the internal computer of the enterprise), destination IP address (IP of the external website server), source port, destination port, and the protocol used (such as TCP protocol for reliable transmission of web page data) and other communication behavior records, as well as the corresponding protocol metadata, such as various control bit information of TCP protocol (SYN, ACK, etc.), which together constitute the real-time network traffic data of the target network system.
[0022] Step S120, extracting behavior features from the network traffic data to obtain network behavior sequence features, where the network behavior sequence features are used to describe the relevance of communication behaviors in the time dimension and the protocol interaction mode.
[0023] Continuing with the above-mentioned enterprise network as an example, the protocol type identifier, port number sequence and load length distribution are extracted from the protocol header of the data packet to construct the protocol interaction feature matrix. Assume that in the enterprise network, there is an internal mail server, which mainly uses the SMTP protocol (protocol type identifier) to send mails, and its default port number is 25. Over a period of time, there are multiple communications between the mail server and different client computers, and the load length (i.e., the size of the mail content plus the length of related information such as the protocol header) of each communication is distributed differently. For example, during rush hour, the content of the mail is mostly short, and the load length may be between a few hundred bytes and a few KB, while when sending large project reports and other mails, the load length may reach tens of MB. These different load length distributions, protocol type identifiers (SMTP) and port number 25 and other information together construct part of the protocol interaction feature matrix. At the same time, the transmission timestamp of the data packet is divided into time windows to generate traffic statistical features in multiple time segments. For example, a day is divided into a 24-hour time window, and the request-response ratio of the mail server is counted in each hour. If a large number of mails fail to be sent in a certain period of time, the number of requests may be much greater than the number of responses, and the request-response ratio will be abnormal. In terms of packet rate fluctuation, when a large-scale mass email activity is carried out simultaneously within an enterprise, the packet sending rate will suddenly increase, which will form rate fluctuation. In terms of connection life cycle, under normal circumstances, the email client will quickly disconnect from the server after establishing a connection and sending an email. However, if there is a malicious program that constantly tries to connect to the email server and maintain the connection, the connection life cycle will be longer. These protocol interaction feature matrices are cross-modally fused with traffic statistical features to generate an initial behavior sequence. For example, the interaction feature matrix related to the SMTP protocol of the email server and the statistical features of the email traffic counted in each time window are fused together. Then, the initial behavior sequence is enhanced with abnormal behavior, and simulated attack behavior data and normal behavior noise data are injected to generate an adversarial training sample set. For the email server, the simulated attack behavior data can be the behavior data of simulating hackers trying to use email server vulnerabilities to brute force password cracking, and the normal behavior noise data can be some random small fluctuations added to the normal email traffic, such as the slight changes in packet transmission time caused by occasional network delays. Finally, the adversarial training sample set is subjected to feature dimensionality reduction and pattern extraction through the temporal convolutional network, and the network behavior sequence features are output. For example, the temporal convolutional network can identify the protocol layer behavior pattern vectors of the mail server when it is working normally, such as the normal value range of each field of the SMTP protocol and the time dependency graph when sending normal emails, such as the time sequence of traffic during peak and off-peak email sending periods and their mutual correlation.
[0024] Step S130, inputting the network behavior sequence features into a pre-trained multimodal threat prediction model to generate a potential attack vector prediction result, wherein the potential attack vector prediction result includes an attack intention label, a penetration path probability distribution, and a threat level score.
[0025] In this enterprise network scenario, the previously obtained network behavior sequence features are input into the pre-trained multimodal threat prediction model. The protocol parsing branch in the multimodal threat prediction model performs protocol semantic parsing on the protocol layer behavior pattern vector. Taking the database server in the enterprise network as an example, assuming that the database server uses Oracle database, its communication protocol may include SQL*Net protocol. The protocol parsing branch extracts the protocol keyword set from the protocol layer behavior pattern vector, such as the keywords (SELECT, INSERT, etc.) in the database query statement and the load structure features, such as whether the structure of the query statement conforms to the normal grammatical specification. At the same time, a protocol threat probability matrix is generated. If some abnormal keyword combinations or statements that do not conform to the conventional grammatical structure are found in the query statement, the threat probability of the protocol being attacked may increase. The behavior pattern branch traverses the graph structure of the time dependency graph to identify high-frequency connection nodes and abnormal path jumps. For example, in the network connection of the database server, it is found that an external IP address frequently connects to the database server in a short period of time. This is a high-frequency connection node. If a connection suddenly jumps from a normal subnet within the enterprise to an abnormal subnet and then connects to the database server, this is an abnormal path jump. Based on these situations, a behavior anomaly scoring matrix is generated. The protocol threat probability matrix and the behavior anomaly score matrix are aligned with cross-modal attention to generate a fused threat feature. For example, if the protocol threat probability matrix shows that the database protocol has a high risk, and the behavior anomaly score matrix also shows abnormal connection behavior, then the fused threat feature will show a higher threat. The fused threat feature is multi-level reasoned through threat reasoning branches, such as attack stage division. Assuming that an external malicious force attempts to access the database server, it may first be in the information collection stage, trying to obtain the database version information, etc.; then if there is a detection behavior for the database vulnerability, it may enter the vulnerability exploitation stage; if the vulnerability is successfully exploited to obtain some permissions, it will enter the permission escalation stage. In terms of vulnerability exploitation chain reconstruction, a series of vulnerability combinations that malicious forces may exploit are analyzed, such as first exploiting the weak password vulnerability of the database to enter the system, and then exploiting the stored procedure vulnerability of the database to escalate permissions. In terms of permission escalation path prediction, it is predicted that malicious forces may use which ways to escalate from ordinary user permissions to administrator permissions, etc., so as to generate attack intention labels and penetration path probability distribution. According to the protocol threat probability matrix, the behavior anomaly score matrix and the penetration path probability distribution, weighted fusion is performed to generate a threat level score. For example, if the protocol threat probability is high, the behavioral anomaly score is also high, and the penetration path probability distribution shows a high probability of reaching critical database resources, then the threat level score will be high, indicating that the database server in the enterprise network faces a serious potential threat.
[0026] Step S140: dynamically verify the potential attack vector prediction result based on the threat knowledge base to generate a penetration threat detection result, wherein the penetration threat detection result includes a verified attack path topology and a matching vulnerability identifier.
[0027] In the scenario of enterprise network, historical attack pattern feature set is extracted from threat knowledge base. The threat knowledge base contains the attacks suffered by the enterprise network in the past or the attack information on similar enterprise networks collected from public channels. For example, the historical attack pattern feature set may contain SQL injection attack patterns against enterprise database servers, which contain known attack fingerprints (such as the feature pattern of specific malicious SQL statements), vulnerability exploitation signatures (such as signatures for injection using vulnerabilities in a specific version of the database), and attack path templates (such as first injecting through the login page of the Web application, and then obtaining database connection permissions, etc.). The previously predicted attack intent label is matched with the historical attack pattern feature set to identify candidate attack patterns with a matching degree higher than the set matching degree. Assuming that the predicted attack intent label shows a malicious access attempt to the database, it is matched with the SQL injection attack pattern in the historical attack pattern feature set. If the matching degree is high, the SQL injection attack pattern is used as a candidate attack pattern. Based on the candidate attack patterns, the probability distribution of penetration paths is modified. For example, if the original probability distribution of penetration paths does not take into account that SQL injection attacks may be transferred through a certain middleware, then this uncovered attack step is supplemented and some low-probability branches are deleted, such as paths that are unlikely to attack through a service unrelated to the database, to generate an optimized attack path set. The vulnerability existence is verified for each path node in the optimized attack path set, and the asset topology map and vulnerability database of the enterprise network are queried. For example, for a database server, querying its asset topology map shows which application servers, firewalls and other devices it is connected to, and looking up whether the current version of the database server has known vulnerabilities that can be exploited by SQL injection from the vulnerability database. If so, the corresponding vulnerability identifier is generated. The attack path topology is constructed based on the verification results. For example, a complete attack path topology from an external attacker through a Web application to a database server is constructed, including the network devices and applications that pass through in the middle. And the new attack path that does not match the historical attack pattern feature set is added to the threat knowledge base for subsequent analysis and prevention.
[0028] Step S150, generating an adaptive defense strategy according to the penetration threat detection result, triggering the defense interface of the target network system to execute the strategy deployment, and updating the attack mode characteristics and defense rule set in the threat knowledge base.
