Network attack research and judgment method and system, program product, equipment and medium

By using large models and agent technologies in the network attack analysis and judgment system, automated network attack analysis and disposal is achieved, solving the problem that existing technology is difficult to deal with complex network threats, and providing a stronger security line and faster response capabilities.

CN120050097AActive Publication Date: 2025-05-27BEIJING TOPSEC NETWORK SECURITY TECH +2

Patent Information

Application Number
CN202510201918.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-27
Estimated Expiration
2045-02-24

AI Technical Summary

Technical Problem

The existing technology has difficulty effectively responding to increasingly complex cyber threats, especially in identifying unknown attack behaviors and providing a solid security line.

Method used

The automated network attack analysis and judgment method and system based on large models are adopted to achieve full process automation such as alarm analysis, attack behavior analysis, attack result evaluation, comprehensive report generation, disposal suggestions formulation and disposal rule creation through the collaborative work of the agent.

Benefits of technology

It improves the ability to analyze and judge known attacks, can identify unknown attack behaviors, form closed-loop protection measures, provide a more solid security line, and promptly respond to complex cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050097A_ABST
    Figure CN120050097A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network attack research and judgment method and system, a program product, equipment and a medium, the system deploys a plurality of agents, and the method comprises the following steps: inputting an attack sample into an attack feature extraction agent, and constructing an attack feature library based on the extracted attack features; inputting the network security log into a field extraction agent to obtain an extracted attack related field; inputting the attack feature library and the attack related fields into an attack analysis module, and obtaining attack analysis data of the attack analysis module on the attack related fields based on the attack feature library; inputting the threat intelligence data, the asset data and the attack analysis data into a comprehensive analysis report agent to obtain an analysis report including an attack result, an attack severity degree, an influence range and an attack technology; and inputting the analysis report into an attack processing module to obtain an attack processing plan. Attack research and judgment process automation is realized by utilizing the intelligent agent, the analysis, research and judgment capability on known attacks can be improved, unknown attack behaviors can be identified, and closed-loop protection measures are formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a network attack analysis method, system, program product, device and medium. Background Art

[0002] With the rapid development of Internet technology, network applications have penetrated into people's daily lives and business operations, becoming a key component. However, with its popularity, network security issues have become more serious. Attackers may leak sensitive information, illegally obtain server permissions, and even cause service interruptions through means such as SQL injection, remote code execution, and file inclusion vulnerabilities. In the face of these challenges, how to provide enterprises and users with a more solid security line of defense and respond to increasingly complex network threats in a timely manner is a technical problem that needs to be solved in this field. Summary of the invention

[0003] The purpose of the embodiments of the present application is to provide a network attack analysis method, system, program product, device and medium to achieve the technical effect of forming a protective measure for a closed loop of network security.

[0004] In a first aspect, an embodiment of the present application provides a network attack analysis method, which is applied to a network attack analysis system; the network attack analysis system is deployed with multiple agents; the method includes:

[0005] Input the acquired attack samples into the attack feature extraction agent, and build an attack feature library based on the extracted attack features;

[0006] Input the acquired network security log into a field extraction agent to obtain the extracted attack-related fields;

[0007] Inputting the attack feature library and the attack-related fields into an attack analysis module, and obtaining attack analysis data of the attack-related fields by the attack analysis module based on the attack feature library;

[0008] Input the threat intelligence data, asset data and the attack analysis data into a comprehensive analysis report agent to obtain an output analysis report, wherein the analysis report includes one or more of attack results, attack severity, impact scope and attack technology;

[0009] The analysis report is input into the attack handling module to obtain an output attack handling plan.

[0010] In the above implementation process, an agent is used to automate the entire process of alarm analysis, attack behavior analysis, attack result evaluation, comprehensive report generation, disposal suggestion formulation, and disposal rule creation. This not only improves the ability to analyze and judge known attacks but also helps identify unknown attack behaviors, forming a closed-loop protection measure, thereby providing a more solid security defense for enterprises and users to timely respond to increasingly complex network threats.

[0011] Further, the attack feature extraction agent includes a pre-trained large language model; inputting the obtained attack samples into the attack feature extraction agent and constructing an attack feature library based on the extracted attack features includes:

[0012] Input the obtained attack samples into the attack feature extraction agent, so that the attack feature extraction agent extracts attack metadata from the attack samples, and extracts the field values of the attack feature fields preset based on the protocol to which the attack samples belong, and uses the large language model to extract attack vectors from the attack metadata and the field values to obtain the attack features corresponding to each attack sample; wherein, the attack features include general fields for recording the attack metadata, protocol fields for recording the field values, and the attack vectors; the attack vectors carry the semantic information of the attack metadata and the field values;

[0013] Construct an attack feature library including each of the attack features.

[0014] In the above implementation process, general fields, protocol fields, and attack vectors are designed for attack samples to form attack features. Through this classification design, the attack feature library can not only efficiently store attack features but also provide refined attack analysis and query capabilities, thus better supporting security analysis and judgment and incident response. At the same time, through data structured processing, the problem of low analysis efficiency caused by format differences can be reduced.

[0015] Further, the network security logs include alarm logs and traffic logs; the attack-related fields include a suspected attack source IP field extracted from the alarm logs; inputting the attack feature library and the attack-related fields into the attack analysis module includes:

[0016] If the suspected attack source IP field in the alarm log matches the preset whitelist rule, determine that the first traffic packet corresponding to the alarm log in the traffic log is non-attack traffic;

[0017] If the suspected attack source IP field of the alarm log does not match the whitelist rule, determine the second traffic packet corresponding to the alarm log from the traffic log, and input the attack feature library and the attack-related fields of the second traffic packet into the attack analysis module.

[0018] In the above implementation process, by matching the suspected attack source IP field in the alarm log with the whitelist rule, the credible first traffic packets and the untrusted second traffic packets are screened out from the traffic log. The first traffic packets do not need to continue the attack analysis, thus reducing the burden of network attack research and judgment and improving the research and judgment efficiency.

[0019] Further, the network security log includes a traffic log, and the traffic log includes a request packet and a response packet; the attack analysis module includes an attack behavior analysis agent and an attack result analysis agent; the obtaining the attack analysis data of the attack-related fields by the attack analysis module based on the attack feature library includes:

[0020] Input the attack feature library and the first attack-related fields of the request packet into the attack behavior analysis agent, and obtain the attack behavior analysis data of the first attack-related fields by the attack behavior analysis agent based on the attack feature library;

[0021] Input the feature library and the second attack-related fields of the response packet into the attack result analysis agent, and obtain the attack result analysis data of the second attack-related fields by the attack result analysis agent based on the attack feature library, and obtain the attack analysis data including the attack behavior analysis data and the attack result analysis data.

[0022] In the above implementation process, the attack behavior analysis agent can receive and integrate multiple data sources, including structured alarm data and request packets. Through the comprehensive analysis of multi-dimensional data, the attack behavior analysis agent can improve the comprehensiveness of the recognition of attack behaviors. The attack result analysis agent can effectively judge whether the attack is successfully executed by analyzing the protocol fields, general fields of the response packet and their correlation with the attack features in detail.