[0029] For example, in the enterprise network scenario, key defense nodes are determined based on the attack path topology. Taking the attack path topology for the database server as an example, the initial intrusion point may be the login page of the enterprise network's Web application, because this is where the attacker may first try to break through; the privilege escalation point may be the module responsible for user privilege management in the database server, where the attacker will try to escalate privileges if he successfully exploits the vulnerability; the data leakage point may be the area where the table storing sensitive data (such as corporate financial data, customer information, etc.) is located in the database server. A defense action sequence is generated for each key defense node. For the initial intrusion point (Web application login page), the defense action sequence includes setting traffic cleaning rules, such as filtering out request traffic containing malicious SQL statements, setting access control policies, allowing only legitimate IP addresses within the enterprise or authenticated external IP addresses to access the login page, and determining the priority of vulnerability patch deployment, giving priority to deploying patches for possible SQL injection vulnerabilities in the Web application. The execution order and triggering conditions of the defense action sequence are adjusted according to the threat level score. If the threat level score is high, the traffic cleaning rules are executed first, and the access rights in the access control policy are reduced, such as only allowing specific internal administrator IP addresses to access the login page. Encapsulate the defense action sequence into an executable policy instruction set, such as converting the traffic cleaning rules and access control policies for the Web application login page into rule instructions that the firewall can recognize and signature rules that the intrusion detection system can recognize. Distribute these rules to the security devices of the target network system through the defense interface, such as distributing these rules to the firewall, intrusion detection system, Web application firewall and other devices in the enterprise network. Monitor the execution effect of the policy instruction set in real time, such as checking whether the traffic containing malicious SQL statements has been successfully intercepted through the firewall log, and checking whether abnormal access behavior has been detected through the intrusion detection system log. Dynamically adjust the parameter thresholds in the defense action sequence according to the monitoring data. For example, if a small amount of malicious traffic is still found to pass through, adjust the filtering parameters in the traffic cleaning rules to increase the strictness of filtering. At the same time, feature vectors of new attack paths are extracted from the penetration threat detection results. For example, a newly discovered new attack path that attacks the database server through a test server within the enterprise has a feature vector that includes the protocol combination features involved (such as the protocol conversion used in the process from the test server to the database server, etc.), time distribution patterns (such as attack attempts within a specific time period), and vulnerability exploitation chains (such as first exploiting a configuration error vulnerability of the test server, and then exploiting the trust relationship vulnerability between the database server and the test server to attack). The feature vectors of the new attack path are clustered with the historical attack pattern feature set for similarity, and an updated attack pattern classification tree is generated to more accurately classify and identify different attack patterns.Generate defense rule weights based on the execution effect data of the adaptive defense strategy. For example, if a defense rule is effective in preventing attacks, then increase its rule matching priority and response speed weight. Synchronize the attack pattern classification tree and defense rule weights to the distributed storage nodes of the threat knowledge base, and trigger the incremental learning module of the multimodal threat prediction model to update the model parameters based on the feature vectors of the new attack path and the defense rule weights, so that the multimodal threat prediction model can better predict possible future attacks.
[0030] Based on the above steps, the embodiment of the present application obtains network traffic data containing multi-dimensional communication behavior records and corresponding protocol metadata in real time, and then obtains the network behavior sequence characteristics in the behavior feature extraction link, which describes the correlation of communication behavior in the time dimension and the protocol interaction mode. This dynamic and temporal representation of network behavior breaks the limitation of focusing only on static behavior characteristics in the past. By mining the behavioral correlation in the time dimension, potential attack behavior chains and patterns can be discovered, and the accurate grasp of the protocol interaction mode helps to identify new attack methods that exploit protocol vulnerabilities, greatly improving the ability to discover unknown threats.
[0031] The network behavior sequence features are input into the pre-trained multimodal threat prediction model to generate potential attack vector prediction results, which include attack intention labels, penetration path probability distribution and threat level scores. This innovative multimodal model combines multiple data modal information and is more comprehensive and accurate than traditional single model predictions. The attack intention label can directly locate the attacker's goals and motivations, providing a clear direction for defense decisions; the penetration path probability distribution helps security personnel understand possible attack paths in advance and take targeted precautions; the threat level score provides a quantitative basis for resource allocation and emergency response priorities, so that defense resources can be used more reasonably and efficiently.
[0032] Based on the threat knowledge base, the prediction results of potential attack vectors are dynamically verified, and the generated penetration threat detection results contain the verified attack path topology and matching vulnerability identifiers. This dynamic verification mechanism avoids the false positive problem that may be caused by relying solely on the prediction results. Through real-time comparison and verification with the threat knowledge base, the accuracy and reliability of the detection results are ensured. The verified attack path topology intuitively shows the propagation path and method of the attack, which helps security personnel quickly understand the attack process and formulate effective countermeasures; the matching vulnerability identifier is directly associated with the known vulnerability information, providing a clear target for subsequent vulnerability repair and defense reinforcement.
[0033] Generate an adaptive defense strategy based on the results of penetration threat detection, trigger the defense interface of the target network system to execute the strategy deployment, and update the attack pattern characteristics and defense rule set in the threat knowledge base. The adaptive defense strategy can automatically adjust the defense measures according to the threat situation detected in real time without manual intervention, which greatly improves the response speed and efficiency. This dynamic adaptive defense mechanism can respond to new attack threats in a timely manner and effectively reduce network security risks. At the same time, the real-time update of the threat knowledge base ensures that the system always has the latest attack pattern characteristics and defense rules, so that the entire detection and defense system can continue to evolve and improve, and continue to maintain a strong defense capability against various network threats.
[0034] In a possible implementation, the network traffic data includes data packets of multiple communication protocol layers, and step S120 includes:
[0035] Step S121, extracting a protocol type identifier, a port number sequence and a load length distribution from the protocol header of the data packet, and constructing a protocol interaction feature matrix based on the protocol type identifier, the port number sequence and the load length distribution.
[0036] In this embodiment, in the enterprise network, the communication between the R&D department and the external code hosting platform is taken as an example. The communication between the server of the R&D department and the code hosting platform may adopt multiple protocols, such as data transmission based on the HTTPS protocol. The protocol type identifier is "HTTPS", which clarifies the basic rules and specifications followed by the communication. In this communication process, the server uses a specific port number to interact with the code hosting platform, assuming port 443. This port number sequence is a key element in the protocol interaction. At the same time, the distribution of the data load length of each transmission is also different. When the R&D personnel upload a small code snippet, the load length may be relatively small, such as between a few KB and tens of KB; and when synchronizing a large project code base, the load length may reach hundreds of MB or even GB. These protocol type identifiers "HTTPS", port number 443, and different load length distributions jointly construct part of the protocol interaction feature matrix. For the internal mail server communication of the enterprise, the SMTP protocol is used, the protocol type identifier is "SMTP", the default port number is 25, and the load length of the mail content fluctuates in different ranges according to the size of the mail. This information is also integrated into the protocol interaction feature matrix.
[0037] Step S122, dividing the transmission timestamp of the data packet into time windows, generating traffic statistical features within multiple time segments, the traffic statistical features including request response ratio, data packet rate fluctuation and connection survival period.
[0038] Taking the operation of the enterprise network for one day as an example, a day is divided into 24 time windows. In the communication between the server of the R&D department and the code hosting platform, the request-response ratio is an important traffic statistical feature. During normal working hours, such as from 9 to 11 a.m., R&D personnel upload code intensively. At this time, the number of requests is large. If the code hosting platform responds normally, the request-response ratio is relatively stable within a reasonable range; if the code hosting platform fails or is attacked, it may cause a response failure, and the request-response ratio will change abnormally. In terms of packet rate fluctuation, when the R&D department performs large-scale code synchronization operations, the packet sending rate will increase significantly, suddenly rising from the normal stable rate to a higher value, which forms a packet rate fluctuation. For the connection survival period, when the R&D personnel establish a connection with the code hosting platform to upload code, under normal circumstances, the connection will be disconnected soon after the upload is completed. If there is a malicious program that continues to occupy the connection, such as a malicious attacker trying to steal data or conduct a man-in-the-middle attack through a continuous connection, the connection survival period will become longer. The same is true for mail server communications. During periods when a large number of emails are sent, such as from 3:00 p.m. to 5:00 p.m. on weekdays, the mail server's traffic statistical characteristics such as request-response ratio, packet rate fluctuations, and connection survival period will also show corresponding changes.
[0039] Step S123: cross-modally fuse the protocol interaction feature matrix with the traffic statistical feature to generate an initial behavior sequence.
[0040] Take the database server in the enterprise network as an example. There is a communication relationship between it and the application server. The protocol interaction feature matrix of the database server contains information such as the protocol type identifier related to the database communication protocol (such as Oracle's SQL*Net protocol), the port number (such as port 1521), and the load length distribution corresponding to different operations. Traffic statistics include the request response ratio of the database server in different time windows (for example, during business peak hours, when the number of query requests increases), packet rate fluctuations (such as changes in packet rate during data backup), and connection survival period (normal connection and abnormal long connection). The information of these different modes is integrated to form an initial behavior sequence. This initial behavior sequence combines the behavior characteristics of the database server at the protocol interaction level and the traffic statistics level, and can more comprehensively describe the behavior pattern of the database server in the network.
[0041] Step S124, performing abnormal behavior enhancement processing on the initial behavior sequence, wherein the abnormal behavior enhancement processing includes injecting simulated attack behavior data and normal behavior noise data to generate an adversarial training sample set.
[0042] For the financial system server in the enterprise network, the injection of simulated attack behavior data is to simulate possible attack scenarios. For example, to simulate hackers trying to exploit the vulnerability of the financial system server for illegal access, they may inject behavior data that simulates SQL injection attacks, construct malicious SQL query statements, and try to break through the database access control of the financial system. The injection of normal behavior noise data takes into account some uncertain factors in the actual network environment. For example, occasional failures of network equipment may cause a slight delay in data packet transmission, which is similar to normal behavior noise data. In the normal financial data query process, such similar slight delay data is injected to more realistically simulate the actual network environment. These simulated attack behavior data and normal behavior noise data are injected into the initial behavior sequence generated previously to form an adversarial training sample set. This adversarial training sample set not only contains normal network behavior features, but also contains interference factors of simulated attack behavior and normal behavior, which helps to perform feature extraction and pattern recognition more accurately in the future.
[0043] Step S125, performing feature dimension reduction and pattern extraction on the adversarial training sample set through a temporal convolutional network, and outputting the network behavior sequence features, wherein the network behavior sequence features include a protocol layer behavior pattern vector and a time dependency graph.
[0044] Take the server cluster in the enterprise network as an example. These servers include Web servers, application servers, and database servers. The temporal convolutional network processes adversarial training sample sets containing various servers. For Web servers, it can identify the protocol layer behavior pattern vectors of Web services in different time periods. For example, in the normal web page access process, the normal value pattern of the HTTP protocol request method, response status code, etc. in the time series. At the same time, it can construct a time dependency graph, such as the order of page requests and the time relationship of interaction with the background server during the peak period of web browsing. For application servers, the temporal convolutional network can identify the behavior pattern vectors of the application protocol layer during the execution of business processes, such as the protocol interaction characteristics of the workflow system within the enterprise at different operation stages, and the time dependency graph between these operations. For database servers, it can extract the protocol layer behavior pattern vectors in the process of data query and update, such as the temporal change law of the structural pattern of SQL query statements, and the time dependency graph between operations such as database connection establishment, data transmission, and connection disconnection. These protocol layer behavior pattern vectors and time dependency graphs extracted from different servers together constitute the network behavior sequence characteristics, which can comprehensively and accurately describe the behavior patterns and time correlations of each device in the enterprise network system in network communications.
[0045] In a possible implementation, the multimodal threat prediction model includes a protocol parsing branch, a behavior pattern branch, and a threat reasoning branch, and step S130 includes:
[0046] Step S131, performing protocol semantic analysis on the protocol layer behavior pattern vector through the protocol analysis branch, extracting a protocol keyword set and load structure features, and generating a protocol threat probability matrix.
[0047] In this embodiment, taking the database server in the enterprise network as an example, the database server uses the SQL*Net protocol for communication. The protocol parsing branch will deeply analyze the content in the protocol when performing protocol semantic parsing on its protocol layer behavior pattern vector. The extraction of the protocol keyword set may involve keywords related to database operations, such as "SELECT", "INSERT", "UPDATE", "DELETE", etc. These keywords have specific semantic meanings in normal database query and data modification operations. In terms of load structure characteristics, for example, in query operations, the structure of the query statement may be constructed according to certain grammatical rules, including the arrangement of the query table name, column name, conditional statement, etc. If it is found that there is a situation in the query statement that does not conform to the normal grammatical structure, such as the abnormal position of a keyword or the lack of necessary grammatical elements, this may indicate a potential threat. Based on these parsing results, a protocol threat probability matrix is generated. Assuming that at a certain moment, the database server receives a query statement containing an abnormal keyword combination or structure, the protocol parsing branch will assign a higher protocol threat probability value to this event according to predefined rules and algorithms. For the SMTP protocol used by mail servers in enterprise networks, the protocol parsing branch will also perform protocol semantic analysis to extract protocol keywords such as "MAILFROM" and "RCPT TO" as well as payload structure features such as the mail content structure. When it is found that the mail header information has an abnormal format or content that does not comply with the SMTP protocol specification, a higher threat probability will be reflected in the protocol threat probability matrix accordingly.
[0048] Step S132, traversing the time dependency graph through the behavior pattern branches, identifying high-frequency connection nodes and abnormal path jumps, and generating a behavior anomaly scoring matrix.
[0049] In the enterprise network, the core switch is used as the observation point, which connects the subnets of various departments within the enterprise. The graph structure of its time dependency graph is traversed to identify high-frequency connection nodes. For example, during working hours on weekdays, there may be frequent communication connections between the R&D department subnet and the test server. This is a high-frequency connection node because R&D personnel may need to continuously deploy code to the test server for testing. In terms of abnormal path jumps, if it is found that a connection from the outside first enters the marketing department subnet of the enterprise and then suddenly jumps to the R&D department subnet, this is an abnormal path jump that does not conform to normal business logic. Based on these identification results, a behavior anomaly score matrix is generated. If the connection frequency of a connection node exceeds the normal business traffic range or an abnormal path jump occurs, the behavior pattern branch will assign it a higher behavior anomaly score according to a predefined algorithm. For the connection of the database server, if an external IP address frequently attempts to connect to the database server in a short period of time, this high-frequency connection node will be reflected in the behavior anomaly score matrix, and if the IP address of the connection source has an abnormal jump path, such as jumping from an unauthorized network area, the behavior anomaly score will be further increased.
[0050] Step S133, performing cross-modal attention alignment on the protocol threat probability matrix and the behavior anomaly score matrix to generate a fused threat feature.
[0051] When an abnormality occurs in the database server, the protocol threat probability matrix shows that there may be risks in the database protocol, such as an increase in the probability of protocol threats due to abnormal query statements, and the behavior anomaly score matrix shows abnormal behaviors such as high-frequency connection attempts from abnormal IP addresses. The cross-modal attention alignment mechanism takes these two factors into consideration, organically combines the threat factors related to the protocol and the abnormal factors related to the behavior pattern, and generates a fused threat feature. For example, if the threat value corresponding to a certain protocol anomaly in the protocol threat probability matrix is high, and the corresponding behavior anomaly score in the behavior anomaly score matrix is also high, then the severity of this potential threat will be more prominent in the fused threat feature, so that the subsequent threat reasoning branch can be analyzed more accurately.
[0052] Step S134, performing multi-level reasoning on the fused threat feature through the threat reasoning branch, the multi-level reasoning includes attack stage division, vulnerability exploitation chain reconstruction and privilege escalation path prediction, to generate the attack intention label and the penetration path probability distribution.
[0053] For database servers in the enterprise network, if potential threats are found, the threat reasoning branch will divide the attack phases. Initially, it may be found that there are information collection behaviors such as port scanning of the database server by external IP addresses, which is determined to be the initial information collection phase of the attack. Over time, if there are detection behaviors for specific database vulnerabilities, such as detection of database version numbers, this may mean that the vulnerability exploitation preparation phase has begun. If a database vulnerability is successfully exploited, such as a weak password vulnerability that obtains partial permissions, the privilege escalation phase will begin. In terms of vulnerability exploitation chain reconstruction, the threat reasoning branch will analyze a series of possible vulnerability combinations. For example, an attacker may first exploit the trust relationship vulnerability between the database server and the application server to obtain partial permissions of the application server, and then exploit the internal permission management vulnerability of the database server to further escalate the permissions of the application server to a higher permission of the database server. In terms of privilege escalation path prediction, based on the topology and permission settings of the enterprise network, it is predicted through which paths the attacker may escalate from ordinary user permissions to administrator permissions. For example, it may be possible to obtain the database superuser password backup file and then use a password cracking tool to obtain the superuser password to achieve privilege escalation. Based on these analysis results, attack intention labels are generated, such as determining malicious data acquisition intentions against the database server, and penetration path probability distribution is generated, such as the probability of entering the database server through a specific vulnerability and elevating permissions.
[0054] Step S135, performing weighted fusion according to the protocol threat probability matrix, the behavior anomaly score matrix and the penetration path probability distribution to generate the threat level score.
[0055] For example, for potential threat assessment of database servers, if the threat probability due to protocol anomalies is high in the protocol threat probability matrix, frequent abnormal connection behaviors are shown in the behavior anomaly score matrix, and the penetration path probability distribution shows that the attacker has a high probability of successfully penetrating into the core area of the database through a certain path to obtain sensitive data, then when weighted fusion is performed, these factors will work together to generate a higher threat level score. This means that the database server faces a more serious potential threat and needs to take corresponding defensive measures in a timely manner.
[0056] In a possible implementation, step S140 includes:
[0057] Step S141, extracting a historical attack pattern feature set from the threat knowledge base, wherein the historical attack pattern feature set includes known attack fingerprints, vulnerability exploitation signatures, and attack path templates.
[0058] For example, in the threat knowledge base of an enterprise network, for a database server, the historical attack pattern feature set may contain information about SQL injection attacks that have occurred before against the database. A known attack fingerprint may be a pattern of a specific malicious SQL statement, such as an SQL query statement containing special character combinations, which are common means for attackers to break through database security protections. An exploit signature may be an identifier of the exploitation method for a vulnerability in a specific version of the database, such as an exploit signature for an authentication bypass vulnerability in a certain version of the database. An attack path template may be a path pattern for an attacker to attack the database server from an external network through the enterprise's Web application, exploiting a connection vulnerability between the Web application and the database server.
[0059] Step S142, performing intent matching on the attack intention label and the historical attack pattern feature set, and identifying a candidate attack pattern with a matching degree higher than a set matching degree.