[0023] Further, inputting the threat intelligence data, asset data and the attack analysis data into the comprehensive analysis report agent to obtain the output analysis report includes:

[0024] Input the threat intelligence data, asset data, and the attack analysis data into the comprehensive analysis report agent, so that the comprehensive analysis report agent determines the attack techniques and corresponding attack results based on the attack analysis data, matches the attack IPs recorded in the attack-related fields with the threat intelligence data to obtain the correlation assessment results between the attack IPs and known attack sources, determines the attacked assets from the asset data, and determines the attack severity based on the vulnerability data of the attacked assets and the correlation assessment results to obtain the analysis report.

[0025] Further, the attack handling module includes a handling suggestion generation agent and a handling rule generation agent; inputting the analysis report into the attack handling module to obtain the output attack handling plan, including:

[0026] Input the analysis report into the handling suggestion generation agent to obtain the output attack response suggestions; among them, the attack response suggestions include one or more of short-term handling suggestions, long-term handling suggestions, business recovery suggestions, and security reinforcement suggestions;

[0027] Input the analysis report into the handling rule generation agent to obtain the output attack handling rules; among them, the attack handling rules include one or more of blacklist rules, whitelist rules, feature matching rules, and behavior analysis rules respectively set for multiple different security devices.

[0028] In the above implementation process, use the handling suggestion generation agent to generate customized handling suggestions instead of relying on fixed templates or manual analysis. Solve the problem of mismatch between general handling suggestions and specific attack scenarios in traditional methods, making the suggestions more accurate and suitable for the actual scenario. And use the handling rule generation agent to generate security device rules adapted to specific attack scenarios, solve the problem of invalid rules or high false alarm rates caused by scenario mismatch in traditional rule generation methods, and significantly shorten the rule deployment cycle by dynamically generating rules.

[0029] The second aspect of the embodiments of this application provides a network attack judgment system, and the system includes:

[0030] An attack feature extraction agent, which is used to extract attack features from the obtained attack samples and construct an attack feature library including the attack features;

[0031] A field extraction agent, which is used to extract attack-related fields from the obtained network security logs;

[0032] An attack analysis module, which is used to generate attack analysis data for the attack-related fields based on the attack feature library;

[0033] A comprehensive analysis report agent for generating an analysis report based on threat intelligence data, asset data, and the attack analysis data, where the analysis report includes one or more of attack results, attack severity, scope of impact, and attack techniques;

[0034] An attack handling module for generating an attack handling plan based on the analysis report.

[0035] In a third aspect of the embodiments of the present application, a computer program product is provided. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the method described in any of the first aspects.

[0036] In a fourth aspect of the embodiments of the present application, an electronic device is provided. The electronic device includes:

[0037] A processor;

[0038] A memory for storing instructions executable by the processor;

[0039] Wherein, when the processor calls the executable instructions, it implements the operations of the method described in any of the first aspects.

[0040] In a fifth aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which computer instructions are stored, and when the computer instructions are executed by a processor, they implement the steps of the method described in any of the first aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] To more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0042] Figure 1 It is a schematic structural diagram of a network attack judgment system provided by an embodiment of the present application;

[0043] Figure 2 It is a schematic flowchart of a network attack judgment method provided by an embodiment of the present application;

[0044] Figure 3 It is a schematic structural diagram of an attack analysis module provided by an embodiment of the present application;

[0045] Figure 4 It is a schematic structural diagram of an attack handling module provided by an embodiment of the present application;

[0046] Figure 5 It is a schematic structural diagram of another network attack judgment system provided by an embodiment of the present application;

[0047] Figure 6 This is a hardware structure diagram of an electronic device provided by an embodiment of the present application. Specific implementation manners

[0048] Next, the technical solutions in the embodiments of the present application will be described in conjunction with the accompanying drawings in the embodiments of the present application.

[0049] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0050] Traditional security detection devices usually rely on known attack features for static detection and generate a large number of security alerts. In this case, the massive alerts will greatly increase the workload of operation and maintenance personnel. Especially for complex attack events, operation and maintenance personnel may have difficulty effectively and quickly identifying real security threats from them due to insufficient or limited experience, especially when facing unknown threat attacks.

[0051] In addition, traditional alert analysis and judgment methods usually rely on correlation analysis of alerts generated by deployed security devices or application of machine learning algorithms, but their analysis dimensions are relatively limited, which may affect the comprehensiveness and accuracy of analysis and judgment.

[0052] Furthermore, traditional threat detection mainly relies on security devices provided by manufacturers and their preset rule libraries to identify attacks through feature libraries and signature matching of known threats. However, due to differences in the rule libraries of each manufacturer and the low efficiency of the field standardization process, the overall detection accuracy and response efficiency are limited. In addition, it requires a high technical level of security operation personnel. Security operation personnel need to be familiar with different security devices to perform effective correlation queries and analysis. Moreover, this method has limitations in dealing with new or unknown threats and is difficult to effectively analyze and judge unrecorded or newly emerging attack patterns.

[0053] To effectively address these challenges, the embodiments of the present application design an automated network attack analysis and judgment method and system based on large models, which utilize the collaborative work of large models and agents to achieve full-process automation of alert analysis, attack behavior analysis, attack result evaluation, comprehensive report generation, disposal suggestion formulation, and disposal rule creation. It can not only improve the analysis and judgment ability of known attacks, but also help identify unknown attack behaviors, form a closed-loop protection measure, thereby providing a more solid security defense line for enterprises and users to timely respond to increasingly complex network threats.

[0054] The first aspect of the embodiment of the present application provides a network attack judgment method, which is applied to the network attack judgment system 100 as shown in Figure 1 . The network attack judgment system 100 deploys multiple agents, such as, including but not limited to, an attack feature extraction agent (Agent1) 110, a field extraction agent (Agent2) 120, an attack analysis module 130, a comprehensive analysis report agent (Agent5) 140, and an attack disposal module 150. Among them, the attack analysis module 130 includes multiple agents, and the attack disposal module 150 includes multiple agents, which will be described in detail below.

[0055] Each agent deploys one or more large models. A large model refers to a machine learning model with a large number of parameters and a complex computing structure, usually constructed by a deep neural network and having billions or even hundreds of billions of parameters. These models learn complex patterns and features by training massive amounts of data, have stronger generalization capabilities, and can make accurate predictions on unseen data. The large model can provide core capabilities for the agent, including but not limited to cognitive and generation capabilities, semantic understanding capabilities, multi-task generalization capabilities, etc. And the agent can expand the ability boundary of the large model. For example, the agent can endow the large model with action and interaction capabilities by integrating modules such as tool calls and sensor inputs. The agent can also save historical interaction information through a knowledge base, a database, or a vector store to make up for the short context limitation of the large model. And the agent can coordinate multi-step tasks through a planning algorithm, call the large model to generate a plan and execute it.

[0056] Specifically, a network attack judgment method provided by the embodiment of the present application includes steps 210-step 250 as shown in Figure 2 .

[0057] Step 210: Input the obtained attack sample into the attack feature extraction agent, and construct an attack feature library based on the extracted attack features.