[0060] Assuming that the previously predicted attack intent label shows malicious access intent to the database server, it is matched with the SQL injection attack pattern in the historical attack pattern feature set. If certain features in the malicious access intent, such as specific keywords or behavior patterns related to SQL injection attacks, have a high degree of similarity with known attack fingerprints, vulnerability exploitation signatures, etc. in the SQL injection attack pattern, and this similarity is higher than the set matching degree, then the SQL injection attack pattern is identified as a candidate attack pattern.
[0061] Step S143, performing path correction on the penetration path probability distribution based on the candidate attack mode, wherein the path correction includes deleting low-probability branches and supplementing uncovered attack steps to generate an optimized attack path set.
[0062] For potential attacks on the database server, if the candidate attack mode is the SQL injection attack mode, there may be some low-probability branches in the original penetration path probability distribution, such as attacking the database server through the internal mail server of the enterprise. This situation has a low probability in the SQL injection attack scenario, so it will be deleted. At the same time, if it is found that the original penetration path probability distribution does not take into account that the SQL injection attack may first use an unappreciated input field in the Web application to attempt an injection, and then further attack the database server, then this uncovered attack step is supplemented to generate an optimized attack path set.
[0063] Step S144, performing vulnerability existence verification on each path node in the optimized attack path set, wherein the vulnerability existence verification includes querying the asset topology map and vulnerability database of the target network system to generate the vulnerability identifier.
[0064] For each path node in the optimized attack path set of the database server, such as the path from the Web application to the database server. By querying the asset topology diagram of the enterprise network, we can know the connection relationship between the Web application and the database server, and the configuration of the firewalls, routers and other network devices in the middle. At the same time, query the vulnerability database to check whether there are vulnerabilities in the Web application that can be exploited by SQL injection, and whether there are vulnerabilities related to the attack path in the current version of the database server. If there are, a corresponding vulnerability identifier is generated. For example, if a specific input validation vulnerability is found in the Web application, a unique vulnerability identifier is generated for it.
[0065] Step S145, constructing the attack path topology according to the verification result, and adding the new attack path that is not matched to the historical attack pattern feature set to the threat knowledge base.
[0066] Based on the results of the above vulnerability existence verification, a complete attack path topology from an external attacker through a Web application to a database server is constructed, including the network devices, applications, and vulnerabilities of each node in the middle. If a new attack path is discovered in this process, such as a new path where an attacker exploits a vulnerability in an internal office software of an enterprise and then attacks the database through the association with the database server, and this new attack path is not matched to the historical attack pattern feature set, it will be added to the threat knowledge base so that this new attack pattern can be considered in future threat detection and defense.
[0067] In a possible implementation, step S150 includes:
[0068] Step S151, determining key defense nodes according to the attack path topology, wherein the key defense nodes include initial intrusion points, privilege escalation points, and data leakage points.
[0069] For example, in the case of a potential attack on a database server mentioned earlier, if the attack path topology shows that an attacker attempts to intrude into the database server from an external network through the company's web application, then the login page of the web application is the initial intrusion point. Because this is the most likely place for an external attacker to break in first, they may try to exploit vulnerabilities such as SQL injection to intrude here. The privilege escalation point may be the module in the database server responsible for user privilege management, such as the role management part of the database management system. Once the attacker successfully enters the database server through the initial intrusion point, they may try to exploit privilege management vulnerabilities in this module to elevate their privileges from ordinary users to administrator privileges so that they can perform more malicious operations, such as modifying key data or obtaining sensitive information. The data leakage point may be the area in the database server where the tables storing the company's core data (such as financial data, customer information, etc.) are located. These areas contain the company's most confidential and valuable information. If the attacker successfully reaches this area, it may steal the data and leak it to the outside.
[0070] Step S152, generating a defense action sequence for each of the key defense nodes, wherein the defense action sequence includes traffic cleaning rules, access control policies, and vulnerability patch deployment priorities.
[0071] For the initial intrusion point (web application login page), in terms of traffic cleaning rules, rules can be set to filter out HTTP request traffic containing specific malicious character combinations, such as those related to SQL injection attacks. Access control policies can restrict access to the login page to only IP addresses in a specific subnet within the enterprise or authenticated external IP addresses. For vulnerability patch deployment priority, since the web application login page is the initial intrusion point, patches for vulnerabilities that may lead to SQL injection found here should be deployed first to prevent attackers from exploiting these vulnerabilities to enter the system. For the privilege escalation point (database server privilege management module), traffic cleaning rules can monitor and block abnormal access requests to the privilege management module, such as frequent privilege modification requests or privilege escalation attempts from abnormal IP addresses. Access control policies can restrict access to privilege management modules to only specific administrator roles or users with multi-level authorization. In terms of vulnerability patch deployment priority, any privilege vulnerability patches found in the privilege management module should be sorted according to their severity and those that may lead to privilege escalation should be deployed first. For data leakage points (database table areas storing core data), traffic cleaning rules should filter abnormal traffic that attempts to directly access these tables, such as blocking unauthorized large-scale data read requests. Access control policies should ensure that only strictly authorized users or processes can access these tables, and restrict direct access to these tables from external networks. In terms of vulnerability patch deployment priority, vulnerability patches that involve protecting the security of core data tables should be given high priority deployment.
[0072] Step S153: adjusting the execution order and triggering conditions of the defense action sequence according to the threat level score.
[0073] For example, if the threat level score is high, it indicates that the database server faces a greater potential threat. For the defense action sequence of the initial intrusion point, it may be to perform traffic cleaning first and then check the access control policy. However, due to the high threat level, it can be adjusted to perform traffic cleaning and stricter access control policy checks at the same time, such as further narrowing the range of IP addresses allowed to access the login page. For the privilege escalation point, it may be triggered and measures taken only after a certain number of abnormal privilege escalation attempts are detected. Due to the high threat level, this trigger threshold can be lowered, and once a small number of abnormal attempts are detected, measures such as restricting access and recording logs can be taken immediately. For data leakage points, when the threat level is high, the deployment of vulnerability patches can be advanced to the highest priority position, and the strictness of traffic cleaning rules can be strengthened, such as intercepting all suspicious requests to read core data, not just a large number of requests.
[0074] Step S154: encapsulate the defense action sequence into an executable policy instruction set, and distribute it to the security device of the target network system through the defense interface.
[0075] For example, for the defense action sequence for the Web application login page, the traffic cleaning rules, access control policies, etc. are encapsulated into a set of rules and instructions that the firewall can recognize. For example, the rules for filtering malicious character combinations are converted into the firewall's access control list (ACL) rules, and the IP address access restriction rules are converted into the firewall's source address and destination address filtering rules. For the defense action sequence for the database server permission management module and data leakage points, the relevant rules are also converted into signature rules that can be recognized by the intrusion detection system (IDS) or intrusion prevention system (IPS). Then, through the defense interface of the enterprise network, these policy instruction sets are distributed to the corresponding security devices, such as firewalls, IDS, IPS, and the database's own security protection module.
[0076] Step S155, monitoring the execution effect of the strategy instruction set in real time, and dynamically adjusting the parameter thresholds in the defense action sequence according to the monitoring data.
[0077] For example, when the firewall filters the traffic of the web application login page, the execution effect of the policy instruction set can be monitored by checking the log of the firewall. If it is found that there are still a small number of requests containing malicious character combinations that pass the traffic cleaning rules, this indicates that the current traffic cleaning rules are not strict enough, then it is necessary to dynamically adjust the parameter thresholds in the traffic cleaning rules, such as increasing the detection sensitivity for specific malicious characters or expanding the detection range. For the monitoring of the execution effect of the defense strategy at the privilege escalation point, if it is found that the IDS records some abnormal privilege escalation attempts but is not blocked in time, it may be necessary to adjust the permission judgment logic in the access control policy or lower the trigger threshold of abnormal behavior. For data leakage points, if it is found that some suspicious requests to read core data are not intercepted, it is necessary to adjust the data reading request judgment conditions in the traffic cleaning rules or add additional protective measures.
[0078] Step S156, extracting a feature vector of a new attack path from the penetration threat detection result, wherein the feature vector includes a protocol combination feature, a time distribution pattern, and a vulnerability exploitation chain.
[0079] For example, in an enterprise network, suppose a new attack path is discovered during the detection of attacks against a database server. In terms of protocol combination characteristics, it may be found that the attacker first uses the HTTP protocol to attempt an attack through a certain page of a Web application, and then after entering the enterprise's internal network, uses the internal SMTP protocol to hide or disguise information, hiding malicious data in the email content and sending it to the service process related to the database server. In terms of time distribution patterns, it is found that this type of attack is mainly concentrated in the time period after the enterprise network maintenance personnel get off work. It may be that the attacker takes advantage of the relatively weak network monitoring during this time period to attack. In terms of vulnerability exploitation chain, the attacker first exploits an input validation vulnerability in the Web application that has not been repaired in time to enter the enterprise's internal network, and then exploits the trust relationship vulnerability between the database server and the mail server to send malicious instructions to the database server through the mail server, thereby attacking the database server.
[0080] Step S157, performing similarity clustering on the feature vector of the new attack path and the feature set of the historical attack pattern to generate an updated attack pattern classification tree.
[0081] In this embodiment, the feature vector of the newly discovered attack path can be compared with the historical attack pattern feature set in the threat knowledge base. For example, in the historical attack pattern feature set, there may be attack patterns for Web applications, attack patterns for mail servers, and separate attack patterns for database servers. The similarity between the new attack path and these historical attack patterns is analyzed by a similarity clustering algorithm. If it is found that the new attack path is similar to some historical attack patterns in terms of exploiting Web application vulnerabilities, but is new in the subsequent way of attacking the mail server, it will be clustered under the relevant attack pattern category, and the relevant branch and node relationships will be updated in the attack pattern classification tree to accurately reflect the relationship between the new attack pattern and the existing attack pattern.
[0082] Step S158, generating defense rule weights according to the execution effect data of the adaptive defense strategy, and the defense rule weights are used to adjust the rule matching priority and response speed.
[0083] For example, during the execution of a defense strategy for a database server, a traffic cleaning rule is set for the initial intrusion point (web application login page). If monitoring shows that this traffic cleaning rule is very effective in blocking attacks and almost intercepts all traffic that attempts to perform SQL injection attacks through the login page, then a higher weight is assigned to this traffic cleaning rule. This means that in the subsequent defense process, this rule will have a higher priority when matching access requests and will be able to respond more quickly when traffic that meets the rule is detected. On the contrary, if a defense rule (such as an access control policy for a privilege escalation point) is found to have a large number of missed reports during execution, that is, some abnormal privilege escalation attempts are not blocked in time, then a lower weight is assigned to this rule, reducing its matching priority and possibly adjusting its response speed-related parameters.
[0084] Step S159, synchronize the attack pattern classification tree and defense rule weights to the distributed storage nodes of the threat knowledge base, and trigger the incremental learning module of the multimodal threat prediction model to update the model parameters based on the feature vector of the new attack path and the defense rule weights.
[0085] In the threat knowledge base of the enterprise network, there may be multiple distributed storage nodes to ensure data redundancy and reliability. The updated attack pattern classification tree and defense rule weight data are accurately synchronized to these distributed storage nodes. For example, the data is sent to each storage node through a network communication protocol, and the consistency of the data between the storage nodes is ensured. This enables the security devices and detection systems in the entire enterprise network to obtain the latest attack pattern classification and defense rule weight information, so that they can work more effectively in the subsequent threat detection and defense process.
[0086] In addition, the multimodal threat prediction model plays an important role in the security protection of enterprise networks. When a new attack path is discovered and its feature vector is obtained, and the defense rule weight is determined according to the execution effect of the defense strategy, the incremental learning module of the multimodal threat prediction model is triggered. For example, the protocol parsing branch of the multimodal threat prediction model can update its parameters for protocol semantic parsing according to the protocol combination characteristics in the new attack path, so that it can more accurately identify similar protocol anomalies. The behavior pattern branch can adjust the analysis of the time dependency graph and the recognition pattern of abnormal behavior according to the time distribution pattern and vulnerability exploitation chain of the new attack path. The threat reasoning branch can optimize the algorithm parameters for attack stage division, vulnerability exploitation chain reconstruction, and privilege escalation path prediction according to the vulnerability exploitation chain and defense rule weights in the new attack path, thereby improving the prediction accuracy of the multimodal threat prediction model for future potential attacks.
[0087] In a possible implementation, the training process of the pre-trained multimodal threat prediction model includes:
[0088] Step S210, obtaining a multi-source heterogeneous training data set, wherein the multi-source heterogeneous training data set includes labeled attack traffic samples, normal behavior logs, and semi-labeled network behavior sequences.
[0089] In this embodiment, in a large enterprise network environment, the marked attack traffic samples can be derived from actual attack records that the enterprise network has suffered. For example, an external attacker once launched an SQL injection attack on the enterprise's database server, and the network security device recorded the traffic data containing attack features, such as data packets containing malicious SQL statements, and these data packets were marked as attack traffic samples. The normal behavior log is a record of network activities generated by each device during the normal daily operation of the enterprise network. Taking the internal office network of the enterprise as an example, the network traffic records when employees normally access the internal file server, mail server and external legal websites include source IP address, destination IP address, port number, protocol type and other information. These records constitute the normal behavior log. Semi-marked network behavior sequences may be some network behavior records that are suspected to have problems in preliminary analysis but have not yet been fully determined. For example, when the enterprise network interacts with a partner network for data, some abnormal traffic fluctuations and protocol interactions occur, but it is not clear whether it is normal business traffic fluctuations or potential attack behaviors. These network behavior sequences are marked as semi-marked network behavior sequences.
[0090] Step S220, constructing a protocol semantic encoder, a time pattern encoder and a threat relationship encoder to encode the protocol features, time features and topology features in the training data set respectively.
[0091] For the protocol semantic encoder, taking the database communication in the enterprise network as an example, the SQL*Net protocol used by the database server has specific protocol semantics. The protocol semantic encoder will parse the protocol features such as keywords and grammatical structures in the protocol. For example, in the SQL*Net protocol, the order and semantic meaning of the keywords such as "SELECT", "FROM", and "WHERE" in the query statement are encoded, and the version number, service type and other information in the protocol header are encoded to accurately represent the protocol semantic features. The time pattern encoder encodes the time characteristics of network behavior. For example, in the mail server communication in the enterprise network, observe the time pattern of mail sending. The peak period of mail sending may be from 9 to 11 am and from 2 to 4 pm on weekdays, while the amount of mail sent in other time periods is relatively small. The time pattern encoder will quantify and encode this time feature, including the time interval of data packet sending, the time distribution of traffic peaks and valleys, etc. The threat relationship encoder focuses on the encoding of network topology features. In the enterprise network, the network topology structure includes the connection relationship between multiple subnets, servers, firewalls, routers and other devices. The threat relationship encoder will encode the topological features such as the connection relationship and trust relationship between devices. For example, a trust relationship between a database server and an application server may allow specific ports to communicate, and the encoder will encode this relationship as a feature related to threat judgment.
[0092] Step S230, aligning the feature spaces of different encoders through a cross-modal contrastive learning algorithm to generate a unified multimodal feature representation.
[0093] Continuing with the example of the enterprise network, in the network communication analysis of the database server, the protocol features obtained by the protocol semantic encoder, the temporal features obtained by the temporal pattern encoder, and the topological features obtained by the threat relationship encoder were originally in different feature spaces. The cross-modal contrastive learning algorithm aligns the relationships between different features into a unified multimodal feature representation space. For example, when analyzing the potential risk of attacks on database servers, it may be found that a specific protocol anomaly (protocol semantic feature) is associated with a traffic peak in a specific time period (temporal feature) and the connection between the database server and a suspicious external IP address (topological feature). By learning this association, the cross-modal contrastive learning algorithm fuses the features of these three different modalities into a unified feature representation so that subsequent models can comprehensively analyze potential threats.
[0094] Step S240: Generate synthetic attack samples using a generative adversarial network, and mix them with real attack samples for model pre-training.
[0095] For example, the adversarial generative network generates synthetic attack samples based on the distribution characteristics of existing attack samples and normal samples. For example, given some features of SQL injection attack samples against enterprise web applications, such as the structural pattern of malicious SQL statements, the target field of the attack, etc., the adversarial generative network will generate synthetic attack samples with similar features but with slight differences. These synthetic attack samples are mixed with real attack samples (such as the SQL injection attack records that the enterprise has actually suffered before) to pre-train the multimodal threat prediction model. Doing so can increase the model's ability to identify different types of attacks, especially for those attack patterns that may have variants or emerge.
[0096] Step S250, jointly optimizing the attack classification loss, path prediction loss and threat score regression loss through a multi-task learning framework to generate an initial multimodal threat prediction model.
[0097] For example, for potential threat analysis of database servers, in terms of attack classification loss, the model needs to accurately distinguish between normal traffic and attack traffic. For example, for database query traffic, if normal queries are misclassified as attacks or attack traffic is misclassified as normal traffic, the attack classification loss will increase. In terms of path prediction loss, when predicting possible penetration paths of attackers, such as the path from the external network through the web application to the database server, if there is a large deviation between the predicted path and the actual attack path, path prediction loss will be generated. Threat score regression loss involves the accuracy of scoring potential threats. If the model scores the threat level faced by the database server too high or too low, which does not match the actual threat severity, threat score regression loss will be generated. The multi-task learning framework jointly optimizes these three losses, adjusts the parameters of the model, and finally generates an initial multimodal threat prediction model, enabling it to achieve good performance in attack classification, path prediction, and threat scoring.
[0098] Step S260, continuously optimizing the initial multimodal threat prediction model using an online learning mechanism, including adjusting the model attention mechanism and feature fusion weights based on real-time network traffic data.