[0058] Exemplarily, the attack feature extraction agent (Agent1) 110 can collect various attack samples from multi-channel threat intelligence sources. For example, it can rely on diverse intelligence sources such as public vulnerability databases (such as CVE, Exploit-DB, etc.), security community sharing (including security projects on GitHub, forums, etc.), vulnerability analysis and reproduction articles, and commercial vulnerability intelligence services, and collect various attack samples by combining Python crawlers and manual collation. The attack samples include, for example, but are not limited to, Proof of Concept (PoC) attack samples, Exploit (Exp) attack samples, and Payload attack samples, etc. The collected attack samples can be stored in text form with the naming method of "threat name + attack type". The attack feature extraction agent (Agent1) 110 can extract attack features from the obtained attack samples. Subsequently, an attack feature library including all the extracted attack features is constructed.

[0059] Step 220: Input the obtained network security logs into the field extraction agent to obtain the extracted attack-related fields.

[0060] Exemplarily, the network attack judgment system 100 can establish an API (Application Programming Interface) interface with the Security Operations Center (SOC) and / or the situation awareness platform, and receive network security logs in real time through the API interface. The field extraction agent (Agent2) 120 is an agent specially designed for network security log information extraction. The field extraction agent (Agent2) 120 can be used to extract attack-related fields from the network security logs.

[0061] As an example, the field extraction agent (Agent2) 120 is deployed with a pre-trained language model. The pre-trained language model is, for example, the BGE (Beijing Academy of Artificial Intelligence General Embedding) model developed by the Beijing Academy of Artificial Intelligence (BAAI). The field extraction agent (Agent2) 120 can use the pre-trained language model to extract multiple attack-related fields from the network security logs. The attack-related fields may include, but are not limited to: timestamp, source IP (Internet Protocol), source port, destination IP, destination port, risk level, request method, application protocol, HTTP (HyperText Transfer Protocol) response code, event type, alert type, alert category, request line, request header, request body, response line, response header, response body, URL (Uniform Resource Locator), host, User-Agent, content_type, number of upstream packets, number of downstream packets, upstream byte count, downstream byte count, x_Forwarded_For, etc.

[0062] After extracting the attack-related fields, the field extraction agent (Agent2) 120 can also clean and format the attack-related fields, such as removing irrelevant spaces, converting the time format, etc., and finally output structured data (such as JSON) for subsequent processing and analysis.

[0063] Step 230: Input the attack feature library and the attack-related fields into the attack analysis module, and obtain the attack analysis data of the attack analysis module based on the attack feature library for the attack-related fields.

[0064] Exemplarily, the attack analysis module 130 is a module specifically designed for analyzing network attack behaviors and network attack results. It can receive the attack feature library generated by the attack feature extraction agent (Agent1) 110 and the attack-related fields extracted by the field extraction agent (Agent2) 120, and perform attack analysis on the attack-related fields based on the attack feature library to obtain analysis data. As an example, the attack analysis module 130 can compare the attack-related fields extracted from each network security log with the attack features recorded in the attack feature library, so as to analyze the attack behavior and attack result of the network security log and obtain analysis data.

[0065] Step 240: Input the threat intelligence data, asset data, and the attack analysis data into the comprehensive analysis report agent to obtain an output analysis report, where the analysis report includes one or more of attack results, attack severity, scope of impact, and attack techniques.

[0066] Exemplarily, the comprehensive analysis report agent (Agent5) 140 is an agent designed for comprehensive analysis and generating analysis reports. It can receive the analysis data generated by the attack analysis module 130, and comprehensively analyze the attack event by combining the asset data in the asset management database and the threat intelligence data from the threat intelligence platform, so as to evaluate the attack results, attack techniques, scope of impact, and severity, and generate a corresponding analysis report. Among them, the asset management database records the asset data of various assets. The asset refers to network security devices, such as but not limited to firewalls, switches, routers, etc. The asset data may include but not limited to asset addresses, software names, version information, asset component vulnerability information, etc.

[0067] Step 250: Input the analysis report into the attack handling module to obtain an output attack handling plan.

[0068] Exemplarily, the attack handling module 150 is a module specifically used for creating an attack handling plan. It receives the analysis report generated by the comprehensive analysis report agent (Agent5) 140 and automatically generates an attack handling plan according to the analysis report to quickly respond to and prevent network attacks. The output attack handling plan can be sent to the operation and maintenance personnel for reference when they respond to network attacks.

[0069] Compared with the related art that mainly relies on the rule base of security detection devices to identify attack features and does not fully utilize threat intelligence sources to extract and compare attack features, it is difficult to form a global perspective and achieve comprehensive threat detection. In the embodiment of the present application, multi-channel threat intelligence sources are used to uniformly collect attack samples. The integration of multi-channel intelligence improves the threat coverage, reduces the problem of low analysis efficiency caused by intelligence redundancy, and realizes the rapid identification of potential threats. Thus, it can be ensured that the network attack judgment system 100 can quickly adapt to new threat scenarios, thereby enhancing the ability to respond to zero-day vulnerabilities or unknown threats. And it improves the accuracy and speed of feature extraction, while ensuring data consistency, providing a basis for subsequent retrieval and comparison analysis.

[0070] In addition, in terms of identifying attack fields, most related technologies extract limited attack fields through a predefined rule library, lacking flexibility, and updating the rule library requires a large amount of manual intervention. In the embodiments of the present application, the field extraction agent (Agent2) adopts an intelligent system based on a pre-trained model, which can identify approximate attack-related fields, improving the comprehensiveness of field extraction to better cope with complex information or unknown threat scenarios. At the same time, related technologies mostly rely on manual or simple keyword matching to process alarm data and are difficult to effectively process unstructured or semi-structured logs. The present invention can automatically parse and standardize diverse data formats, including unstructured text or log files in network security logs, and perform normalization conversion using intelligent parsing algorithms, thus solving the problem of difficult data processing caused by diverse formats and providing the possibility for unified analysis and integration of network security logs.

[0071] The attack analysis module uses the attack feature library to conduct attack analysis on attack-related fields and transmits the attack analysis data to the comprehensive analysis report agent (Agent5) to provide data support for comprehensive analysis. Subsequently, the comprehensive analysis report agent (Agent5) conducts multi-dimensional cross-analysis by integrating attack analysis data, asset data, and threat intelligence data, exceeding the traditional isolated analysis method for alarm information only. This method can achieve in-depth association of cross-source data, not only improving the accuracy of analysis results but also comprehensively evaluating the full-chain impact scope and severity of attack events, thus effectively reducing analysis omissions.

[0072] Finally, the attack disposal module specifies the attack disposal plan according to the analysis report instead of relying on a fixed template or manual analysis. It solves the mismatch problem between general disposal suggestions and specific attack scenarios in traditional methods, making the attack disposal plan more accurate and in line with the actual scenario.