[0099] In the daily operation of enterprise networks, real-time network traffic data is constantly generated. For example, as the enterprise business develops, new application systems may be launched or new partner networks may be connected. Based on these real-time network traffic data, the model's attention mechanism will be adjusted. If a new protocol interaction mode is generated by a newly launched application system, the model will allocate more attention to the analysis of this new protocol interaction mode. At the same time, the feature fusion weights will also be adjusted according to real-time data. For example, during a certain period of time, a subnet in the enterprise network has abnormal traffic fluctuations. At this time, the importance of time features in judging potential threats may increase. The model will accordingly increase the weight of time features in feature fusion to better adapt to changes in the network environment.
[0100] In a possible implementation manner, the steps of constructing and maintaining the threat knowledge base include:
[0101] Step S310, extracting attack behavior metadata from public vulnerability databases, penetration test reports, and honeypot system logs.
[0102] In enterprise network security management, public vulnerability databases contain known vulnerability information of various software and systems. For example, the Oracle database used by the enterprise's database server may contain vulnerability information for a specific version of Oracle, such as buffer overflow vulnerabilities, authentication bypass vulnerabilities, and other related attack behavior metadata. A penetration test report is a report on the results of a penetration test conducted on the enterprise network by an internal or external security team of the enterprise. It contains attack behavior metadata such as potential attack paths, exploited vulnerabilities, and attack methods found in a simulated attack environment. The honeypot system log records the behavior of attackers attracted by a honeypot (a deliberately set bait system). For example, the honeypot system disguises itself as a key server of the enterprise. When an attacker attempts to attack the honeypot, the honeypot system records the attacker's IP address, attack time, attack type (such as brute force password cracking, malicious scanning, etc.), and other attack behavior metadata.
[0103] Step S320, structurally process the attack behavior metadata to generate a standardized attack pattern description framework, wherein the attack pattern description framework includes attack stages, exploitation techniques, and impact scope.
[0104] Take the attack on the enterprise database server as an example. In terms of the attack phase, the first phase may be the information collection phase, where the attacker obtains information such as the version number of the database server by scanning the port information of the enterprise network; the next phase is the exploitation phase, where the attacker exploits a known vulnerability in the database, such as a weak password vulnerability, and attempts to log in to the database server; the last phase is the impact scope phase. If the attacker successfully logs in, he may obtain the core data of the enterprise (such as financial data, customer information, etc.), affecting the normal operation and data security of the enterprise. By structuring the attack behavior metadata obtained from various sources, these attack processes are described according to the attack phase, exploitation technology and impact scope, forming a standardized attack pattern description framework.
[0105] Step S330, establishing a correlation map between attack modes, wherein the correlation map includes vulnerability dependencies, attack tool chains, and lateral movement paths.
[0106] In an enterprise network, consider attacks against multiple servers. For database servers and application servers, if there is a permission management vulnerability in the database server, and this vulnerability can be exploited by malicious programs on the application server to elevate permissions, this forms a vulnerability dependency. In terms of the attack tool chain, an attacker may first use a port scanning tool to obtain the open port information of the enterprise network, then use a vulnerability scanning tool to determine the exploitable vulnerability, and then use a specific attack tool (such as an injection tool for the database) to attack. The order and association between these tools constitute the attack tool chain. In terms of lateral movement paths, if an attacker successfully invades a server in a subnet of the enterprise, he may use the trust relationship between the server and other subnet servers to move laterally to servers in other subnets to continue the attack. This movement path between different subnets within the enterprise network constitutes a lateral movement path. By establishing a correlation map between these attack modes, we can more comprehensively understand the relationship between different attack modes and provide a deeper basis for threat detection and defense.
[0107] Step S340: construct a threat retrieval model based on graph neural network to quickly match similar attack patterns according to the input feature vector.
[0108] In enterprise network security protection, when a potential attack behavior is detected, its feature vector is input into the threat retrieval model based on graph neural network. For example, when abnormal database access behavior is found in the enterprise network, the feature vector of this abnormal behavior (including protocol features, time features, source and destination IP addresses, etc.) is input into the model. The model quickly searches for attack patterns similar to the feature vector based on the previously constructed attack pattern association map. If there are similar attack patterns, the existing defense measures and attack analysis results can be referred to and corresponding defense strategies can be adopted in a timely manner.
[0109] Step S350, construct a knowledge base version control mechanism to record the content changes and impact assessment results of each update.
[0110] In the threat knowledge base management of enterprise networks, each update may be due to the discovery of new attack patterns or a deeper understanding of existing attack patterns. For example, when a new attack method against the mail server in the enterprise network is discovered, the knowledge base version control mechanism will record the information related to the newly added attack pattern, including the characteristics of the attack, the vulnerabilities exploited, and other content changes. At the same time, the impact of this new attack pattern on the enterprise network security will be evaluated, such as the range of servers that may be affected, the risk of data leakage, and other impact assessment results. Through this version control mechanism, the development of the threat knowledge base can be tracked to ensure the accuracy and effectiveness of the knowledge base.
[0111] Step S360: regularly archive expired attack patterns in the knowledge base and perform version iteration based on new attack data.
[0112] With the development of technology and the strengthening of network security protection measures, some past attack patterns may no longer pose a threat due to system upgrades, vulnerability repairs, etc. For example, if an enterprise upgrades the version of the database server and repairs a previously existing serious vulnerability, the attack pattern associated with this vulnerability may no longer be effective in the current network environment. Archive these expired attack patterns regularly and remove them from the active threat knowledge base to reduce unnecessary queries and analysis. At the same time, based on new attack data, such as newly emerging zero-day vulnerability attack data targeting enterprise network applications, iterate the threat knowledge base version, update the attack pattern description framework, association map and other content to adapt to the new network security situation.
[0113] Wherein, step S150 further includes:
[0114] Step S410: parsing the policy instruction set in the adaptive defense policy to generate a security configuration command executable by a device.
[0115] For example, for the adaptive defense strategy previously developed for the database server, its policy instruction set includes defense measures for each key defense node of the database server (such as the initial intrusion point, the privilege escalation point, and the data leakage point). By parsing this policy instruction set, for the defense measures of the initial intrusion point (the web application login page), security configuration commands executable by the firewall are generated, such as setting specific access control list (ACL) rules to allow or prohibit access to a specific IP address range; for the defense measures of the database server's privilege management module, privilege control commands that can be recognized by the database's own security mechanism are generated, such as limiting the operation permissions of specific user roles on the privilege management module.
[0116] Step S420: convert the format of the security configuration command according to the security device type, wherein the format conversion includes firewall rule syntax conversion and intrusion detection system signature generation.
[0117] For firewall devices, convert the previously generated security configuration commands for the web application login page into rule syntax that the firewall can recognize. For example, write the access control list rules according to the specific syntax format of the firewall to ensure that the firewall can parse and execute them correctly. For intrusion detection systems (IDS) or intrusion prevention systems (IPS), generate intrusion detection system signatures based on the relevant defense measures in the adaptive defense strategy. For example, if the defense strategy includes detection of specific malicious database operations, convert this detection rule into a signature pattern that the IDS can recognize so that the IDS can promptly detect and prevent similar malicious behaviors.
[0118] Step S430: Distribute the converted security configuration command to the protection devices in the corresponding network area through the security orchestration platform.
[0119] Under the enterprise network architecture, the security orchestration platform is responsible for coordinating and managing security devices in each network area. For example, the security configuration commands for the database server in the enterprise's internal R&D subnet are distributed to the firewall, IDS, IPS in the R&D subnet, and the database server's own security protection module and other protection devices through the security orchestration platform. Ensure that each protection device can receive the security configuration commands related to itself, thereby achieving comprehensive protection for the database server.
[0120] Step S440: Establish a policy execution monitoring channel to collect the policy effectiveness status and traffic interception logs of each device in real time.
[0121] In order to ensure the effective execution of defense strategies, establish a strategy execution monitoring channel. For firewall devices, collect in real time whether the strategy is effective to intercept or release traffic according to the predetermined access control rules, and record detailed information of intercepted traffic (such as source IP address, destination IP address, protocol type, and other traffic interception logs). For IDS or IPS devices, collect whether it successfully detects intrusion behavior and the corresponding detection result log. For the security protection module of the database server itself, collect log information such as the monitoring results of permission operations and the execution of data access control.
[0122] Step S450, when a policy conflict or device execution abnormality is detected through the policy execution monitoring channel, a rollback mechanism is started and an alarm notification is generated, and the policy execution effect data is fed back to the multimodal threat prediction model for reinforcement learning.
[0123] If a new configuration rule of the firewall conflicts with the original rule, for example, the new access control rule causes legitimate business traffic to be intercepted incorrectly, the policy execution monitoring channel detects this situation and immediately starts the rollback mechanism to restore the firewall configuration to its previous normal state, and generates an alarm notification to send to the network security manager. At the same time, the firewall's policy execution effect data (such as the characteristics of the traffic that was intercepted incorrectly, the situation where normal traffic was misjudged, etc.) is fed back to the multimodal threat prediction model. The multimodal threat prediction model performs reinforcement learning based on this feedback data and adjusts its own model parameters to avoid similar errors in future threat prediction and defense strategy generation.
[0124] In a possible implementation, the method further includes:
[0125] Step S510, constructing a network security situation indicator system, including attack activity, vulnerability exposure and defense effectiveness dimensions.