[0073] It can be seen that the embodiments of the present application can bring the following beneficial effects:

[0074] (1) Through the large model and agent technology, the embodiments of the present application achieve the full automation of the analysis, research, judgment, and response disposal process of network security logs, significantly shortening the manual analysis and research time, improving the alarm handling efficiency, and effectively reducing the dependence on the professional experience of security personnel;

[0075] (2) Through comprehensive analysis and research on multi-dimensional data such as network security logs, asset data, and threat intelligence, the embodiments of the present application conduct in-depth analysis and evaluation from multiple perspectives to improve the comprehensiveness and accuracy of analysis and research;

[0076] (3) Through the comprehensive analysis technology of the large model and agent, the embodiments of the present application deeply match attack features with network security logs to identify potential unknown threats, demonstrating the ability in unknown threat hunting;

[0077] (4) The analysis reports and attack handling plans generated by the large model and the agent in the present invention visually display the threat detection and response results, assist security personnel in comprehensively understanding and accurately evaluating relevant information, thereby significantly improving the security operation efficiency and response ability, and thus forming a closed-loop response process.

[0078] The following provides a detailed introduction to steps 210 - 250.

[0079] According to some embodiments of the present application, the attack feature extraction agent (Agent1) 110 includes a pre-trained large language model. The pre-trained large language model is, for example, the Sentence-BERT (SBERT) model. The SBERT model is an improved model based on BERT (Bidirectional Encoder Representations from Transformers), and is specifically used to generate sentence-level embedding vectors (sentence embeddings). Different from the traditional BERT model, the SBERT model can efficiently compare the similarity between sentences without a large amount of computation.

[0080] Based on this, the process of extracting attack features and the process of constructing the attack feature library in step 210 may specifically include steps 211 - 212.

[0081] Step 211: Input the obtained attack samples into the attack feature extraction agent, so that the attack feature extraction agent extracts attack metadata from the attack samples, and the attack feature fields preset based on the protocol to which the attack samples belong, extracts the field values of the attack feature fields, and uses the large language model to extract attack vectors from the attack metadata and the field values, obtaining the attack features corresponding to each attack sample; wherein, the attack features include general fields for recording the attack metadata, protocol fields for recording the field values, and the attack vectors; the attack vectors carry the semantic information of the attack metadata and the field values;

[0082] Step 212. Construct an attack feature library including each of the attack features.

[0083] Exemplarily, after inputting the attack sample into the attack feature extraction agent (Agent1) 110, the attack feature extraction agent (Agent1) 110 can extract attack metadata from the attack sample and can create common fields to record the extracted attack metadata. The attack metadata can help to comprehensively understand the characteristics and background of the attack. Among them, the attack metadata includes but is not limited to threat name (attack_name), attack type (attacktype), attack severity (severity), Common Vulnerabilities and Exposures (CVE), creation time (create_time), update time (update_time), and attack description (description), etc.

[0084] In addition, corresponding attack feature fields can be pre-designed for different protocols. It can be understood that the attack sample is actually the captured known attack traffic, and the attack traffic is transmitted in the network based on various transmission protocols. The protocols include but are not limited to the HTTP protocol, TCP (Transmission Control Protocol) protocol, and DNS (Domain Name System) protocol, etc. In different protocols, attack behaviors and attack results will be reflected in different protocol fields. Therefore, the attack feature fields that can carry attack behavior information or attack result information in different protocols can be determined in advance to obtain the corresponding relationship between the protocol and the attack feature fields. When inputting the attack sample into the attack feature extraction agent (Agent1) 110, the attack feature extraction agent (Agent1) 110 can determine the corresponding attack feature fields based on the protocol to which the attack sample belongs, extract the field values of the attack feature fields, and create protocol fields to record the extracted attack feature fields and their field values.

[0085] Taking the HTTP protocol as an example, Table 1 shows the attack feature fields corresponding to the HTTP protocol.

[0086] Table 1

[0087]

[0088]

[0089] Subsequently, the attack feature extraction agent (Agent1) 110 can use a large language model, such as the SBERT model, to extract attack vectors from the attack metadata and the field values of the attack feature fields. The attack vectors carry the semantic information of the attack metadata and the field values.

[0090] Exemplarily, the attack feature extraction agent (Agent1) 110 can convert text data such as threat names, CVE numbers, attack types, network protocols, disclosure dates, vulnerability descriptions, and PoC / Payload / Exp attack code snippets in attack samples into high-dimensional vector representations through the SBERT model to obtain attack vectors. The attack vector of each attack sample not only retains the semantic information of the text data but also can efficiently capture the similarities and differences between different text data.

[0091] Finally, attack features can be obtained, including general fields for recording attack metadata, protocol fields for recording attack feature fields and their field values, and attack vectors. Continuing with the example of attack samples based on the HTTP protocol, Table 2 shows the attack features extracted from the attack samples recorded in the attack feature library.

[0092] Table 2

[0093]

[0094]

[0095] In addition, as described above, attack samples are actually known attack traffic. Attack traffic can be divided into request messages and response messages. Therefore, attack samples actually include attack request message samples and attack response message samples. Attack request message samples carry attack behavior information, and attack response message samples carry attack result information. The attack features recorded in the above attack feature library are the attack features extracted from attack request message samples and the attack features extracted from attack response message samples. Among them, in the attack features of attack request message samples, the protocol field carries attack behavior information; in the attack features of attack response message samples, the protocol field carries attack result information.

[0096] In addition, the attack feature extraction agent (Agent1) 110 can further perform data cleaning on the extracted attack features, including but not limited to removing duplicate samples, unifying the sample format (such as JSON format), and removing invalid or damaged attack samples, so as to convert the attack features into a structured storage format for convenient subsequent rapid retrieval and efficient analysis.

[0097] It can be seen that in this embodiment, general fields, protocol fields, and attack vectors are designed for attack samples to form attack features. Through this classification design, the attack feature library can not only efficiently store attack features but also provide refined attack analysis and query capabilities, thus better supporting security analysis and judgment and incident response. At the same time, through data structuring processing, the problem of low analysis efficiency caused by format differences can be reduced.

[0098] Based on any of the above embodiments, the network security logs include alarm logs and traffic logs. Among them, the traffic logs record all data flow information in the network, including various packets sent and received. It can be seen that there is attack traffic and non-attack traffic in the traffic logs. When the detection system detects traffic that may have an attack behavior from the traffic logs, corresponding alarm logs will be generated. Therefore, the alarm logs can match one or some of the traffic packets in the traffic logs.

[0099] It can be seen that the attack-related fields extracted from the network security logs in step 220 include the attack-related fields extracted from the alarm logs and the attack-related fields extracted from the traffic logs. Among them, the attack-related fields extracted from the alarm logs include the suspected attack source IP field. The suspected attack source IP field can be the source IP or the destination IP. Whether to input the traffic packet matching the alarm log into the attack analysis module for analysis can specifically include the following two situations:

[0100] Situation 1) If the suspected attack source IP field of the alarm log matches the preset white list rule, determine that the first traffic packet corresponding to the alarm log in the traffic log is non-attack traffic.