[0126] In this embodiment, the attack activity can be measured from multiple aspects. For example, by analyzing the network traffic data, the number of suspected attack behaviors detected within a certain period of time (such as one day or one week) is counted. If within a certain day, the intrusion detection system in the enterprise network detects a large number of SQL injection attempts against the database server and abnormal scanning behaviors on the network port, this indicates that the attack activity is high. For the vulnerability exposure surface, it is necessary to consider the known vulnerabilities of various devices and systems in the enterprise network. Taking the office computers of the enterprise as an example, if the operating systems installed on these computers are not updated with patches in time, the vulnerability exposure surface will increase. At the same time, the servers within the enterprise, such as mail servers, file servers, etc., will also become part of the vulnerability exposure surface if there are improper configurations or outdated software versions. The defense effectiveness dimension involves the ability of the deployed security measures to resist potential threats. For example, the success rate of firewall interception of external malicious traffic, the accurate detection rate of intrusion detection system for intrusion behavior, and whether the patches for vulnerabilities are effectively prevented after deployment, etc., all reflect the effectiveness of defense.
[0127] Step S520: extracting original data of situation indicators from the penetration threat detection result and the policy execution monitoring channel.
[0128] For example, if the penetration threat detection results show that an attacker approaches the database server through a specific path (such as invading the database server from the external network through a web application), this information can be used to measure the attack activity and vulnerability exposure. For example, the existence of this attack path indicates that attack attempts against the database server are relatively active, and it also exposes the security vulnerabilities of the path where the database server is located. The data obtained from the policy execution monitoring channel is also critical. For example, the firewall's policy execution monitoring channel records the firewall's interception of various types of traffic, and this data can be used to evaluate the effectiveness of the defense. If the firewall successfully intercepts a large number of access requests from external suspicious IP addresses, this is a positive feedback for the defense effectiveness indicator; conversely, if a large amount of suspicious traffic penetrates the firewall, it means that there is a problem with the effectiveness of the defense.
[0129] Step S530, calculating the comprehensive threat index and risk distribution heat map of the current network system through a spatiotemporal fusion algorithm.
[0130] For example, in the time dimension, the changes in attack activity at different times of the day are analyzed. During working hours, the traffic of the enterprise network is large, and the attacks may be more focused on obtaining internal information resources; after get off work, there may be more attacks that attempt to break through the network boundary protection. In the spatial dimension, the security status of different subnets is different. The R&D subnet may have more vulnerability exposures due to frequent activities such as software testing; and the financial subnet may become a key target of attack due to the storage of important data. Combining these time and space factors, the comprehensive threat index of the entire network system is calculated. For example, if the attack activity of the R&D subnet suddenly increases in a certain period of time, new vulnerabilities are discovered, and the defense effectiveness of the firewall against the subnet decreases, then the comprehensive threat index will increase accordingly. Based on these calculation results, a risk distribution heat map is generated, in which the risk level of each area of the enterprise network (such as different subnets, server areas, etc.) can be intuitively seen. A high-risk area (such as a red area) may indicate that the comprehensive threat index of the area is high. For example, the area where the database server is located is displayed as a high-risk area on the heat map due to the existence of potential attack paths and high attack activity. A low-risk area (such as a green area) indicates that the area is relatively safe, such as some ordinary office subnets within the enterprise, where no obvious attack behavior has been found and the defense measures are effective.
[0131] Step S540, generating a multi-level visualization view, including a three-dimensional topological map of the attack path, a threat evolution timeline, and a defense effect comparison dashboard.
[0132] For the three-dimensional topology of attack paths, taking the attack on the database server in the enterprise network as an example, the starting point of the attack (such as the location of the IP address of the external attacker), the network devices (such as firewalls, routers, etc.) passed through in the middle, and the final target (database server) are displayed in three-dimensional space. The intensity and success rate of the attack are represented by different line colors and thicknesses. For example, a thicker red line may indicate a successful attack attempt, and a thinner yellow line indicates a suspected attack detection path. The threat evolution timeline shows the changes in threats faced by the enterprise network over time. From the initial discovery of a simple port scan against the database server (in the early stages of the timeline) to the subsequent complex attack attempts (such as a combined attack using multiple vulnerabilities), as well as the corresponding adjustment process of the defense measures can all be reflected on the timeline. The defense effect comparison dashboard can intuitively compare the defense effects of different security devices or different defense strategies in different time periods. For example, on a dashboard, the change curve of the firewall's interception success rate within a week can be displayed, and the detection accuracy curve of the intrusion detection system in the same time period can be displayed at the same time, so that network security managers can clearly see the execution effect of each defense measure and compare them.
[0133] Step S550, setting an adaptive warning threshold, and triggering a multi-level warning notification when the comprehensive threat index exceeds the set threat index.
[0134] In enterprise network security management, adaptive warning thresholds are set according to the business needs and network security strategies of the enterprise. For example, considering the importance of the core data of the enterprise (such as financial data, R&D results, etc.), if the comprehensive threat index reaches a higher value (set threat index), it indicates that the network faces a greater risk. When the comprehensive threat index exceeds this set value, a multi-level alarm notification is triggered. The first-level alarm may be an email notification sent to the network security administrator to inform the network security administrator of the increase in overall risk and attach a brief threat overview; the second-level alarm may be a text message notification sent to senior management of the enterprise, emphasizing the serious impact that network security risks may have on the enterprise's business; if the comprehensive threat index continues to rise to a more dangerous level, the third-level alarm may be triggered, such as popping up an emergency alarm window in the enterprise's internal security management system, requiring immediate measures to deal with network security threats.
[0135] Step S560, providing a threat tracing analysis tool and a defense strategy simulation test environment through an interactive interface.
[0136] On the security management platform of the enterprise network, a threat tracing analysis tool is provided to network security personnel through an interactive interface. For example, when a database server is found to be under attack, security personnel can use this tool to enter attack-related information (such as the time of the attack, the IP address of the attack source, etc.) on the interface. Then the tool will conduct in-depth mining based on network traffic data, log files and other information to trace the source of the attack. It may be found that the attacker first used an infected office computer within the enterprise as a springboard, and then gradually infiltrated the database server. At the same time, this interactive interface also provides a defense strategy simulation test environment. Network security personnel can simulate the effect of different defense strategies on potential attacks in this environment. For example, simulate the adjustment of the firewall's access control policy, and then observe whether the attack attempt against the database server can be effectively blocked under this new policy. In this way, the defense strategy can be evaluated and optimized to improve the overall security of the enterprise network.
[0137] Figure 2 The hardware structure of the artificial intelligence-based network security penetration detection system 100 for implementing the artificial intelligence-based network security penetration detection method provided in an embodiment of the present invention is shown as follows: Figure 2 As shown, the artificial intelligence-based network security penetration detection system 100 may include a processor 110 , a machine-readable storage medium 120 , a bus 130 , and a communication unit 140 .
[0138] In one possible design, the artificial intelligence-based network security penetration detection system 100 can be directly connected to the machine-readable storage medium 120 to access the stored information and / or data. In some embodiments, the artificial intelligence-based network security penetration detection system 100 can be implemented on an artificial intelligence-based network security penetration detection system.
[0139] The machine-readable storage medium 120 may store data and / or instructions. In some embodiments, the machine-readable storage medium 120 may store data obtained from an external terminal. In some embodiments, the machine-readable storage medium 120 may store data and / or instructions that the artificial intelligence-based network security penetration detection system 100 uses to execute or use to complete the exemplary method described in the present invention.
[0140] During the specific implementation process, one or more processors 110 execute computer executable instructions stored in the machine-readable storage medium 120, so that the processor 110 can execute the artificial intelligence-based network security penetration detection method of the above method embodiment. The processor 110, the machine-readable storage medium 120 and the communication unit 140 are connected through the bus 130, and the processor 110 can be used to control the sending and receiving actions of the communication unit 140.
[0141] The specific implementation process of the processor 110 can refer to the various method embodiments executed by the above-mentioned artificial intelligence-based network security penetration detection system 100. The implementation principles and technical effects are similar, and this embodiment will not be repeated here.
[0142] In addition, an embodiment of the present invention further provides a readable storage medium, in which computer executable instructions are preset. When a processor executes the computer executable instructions, the above-mentioned artificial intelligence-based network security penetration detection method is implemented.
[0143] It should be noted that in order to simplify the description of the present invention and thus help understand one or more embodiments of the invention, in the foregoing description of the embodiments of the present invention, various features are sometimes combined into one embodiment, drawing or description thereof.
Claims
1. A network security penetration detection method based on artificial intelligence, characterized in that: The method comprises: Obtaining real-time network traffic data of the target network system, wherein the network traffic data includes multi-dimensional communication behavior records and corresponding protocol metadata; Extracting behavior features from the network traffic data to obtain network behavior sequence features, where the network behavior sequence features are used to describe the relevance of communication behaviors in the time dimension and protocol interaction patterns; Inputting the network behavior sequence features into a pre-trained multimodal threat prediction model to generate a potential attack vector prediction result, wherein the potential attack vector prediction result includes an attack intention label, a penetration path probability distribution, and a threat level score; Dynamically verifying the potential attack vector prediction result based on the threat knowledge base to generate a penetration threat detection result, wherein the penetration threat detection result includes a verified attack path topology and a matching vulnerability identifier; An adaptive defense strategy is generated according to the penetration threat detection result, and the defense interface of the target network system is triggered to execute the strategy deployment, while the attack mode characteristics and defense rule set in the threat knowledge base are updated.
2. The network security penetration detection method based on artificial intelligence according to claim 1 is characterized in that: The network traffic data includes data packets of multiple communication protocol layers, and the behavior feature extraction of the network traffic data to obtain network behavior sequence features includes: Extracting a protocol type identifier, a port number sequence, and a load length distribution from a protocol header of the data packet, and constructing a protocol interaction feature matrix based on the protocol type identifier, the port number sequence, and the load length distribution; Dividing the transmission timestamp of the data packet into time windows to generate traffic statistical features in multiple time segments, wherein the traffic statistical features include request-response ratio, data packet rate fluctuation, and connection survival period; Cross-modally fusing the protocol interaction feature matrix with the traffic statistical features to generate an initial behavior sequence; Performing abnormal behavior enhancement processing on the initial behavior sequence, wherein the abnormal behavior enhancement processing includes injecting simulated attack behavior data and normal behavior noise data to generate an adversarial training sample set; The adversarial training sample set is subjected to feature dimension reduction and pattern extraction through a temporal convolutional network, and the network behavior sequence features are output, wherein the network behavior sequence features include a protocol layer behavior pattern vector and a time dependency relationship map.
3. The network security penetration detection method based on artificial intelligence according to claim 2 is characterized in that: The multimodal threat prediction model includes a protocol analysis branch, a behavior pattern branch, and a threat reasoning branch. The network behavior sequence features are input into the pre-trained multimodal threat prediction model to generate a potential attack vector prediction result, including: Performing protocol semantic analysis on the protocol layer behavior pattern vector through the protocol analysis branch, extracting a protocol keyword set and load structure features, and generating a protocol threat probability matrix; Performing a graph structure traversal on the time dependency graph through the behavior pattern branch, identifying high-frequency connection nodes and abnormal path jumps, and generating a behavior anomaly scoring matrix; Performing cross-modal attention alignment on the protocol threat probability matrix and the behavior anomaly score matrix to generate a fused threat feature; Performing multi-level reasoning on the fused threat feature through the threat reasoning branch, the multi-level reasoning includes attack stage division, vulnerability exploitation chain reconstruction and privilege escalation path prediction, and generating the attack intention label and the penetration path probability distribution; The threat level score is generated by performing weighted fusion based on the protocol threat probability matrix, the behavior anomaly score matrix and the penetration path probability distribution.
4. The network security penetration detection method based on artificial intelligence according to claim 3 is characterized in that: The dynamically verifying the potential attack vector prediction result based on the threat knowledge base to generate the penetration threat detection result includes: Extracting a historical attack pattern feature set from the threat knowledge base, wherein the historical attack pattern feature set includes known attack fingerprints, vulnerability exploitation signatures, and attack path templates; Performing intent matching on the attack intention label and the historical attack pattern feature set, and identifying a candidate attack pattern with a matching degree higher than a set matching degree; Performing path correction on the probability distribution of the penetration path based on the candidate attack mode, wherein the path correction includes deleting low-probability branches and supplementing uncovered attack steps to generate an optimized attack path set; Performing vulnerability existence verification on each path node in the optimized attack path set, wherein the vulnerability existence verification includes querying the asset topology map and vulnerability database of the target network system to generate the vulnerability identifier; The attack path topology is constructed according to the verification result, and new attack paths that are not matched to the historical attack pattern feature set are added to the threat knowledge base.
5. The network security penetration detection method based on artificial intelligence according to claim 4 is characterized in that: Generating an adaptive defense strategy according to the penetration threat detection result includes: Determine key defense nodes according to the attack path topology, wherein the key defense nodes include initial intrusion points, privilege escalation points, and data leakage points; Generate a defense action sequence for each of the key defense nodes, wherein the defense action sequence includes traffic cleaning rules, access control policies, and vulnerability patch deployment priorities; adjusting the execution order and triggering conditions of the defense action sequence according to the threat level score; Encapsulating the defense action sequence into an executable policy instruction set, and distributing it to the security device of the target network system through the defense interface; The execution effect of the strategy instruction set is monitored in real time, and the parameter thresholds in the defense action sequence are dynamically adjusted according to the monitoring data.
6. The network security penetration detection method based on artificial intelligence according to claim 5 is characterized in that: The updating of the attack pattern features and defense rule sets in the threat knowledge base includes: Extracting a feature vector of a new attack path from the penetration threat detection result, wherein the feature vector includes a protocol combination feature, a time distribution pattern, and a vulnerability exploitation chain; Performing similarity clustering on the feature vector of the new attack path and the feature set of the historical attack pattern to generate an updated attack pattern classification tree; Generate defense rule weights according to the execution effect data of the adaptive defense strategy, and the defense rule weights are used to adjust the rule matching priority and response speed; Synchronizing the attack pattern classification tree and defense rule weights to the distributed storage nodes of the threat knowledge base; The incremental learning module of the multimodal threat prediction model is triggered to update the model parameters based on the feature vector of the new attack path and the defense rule weight.
7. The network security penetration detection method based on artificial intelligence according to claim 6 is characterized in that: The training process of the pre-trained multimodal threat prediction model includes: Acquire a multi-source heterogeneous training data set, wherein the multi-source heterogeneous training data set includes labeled attack traffic samples, normal behavior logs, and semi-labeled network behavior sequences; Constructing a protocol semantic encoder, a time pattern encoder and a threat relationship encoder to respectively encode the protocol features, time features and topological features in the training data set; Align the feature spaces of different encoders through a cross-modal contrastive learning algorithm to generate a unified multimodal feature representation; Use a generative adversarial network to generate synthetic attack samples, and mix them with real attack samples for model pre-training; The attack classification loss, path prediction loss, and threat score regression loss are jointly optimized through a multi-task learning framework to generate an initial multimodal threat prediction model. The initial multimodal threat prediction model is continuously optimized using an online learning mechanism, including adjusting the model attention mechanism and feature fusion weights based on real-time network traffic data.
8. The network security penetration detection method based on artificial intelligence according to claim 7 is characterized in that: The steps of constructing and maintaining the threat knowledge base include: Extract attack behavior metadata from public vulnerability databases, penetration test reports, and honeypot system logs; Structuring the attack behavior metadata to generate a standardized attack pattern description framework, wherein the attack pattern description framework includes attack stages, exploitation techniques, and impact scope; Establishing a correlation map between attack modes, wherein the correlation map includes vulnerability dependencies, attack tool chains, and lateral movement paths; Build a threat retrieval model based on graph neural network to quickly match similar attack patterns based on input feature vectors; Build a knowledge base version control mechanism to record content changes and impact assessment results of each update; Regularly archive outdated attack patterns in the knowledge base and iterate versions based on new attack data; The triggering of the defense interface execution strategy deployment of the target network system includes: Parsing the policy instruction set in the adaptive defense policy to generate a security configuration command executable by the device; Performing format conversion on the security configuration command according to the security device type, wherein the format conversion includes firewall rule syntax conversion and intrusion detection system signature generation; Distribute the converted security configuration commands to the protection devices in the corresponding network areas through the security orchestration platform; Establish a policy execution monitoring channel to collect the policy effectiveness status and traffic interception logs of each device in real time; When a policy conflict or device execution anomaly is detected through the policy execution monitoring channel, a rollback mechanism is initiated and an alarm notification is generated, and the policy execution effect data is fed back to the multimodal threat prediction model for reinforcement learning.
9. The network security penetration detection method based on artificial intelligence according to claim 8 is characterized in that: The method further comprises: Build a network security situation indicator system, including attack activity, vulnerability exposure and defense effectiveness dimensions; Extracting raw data of situation indicators from the penetration threat detection results and the strategy execution monitoring channel; Calculate the comprehensive threat index and risk distribution heat map of the current network system through the time-space fusion algorithm; Generate multi-level visualization views, including 3D topology of attack paths, threat evolution timeline, and defense effectiveness comparison dashboard; Setting an adaptive warning threshold, when the comprehensive threat index exceeds the set threat index, triggering a multi-level warning notification; Provides threat tracing analysis tools and defense strategy simulation testing environment through an interactive interface.
10. A network security penetration detection system based on artificial intelligence, characterized in that: The artificial intelligence-based network security penetration detection system includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the artificial intelligence-based network security penetration detection method described in any one of claims 1 to 9 above.
Citation Information
Cited By
Multi-modal content processing method, device, system and equipment generated by artificial intelligence
CN120277728A
Network threat detection method and system under dynamic protocol recombination
CN120321043A
A network threat detection method and system under dynamic protocol reorganization
CN120321043B
Network security protection method and system based on flow analysis
CN120321044A
Flow filtering method and device based on CC attack characteristics
CN120358098A