[0101] Exemplarily, if the suspected attack source IP field extracted from the alarm log belongs to the white list IP recorded in the white list rule, it means that the suspected attack source IP is trustworthy. At this time, the first traffic packet corresponding to the alarm log can be determined from the traffic log, and it is determined that the first traffic packet is non-attack traffic and does not need to be input into the attack analysis module for analysis. Among them, the first traffic packet can include one or more, and the first traffic packet can be a request packet and / or a response packet.

[0102] Situation 2) If the suspected attack source IP field of the alarm log does not match the white list rule, determine the second traffic packet corresponding to the alarm log from the traffic log, and input the attack feature library and the attack-related fields of the second traffic packet into the attack analysis module.

[0103] Exemplarily, if the suspected attack source IP field extracted from the alarm log does not belong to the white list IP recorded in the white list rule, it means that the suspected attack source IP is untrustworthy. At this time, the second traffic packet corresponding to the alarm log can be determined from the traffic log, and the second traffic packet and the attack feature library are input into the attack analysis module for analysis. Among them, the second traffic packet can include one or more, and the second traffic packet can be a request packet and / or a response packet. The first traffic packet and the second traffic packet do not specifically refer to a certain one or some packets in this embodiment, and they are only used to distinguish whether the traffic packet comes from a white list IP.

[0104] It can be seen that in this embodiment, the suspected attack source IP field in the alarm log is matched with the whitelist rule, and the trusted first traffic packets and the untrusted second traffic packets are filtered out from the traffic log. The first traffic packets do not need to be further analyzed for attacks, thereby reducing the burden of network attack research and judgment and improving the research and judgment efficiency.

[0105] Based on any of the above embodiments, the network security log includes traffic logs, and the traffic logs can be specifically divided into request packets and response packets. In addition, as Figure 3 shown, the attack analysis module 130 is specifically deployed with an attack behavior analysis agent (Agent3) 131 and an attack result analysis agent (Agent4) 132. Based on this, obtaining the attack analysis data of the attack-related fields by the attack analysis module 130 based on the attack feature library in step 230 above may specifically include steps 231-step 232.

[0106] Step 231: Input the attack feature library and the first attack-related field of the request packet into the attack behavior analysis agent, and obtain the attack behavior analysis data of the first attack-related field by the attack behavior analysis agent based on the attack feature library.

[0107] Exemplarily, the attack-related field extracted from the request packet is called the first attack-related field. The attack behavior analysis agent (Agent3) 131 is an agent specifically designed for analyzing network attack behaviors. It can receive the attack feature library generated by the attack feature extraction agent (Agent1) 110 and the first attack-related field extracted by the field extraction agent (Agent2) 120. The attack behavior analysis agent (Agent3) 131 calculates the similarity and performs pattern matching between the first attack-related field corresponding to each request packet and the attack features in the attack feature library to identify whether the first attack-related field contains known attack features. Through this comparison and analysis, the attack behavior analysis agent (Agent3) 131 can determine whether there is an attack behavior in each request packet.

[0108] Specifically, the attack behavior analysis agent (Agent3) 131 is deployed with a specifically fine-tuned large language model. The specific large language model is, for example, the deepseek-coder model. The specific large language model can be fine-tuned on a specific attack type dataset (such as an SQL injection attack dataset), so as to be able to more accurately identify the features related to specific attack types and determine whether there is a clear attack attempt in the request packet. If the request packet successfully matches the attack features in the attack feature library, the request packet can be marked as "attack attempt". If the request packet does not match the attack features, it is further analyzed in step 232 whether the corresponding response packet of the request packet is an attack success.

[0109] Step 232: Input the feature library and the second attack-related field of the response message into the attack result analysis agent to obtain the attack result analysis data of the second attack-related field by the attack result analysis agent based on the attack feature library, and obtain attack analysis data including the attack behavior analysis data and the attack result analysis data.

[0110] Exemplarily, the attack-related field extracted from the response message is called the second attack-related field. The attack result analysis agent (Agent4) 132 is an agent designed specifically for analyzing network attack behaviors. It can receive the attack feature library generated by the attack feature extraction agent (Agent1) 110 and the second attack-related field extracted by the field extraction agent (Agent2) 120. The attack result analysis agent (Agent4) 132 calculates the similarity and pattern matching between the second attack-related field corresponding to each response message and the attack features in the attack feature library to identify whether the second attack-related field contains known attack features. Through this comparison and analysis, the attack result analysis agent (Agent4) 132 can determine whether each response message is an attack success.

[0111] Specifically, the attack result analysis agent (Agent4) 132 can calculate the cosine similarity between the embedding vector of the second attack-related field extracted from the response message and the attack vector in the attack feature, and determine whether the response message is an attack success based on the cosine similarity. Specifically, if the response message presents the result features of operating system command execution (such as "uid=0(", "gid=0(", "groups=0(", "PID / Program name", "%CPU", "%MEM", "inetaddr:", etc.), the read features of specific files (such as "root:x:0:0:root: / root: / ", "bin:*:", etc.), and the connection features of WebShell tools (such as the regular features of the connection of the BingXie WebShell tool, the regular features of the connection of the Yijian WebShell tool, etc.), etc., then the response message can be marked as "attack success". On the contrary, if the response message presents error return codes, such as "400", "401", "403", and "404", etc., then the response message can be marked as "attack failure".

[0112] It can be seen that traditional attack detection systems usually rely only on a single data source (such as log data or traffic data) for attack detection, while the attack behavior analysis agent in this embodiment can receive and integrate multiple data sources, including structured alarm data and request messages. Through the comprehensive analysis of multi-dimensional data, the attack behavior analysis agent can improve the comprehensiveness of attack behavior recognition. In addition, traditional attack analysis tools mainly focus on the behavior analysis before and during the attack, and rarely conduct in-depth research on response message data. However, the attack result analysis agent in this embodiment can effectively judge whether the attack has been successfully executed by analyzing the protocol fields, general fields of the response message and their correlations with attack characteristics.

[0113] Based on any of the above embodiments, in step 240, the threat intelligence data, asset data, and attack analysis data are input into the comprehensive analysis report agent to obtain the output analysis report, which specifically includes step 241.

[0114] Step 241: Input the threat intelligence data, asset data, and the attack analysis data into the comprehensive analysis report agent, so that the comprehensive analysis report agent determines the attack technique and the corresponding attack result based on the attack analysis data, and matches the attack IP recorded in the attack-related fields with the threat intelligence data to obtain the correlation evaluation result between the attack IP and the known attack source, and determines the attacked asset from the asset data, and determines the attack severity based on the vulnerability data of the attacked asset and the correlation evaluation result to obtain the analysis report.

[0115] Exemplarily, the attack analysis data includes the attack behavior analysis data of the request message and the attack result analysis data of the response message. The comprehensive analysis report agent (Agent5) 140 combines the analysis results of the request message and the response message, and further integrates the threat intelligence data, the component information involved in the asset, and the possible vulnerabilities thereof for comprehensive analysis.

[0116] Specifically, the comprehensive analysis report agent (Agent5) 140 can determine the attack technique used in a certain attack and the corresponding attack result based on the attack behavior analysis data and the attack result analysis data.

[0117] In addition, the comprehensive analysis report agent (Agent5) 140 can match the attack IP recorded in the attack-related fields with the threat intelligence data to obtain the correlation assessment result between the attack IP and the known attack sources. For example, the threat intelligence of the attack IP can be obtained from the threat intelligence data and analyzed in detail to determine whether there are known malicious activities for the attack IP. By comparing the historical records and associated domain names of the attack IP, it is evaluated whether the attack IP is related to the known attack sources. If it is initially judged as a real attack, a threat warning is issued in a timely manner, and the corresponding label is attached to the attack. The labels may include, but are not limited to, "remote control", "malware", "phishing", "spam", "botnet", and "APT" (Advanced Persistent Threat).

[0118] In addition, the comprehensive analysis report agent (Agent5) 140 can also determine the attacked assets from the asset data. The attacked assets are the scope of influence of the attack. At the same time, the attack severity can be determined based on the vulnerability data of the attacked assets and the correlation assessment result. Specifically, the comprehensive analysis report agent (Agent5) 140 extracts the address, software name, and version information of the attacked assets from the attack characteristics. And it searches for the corresponding attacked assets in the asset management database to determine the scope of influence of the attack and evaluate whether the attacked assets have been exploited by the attack. Finally, based on these analysis results, a comprehensive assessment of the attack event is carried out, and a conclusion is drawn and the analysis process of the event is presented.

[0119] After obtaining the attack result, attack technique, scope of influence, and severity, the comprehensive analysis report agent (Agent5) 140 can generate the corresponding analysis report. Specifically, the comprehensive analysis report agent (Agent5) 140 can use prompt engineering techniques to construct prompt templates for various attack types. These prompt templates can guide the large language model to generate more targeted and readable analysis reports. For example, the report template for SQL injection attacks will include key information such as attack vectors, injection points, and database types. Table 3 below lists the judgment logics in different scenarios and explains each scenario.

[0120] Table 3

[0121]

[0122]

[0123] As an example, the analysis report generated by the comprehensive analysis report agent (Agent5) 140 for a certain attack can be output in the form of a table, as shown in Table 4 below.

[0124] Table 4

[0125]

[0126] In addition, the analysis report can be output in natural language to clearly present the analysis process and conclusions. For example, it can be expressed as: "The attacker successfully executed remote code and fully controlled the server by exploiting the CVE-XXXX-XXXX vulnerability."

[0127] In addition, the analysis report can also provide detailed judgment basis, such as "the error information in the response message indicates that the attacker has performed a SQL injection attack" or "according to threat intelligence, the relevant IP address has a known association with an APT organization." This form of report combines technical analysis and actual judgment, which is convenient for accurately conveying the cause and background of the security incident. Taking SQL injection attack as an example, the analysis report can be expressed as: "1. Analysis conclusion: There is a high-risk SQL injection attack attempt. Although no signs of successful attack have been found at present, the target system has a high-risk vulnerability, and the attack feature is a high-risk SQL injection, which still poses a high risk. 2. Judgment basis: The request message matches the high-risk SQL injection attack feature, and the target system has a corresponding vulnerability. Although no signs of successful attack were found in the response message, the possible reasons are: 1. The defense system intercepted the attack; 2. The attacker used evasion techniques; 3. The attack is in progress and has not yet produced any effect."

[0128] It can be seen that in this embodiment, the comprehensive analysis report agent has the ability of correlation analysis: when the response message does not show any signs of a successful attack, and the request message matches the high-risk attack characteristics, and the attacked assets have related vulnerabilities, the comprehensive analysis report agent can rely on its deep analysis ability to infer that the attack may have been successfully intercepted by the defense system, or that the attacker has adopted a more covert and difficult to detect attack method.

[0129] In addition, the comprehensive analysis report agent has the ability to perform causal analysis. It can deeply analyze the inherent causal relationship between relevant factors and accurately determine the real cause behind the success or failure of an attack. For example, it can clarify whether the success of an attack is attributed to a vulnerability in a specific asset component, or whether the failure of an attack is due to the successful functioning of the defense system. This provides a valuable basis for comprehensive control of the security situation and the formulation of subsequent response strategies.

[0130] In addition, the comprehensive analysis report agent has counterfactual reasoning capabilities, which can accurately infer whether the attack will be successful if the attacked assets do not have vulnerabilities. Similarly, when it is assumed that the defense system is not effective, it can also accurately determine whether the attack can be effectively intercepted. This counterfactual reasoning capability plays an extremely important auxiliary role in helping analysts gain a deep insight into the core essence of the attack event and comprehensively evaluate its impact, and can provide assistance in formulating more accurate and efficient security protection strategies and response plans.

[0131] Based on any of the above embodiments, as Figure 4 shown, the attack handling module 150 includes a handling suggestion generation agent (Agent6) 151 and a handling rule generation agent (Agent7) 152. Based on this, in step 250 above, the analysis report is input into the attack handling module 150 to obtain an attack handling plan, which specifically includes steps 251 - step 252.

[0132] Step 251: Input the analysis report into the handling suggestion generation agent to obtain the output attack response suggestions; wherein, the attack response suggestions include one or more of short-term handling suggestions, long-term handling suggestions, business recovery suggestions, and security reinforcement suggestions.

[0133] Exemplarily, the handling suggestion generation agent (Agent6) 151 is an agent specifically designed to generate network security incident handling suggestions. It receives the analysis report generated by the comprehensive analysis report agent (Agent5) 140 and automatically generates attack response suggestions for specific attacks to help network security personnel quickly formulate response strategies and reduce the harm caused by attacks.

[0134] Specifically, the above analysis report, asset information, its vulnerability data, security policies, and other relevant data can be input into the handling suggestion generation agent (Agent6) 151. The handling suggestion generation agent (Agent6) 151 uses a large language model to generate multi-dimensional attack response suggestions. The attack response suggestions include one or more of short-term handling suggestions, long-term handling suggestions, business recovery suggestions, and security reinforcement suggestions.

[0135] Among them, the short-term handling suggestions can include, but are not limited to: immediately isolating the infected host, blocking malicious IPs, rolling back malicious files, etc. The long-term handling suggestions can include, but are not limited to: fixing vulnerabilities, upgrading the system, strengthening security configurations, optimizing security policies, etc. The business recovery suggestions can include, but are not limited to: recovering damaged data, reconstructing business systems, etc. The security reinforcement suggestions can include, but are not limited to: strengthening access control, deploying security devices, conducting security audits, etc.

[0136] In addition, to ensure the security and effectiveness of the attack response suggestions, all generated attack response suggestions can be refined by combining predefined handling templates and other means, then reviewed by security experts, and the monitoring and analysis of the handling effects are added. For example, monitoring the status of affected assets, the logs of security devices, etc., to determine whether the handling is effective, etc., for the continuous optimization and improvement of the model.

[0137] The following is an example of the attack response suggestions generated by the Disposal Suggestion Generation Agent (Agent6) 151 for SQL injection attacks: "I. SQL injection disposal suggestions: 1. Input validation: Ensure that all inputs (especially user-provided inputs) are strictly validated and sanitized to avoid direct insertion into SQL queries. Use parameterized queries or prepared statements. 2. Principle of least privilege: When creating database users, grant them only the minimum necessary privileges and avoid granting UPDATE, INSERT, or DELETE privileges. 3. Error message hiding: Avoid exposing detailed error messages to users to reduce the risk of leaking system information. 4. Use a web application firewall: Deploy a WAF to detect and prevent SQL injection attacks. II. System construction suggestions: 1. Secure Development Lifecycle (SDL): Introduce security checks in the software development lifecycle to ensure that potential SQL injection risks are considered at each stage. 2. Log monitoring and auditing: Strengthen the logging of database operations and conduct regular audits to detect potential attack behaviors early. 3. Vulnerability repair and update: Regularly update the security patches of the system and database to avoid exploitation of known vulnerabilities."

[0138] Step 252: Input the analysis report into the Disposal Rule Generation Agent to obtain the output attack disposal rules; wherein, the attack disposal rules include one or more of blacklist rules, whitelist rules, signature matching rules, and behavior analysis rules respectively set for multiple different security devices.

[0139] Exemplarily, the Disposal Rule Generation Agent (Agent7) 152 is an agent specifically designed to create security device disposal rules. It receives the analysis report from the Comprehensive Analysis Report Agent (Agent5) 140 and automatically generates attack disposal rules applicable to different security devices to quickly respond to and prevent attacks, ensuring that various security devices can effectively respond to and prevent security threats.

[0140] Specifically, relevant data such as the above analysis report, attack response suggestions, security device types, existing rules, etc. can be input into the Disposal Rule Generation Agent (Agent7) 152, and the attack disposal rules for security devices can be automatically generated using a fine-tuned large language model. Subsequently, the generated attack disposal rules can be checked for grammar, and finally, the generated attack disposal rules are output in a format supported by the security device. To ensure the security and effectiveness of the suggestions, all generated attack disposal rules need to be reviewed by security experts or tested in a simulated environment.

[0141] The attack handling rules include one or more of blacklist rules, whitelist rules, signature matching rules, and behavior analysis rules separately set for multiple different security devices. Among them, the blacklist rules may include, but are not limited to: blocking malicious IP addresses, domain names, URLs, etc. The whitelist rules may include, but are not limited to: allowing specific IP addresses, domain names, URLs, etc. to access. The signature matching rules may include, but are not limited to, matching specific attack signatures, such as malicious code, malicious files, malicious requests, etc. The behavior analysis rules may include, but are not limited to, matching abnormal behaviors, such as multiple failed logins, a large number of port scans, frequent access to sensitive files, etc.

[0142] It can be seen that in this embodiment, the disposal recommendation generation agent is used to generate customized disposal recommendations, rather than relying on fixed templates or manual analysis. This solves the mismatch problem between general disposal recommendations and specific attack scenarios in traditional methods, making the recommendations more accurate and suitable for the actual scenario. In addition, the disposal rule generation agent is used to generate security device rules adapted to specific attack scenarios, solving the problem of invalid rules or high false alarm rates caused by scenario mismatches in traditional rule generation methods, and significantly shortening the rule deployment cycle by dynamically generating rules.

[0143] Based on any of the above embodiments, the present application further provides a network attack judgment system. As Figure 1 With Figure 5 shown, the network attack judgment system 100 includes:

[0144] An attack feature extraction agent 110, configured to extract attack features from the obtained attack samples and construct an attack feature library including the attack features;

[0145] A field extraction agent 120, configured to extract attack-related fields from the obtained network security logs;

[0146] An attack analysis module 130, configured to generate attack analysis data for the attack-related fields based on the attack feature library;

[0147] A comprehensive analysis report agent 140, configured to generate an analysis report based on threat intelligence data, asset data, and the attack analysis data, where the analysis report includes one or more of attack results, attack severity, impact scope, attack techniques;

[0148] An attack handling module 150, configured to generate an attack handling plan based on the analysis report.

[0149] In some embodiments, the attack feature extraction agent 110 includes a pre-trained large language model; specifically, the attack feature extraction agent 110 is configured to:

[0150] Input the obtained attack samples into the attack feature extraction agent, so that the attack feature extraction agent extracts attack metadata from the attack samples, and extracts the field values of the attack feature fields preset based on the protocol to which the attack samples belong, and uses the large language model to extract attack vectors from the attack metadata and the field values to obtain the attack features corresponding to each of the attack samples; wherein, the attack features include general fields for recording the attack metadata, protocol fields for recording the field values, and the attack vectors; the attack vectors carry the semantic information of the attack metadata and the field values;

[0151] Construct an attack feature library including each of the attack features.

[0152] In some embodiments, the network security logs include alarm logs and traffic logs; the attack-related fields include a suspected attack source IP field extracted from the alarm logs; the attack analysis module 130 is specifically configured to:

[0153] If the suspected attack source IP field in the alarm log matches the preset whitelist rule, determine that the first traffic packet corresponding to the alarm log in the traffic log is non-attack traffic;

[0154] If the suspected attack source IP field in the alarm log does not match the whitelist rule, determine the second traffic packet corresponding to the alarm log in the traffic log, and input the attack feature library and the attack-related fields of the second traffic packet into the attack analysis module.

[0155] In some embodiments, the network security logs include traffic logs, and the traffic logs include request packets and response packets; the attack analysis module 130 includes an attack behavior analysis agent 131 and an attack result analysis agent 132; the attack analysis module 130 is specifically configured to:

[0156] Input the attack feature library and the first attack-related fields of the request packet into the attack behavior analysis agent, and obtain the attack behavior analysis data of the first attack-related fields by the attack behavior analysis agent based on the attack feature library;

[0157] Input the feature library and the second attack-related fields of the response packet into the attack result analysis agent, and obtain the attack result analysis data of the second attack-related fields by the attack result analysis agent based on the attack feature library, so as to obtain attack analysis data including the attack behavior analysis data and the attack result analysis data.

[0158] In some embodiments, the comprehensive analysis report agent 140 is specifically configured to:

[0159] Input the threat intelligence data, asset data, and the attack analysis data into the comprehensive analysis report agent, so that the comprehensive analysis report agent determines the attack techniques and the corresponding attack results based on the attack analysis data, matches the attack IPs recorded in the attack-related fields with the threat intelligence data to obtain the correlation evaluation results between the attack IPs and known attack sources, determines the attacked assets from the asset data, and determines the attack severity based on the vulnerability data of the attacked assets and the correlation evaluation results to obtain the analysis report.

[0160] In some embodiments, the attack handling module 150 includes a handling suggestion generation agent 151 and a handling rule generation agent 152; specifically, the attack handling module 150 is configured to:

[0161] Input the analysis report into the handling suggestion generation agent to obtain the output attack response suggestions; wherein, the attack response suggestions include one or more of short-term handling suggestions, long-term handling suggestions, service recovery suggestions, and security reinforcement suggestions;

[0162] Input the analysis report into the handling rule generation agent to obtain the output attack handling rules; wherein, the attack handling rules include one or more of blacklist rules, whitelist rules, feature matching rules, and behavior analysis rules respectively set for multiple different security devices.

[0163] For the implementation processes of the functions and roles of each module in the above system, please refer to the implementation processes of the corresponding steps in the above method for details, which will not be elaborated here.

[0164] Based on the network attack research and judgment method described in any of the above embodiments, the present application further provides a computer program product, which includes one or more computer programs or instructions. The computer programs or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. When the computer program is executed by a processor, it implements the network attack research and judgment method described in any of the above embodiments.

[0165] Based on the network attack research and judgment method described in any of the above embodiments, the present application further provides a Figure 6 structural schematic diagram of an electronic device as shown in Figure 6, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, it may also include other hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the network attack judgment method described in any of the above embodiments. Among them, the electronic device may be deployed with the network attack judgment system described in any of the above embodiments.

[0166] The present application also provides a computer storage medium storing a computer program, which when executed by a processor can be used to execute a network attack judgment method described in any of the above embodiments.

[0167] In several embodiments provided by the present application, it should be understood that the disclosed device and method can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0168] In addition, in each embodiment of the present application, the various functional modules may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0169] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0170] The above are only the embodiments of this application and are not used to limit the protection scope of this application. For those skilled in the art, this application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0171] As mentioned above, this is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by this application and should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0172] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A network attack analysis method, characterized in that: The method is applied to a network attack analysis system; The network attack analysis and judgment system is deployed with multiple intelligent agents; the method includes: Input the acquired attack samples into the attack feature extraction agent, and build an attack feature library based on the extracted attack features; Input the acquired network security log into a field extraction agent to obtain the extracted attack-related fields; Inputting the attack feature library and the attack-related fields into an attack analysis module, and obtaining attack analysis data of the attack-related fields by the attack analysis module based on the attack feature library; Input the threat intelligence data, asset data and the attack analysis data into a comprehensive analysis report agent to obtain an output analysis report, wherein the analysis report includes one or more of attack results, attack severity, impact scope and attack technology; The analysis report is input into the attack handling module to obtain an output attack handling plan.

2. The method according to claim 1, characterized in that The attack feature extraction agent includes a pre-trained large language model; the acquired attack samples are input into the attack feature extraction agent, and an attack feature library is constructed based on the extracted attack features, including: Input the acquired attack sample into the attack feature extraction agent, so that the attack feature extraction agent extracts attack metadata from the attack sample, and extracts the field value of the attack feature field based on the attack feature field preset in the protocol to which the attack sample belongs, and uses the large language model to extract the attack vector from the attack metadata and the field value, so as to obtain the attack feature corresponding to each of the attack samples; wherein the attack feature includes a general field for recording the attack metadata, a protocol field for recording the field value, and the attack vector; the attack vector carries the semantic information of the attack metadata and the field value; An attack feature library including each of the attack features is constructed.

3. The method according to claim 1, characterized in that The network security log includes an alarm log and a traffic log; the attack-related field includes a suspected attack source IP field extracted from the alarm log; and the attack feature library and the attack-related field are input into the attack analysis module, including: If the suspected attack source IP field of the alarm log matches a preset whitelist rule, determining from the traffic log that the first traffic message corresponding to the alarm log is non-attack traffic; If the suspected attack source IP field of the alarm log does not match the whitelist rule, determine the second traffic message corresponding to the alarm log from the traffic log, and input the attack feature library and the attack-related fields of the second traffic message into the attack analysis module.

4. The method according to any one of claims 1 to 3, characterized in that: The network security log includes a traffic log, and the traffic log includes a request message and a response message; the attack analysis module includes an attack behavior analysis agent and an attack result analysis agent; The acquiring of attack analysis data of the attack-related fields by the attack analysis module based on the attack feature library comprises: Inputting the attack feature library and the first attack-related field of the request message into the attack behavior analysis agent, and obtaining attack behavior analysis data of the first attack-related field by the attack behavior analysis agent based on the attack feature library; The feature library and the second attack-related field of the response message are input into the attack result analysis agent, and attack result analysis data of the second attack-related field by the attack result analysis agent based on the attack feature library is obtained to obtain attack analysis data including the attack behavior analysis data and the attack result analysis data.

5. The method according to claim 1, characterized in that The threat intelligence data, asset data and attack analysis data are input into the comprehensive analysis report intelligent body to obtain an output analysis report, including: The threat intelligence data, asset data and the attack analysis data are input into the comprehensive analysis report intelligent body, so that the comprehensive analysis report intelligent body determines the attack technology and the corresponding attack result based on the attack analysis data, and matches the attack IP recorded in the attack-related field with the threat intelligence data to obtain the correlation evaluation result between the attack IP and the known attack source, and determines the attacked asset from the asset data, determines the severity of the attack based on the vulnerability data of the attacked asset and the correlation evaluation result, and obtains the analysis report.

6. The method according to claim 1, characterized in that The attack handling module includes a handling suggestion generating agent and a handling rule generating agent; the analysis report is input into the attack handling module to obtain an output attack handling plan, including: Input the analysis report into the disposal suggestion generating agent to obtain an output attack response suggestion; wherein the attack response suggestion includes one or more of a short-term disposal suggestion, a long-term disposal suggestion, a business recovery suggestion, and a security reinforcement suggestion; The analysis report is input into the disposal rule generation agent to obtain output attack disposal rules; wherein the attack disposal rules include one or more of blacklist rules, whitelist rules, feature matching rules and behavior analysis rules set for multiple different security devices.

7. A network attack analysis system, characterized in that: The system comprises: An attack feature extraction agent, used to extract attack features from the acquired attack samples and construct an attack feature library including the attack features; A field extraction agent is used to extract attack-related fields from the acquired network security logs; An attack analysis module, used to generate attack analysis data for the attack-related fields based on the attack feature library; A comprehensive analysis report agent, used to generate an analysis report based on threat intelligence data, asset data and the attack analysis data, wherein the analysis report includes one or more of attack results, attack severity, impact scope and attack technology; An attack handling module is used to generate an attack handling plan based on the analysis report.

8. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

9. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing processor-executable instructions; Wherein, when the processor calls the executable instruction, it implements the operation of any method described in claims 1-6.

10. A computer-readable storage medium, characterized in that: Computer instructions are stored thereon, and when the computer instructions are executed by a processor, the steps of any method described in claims 1-6 are implemented.

Citation Information

Patent Citations

  • Network safety event hazard index evaluation method and system based on multi-dimensional association

    CN110620759A

  • Industrial control information safety monitoring system adopting black and white lists for analysis

    CN110868425A

  • Network attack detection system and method based on intelligent threat intelligence

    CN110912889A

  • Network intrusion detection method and system and related equipment

    CN111510434A

  • Malicious event alarm and protection method and system based on service access

    CN114021040A

Cited By

  • Security alarm information processing method and device based on multi-agent cooperation

    CN120378229A

  • A method and apparatus for processing security alarm information based on multi-agent collaboration

    CN120378229B

  • Network information security protection method, device and system

    CN120825337A

  • Multi-agent driven safety alarm log simulation generation method

    CN121098738A

  • Key infrastructure attack detection and analysis method based on agent de-obfuscation

    CN122437734A