Method and system for generating rule of APT attack clue detection

By obtaining security data and threat intelligence within the system, static and dynamic rule models are built based on the adversarial knowledge base, detection rules are generated and optimized, and the problems of low detection accuracy, weak real-time and poor adaptability in the existing technology are solved, and accurate and comprehensive detection of APT attack behavior is achieved.

CN120074959AActive Publication Date: 2025-05-30GUANGZHOU UNIVERSITY
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510541474.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-05-30
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

When detecting APT attack clues, the detection accuracy is low, the real-time is weak, and the adaptability is poor, making it difficult to effectively prevent and deal with APT attacks.

Method used

By obtaining security data and threat intelligence within the system, tactical associations are made based on the adversarial knowledge base, static and dynamic rule models are built, static and dynamic detection rules are generated, and dynamic detection rules are optimized through feedback learning and intelligence update mechanisms.

Benefits of technology

It realizes accurate and comprehensive detection of APT attack behavior, improves the adaptability and real-timeness of detection rules, and can respond and prevent APT attacks in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074959A_ABST
    Figure CN120074959A_ABST
Patent Text Reader

Abstract

The invention provides a rule generation method and generation system for APT attack clue detection, and relates to the field of network information security. The method provided by the invention comprises the following steps: acquiring security data and threat intelligence in a system, and performing tactical association on the threat intelligence based on an adversarial knowledge base to obtain tactical labels; constructing a static rule model based on known APT attack chain data, fusing threat intelligence and time sequence data, and constructing a dynamic rule model based on an antagonism knowledge base; extracting threat nodes in the security data, generating a static detection rule according to the static rule model, obtaining the priority of threat intelligence, and generating a dynamic detection rule according to the dynamic rule model; and optimizing the dynamic detection rule based on feedback learning and an intelligence updating mechanism. According to the APT attack behavior detection method, an adversarial knowledge base, threat intelligence and a feedback learning technology are fused, accurate and comprehensive detection of APT attack behaviors is achieved, and the adaptability and the real-time performance of detection rules are improved through an automatic optimization mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network information security, and in particular, to a method and system for generating rules for detecting APT attack clues. Background Art

[0002] With the rapid development of information technology and the increasing complexity of the network environment, APT (Advanced Persistent Threat) attacks have become a major threat in the current network security field. APT attacks usually involve attackers lurking in the target system for a long time through precise target selection and customization means, and carrying out malicious activities such as stealing and destroying. Due to its concealment and complexity, traditional security defense means are difficult to effectively prevent and respond to APT attacks.

[0003] The research on APT attack clue detection has gradually developed from single-stage detection to multi-stage detection methods. Rule-based detection technology can design a large number of rules to identify abnormal behaviors in network traffic. However, this detection technology is difficult to accurately identify unknown attacks. Detection technology combined with machine learning mainly relies on feature engineering, extracts features from data such as network traffic and system logs, and combines traditional classification algorithms to identify attack behaviors. However, this detection technology is prone to missing complex attack paths and variable attack features, resulting in low accuracy. Detection technology combined with deep learning can automatically extract effective features from a large amount of data, improving the accuracy of detection. However, this detection technology requires a large amount of computing resources and is difficult to adapt to the real-time detection environment. The detection technology of reconstructing the attack chain can identify each stage of the attack and reveal the whole process of the attacker from the initial penetration to the achievement of the final goal. However, this detection technology needs to conduct in-depth analysis of the attack behaviors at each stage during the reconstruction of the attack chain and conduct retrospective analysis on the long-term collected data, so it cannot respond to attacks in a timely manner. Therefore, there is an urgent need to provide a solution to improve the above problems. Summary of the Invention

[0004] The purpose of the present invention is to provide a method and system for generating rules for detecting APT attack clues, which can improve the problems of low detection accuracy, weak real-time performance, and poor adaptability in the existing APT attack clue detection.

[0005] In a first aspect, a method for generating rules for detecting APT attack clues provided by the present invention includes: Obtaining security data and threat intelligence inside the system, and performing tactical association on the threat intelligence based on an adversarial knowledge base to obtain tactical tags; Constructing a static rule model based on known APT attack chain data, fusing the threat intelligence and time-series data, and constructing a dynamic rule model based on the adversarial knowledge base; Extract threat nodes from the security data and generate static detection rules according to the static rule model, obtain the priority of the threat intelligence and generate dynamic detection rules according to the dynamic rule model; Optimize the dynamic detection rules based on the feedback learning and intelligence update mechanism.

[0006] A method for generating rules for detecting APT attack clues provided by the present invention realizes accurate and comprehensive detection of APT attack behaviors by integrating adversarial knowledge bases, threat intelligence, and feedback learning technologies, and improves the adaptability and real-time performance of detection rules through an automatic optimization mechanism.

[0007] Optionally, when optimizing the dynamic detection rules based on the feedback learning and intelligence update mechanism, it includes: the system detects the execution feedback of the dynamic detection rules, and optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback; optimizing the matching parameters of the dynamic detection rules based on the threat intelligence and the technical activity of the dynamic detection rules, where the technical activity includes the popularity and activity of attack techniques; When the system optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback, define the state of the dynamic detection rules according to the threat intelligence, the attack chain process, and the execution feedback, where the state includes the matching situation of the dynamic detection rules and the technical activity of the threat intelligence; According to the state, select the corresponding action to optimize the parameters of the dynamic detection rules, and the actions include increasing the matching time of intrusion indicators and adjusting the sensitivity of attack techniques; According to each execution feedback, when the execution feedback is a low false negative rate and a low false positive rate, a positive reward is given, and when the execution feedback is a high false negative rate or a high false positive rate, a negative reward is given; Update the strategy of the dynamic detection rules through the Q-learning algorithm in the reinforcement learning according to the positive reward and the negative reward, and the update formula is: , where, is the expected return of taking action in state , is the learning rate, is the discount factor, is the immediate reward obtained after executing action , is the expected return of the best action that may be taken in the next state .

[0008] Optionally, when obtaining the priority of the threat intelligence and generating dynamic detection rules according to the dynamic rule model, the priority of the threat intelligence includes the credibility, activity, and context relevance of intrusion indicators, and the threat intelligence nodes include intrusion indicators and attack phases; The formula used is as follows: , where, is the dynamic detection rule finally generated by the dynamic rule model, is the priority weight of the th node in the threat intelligence, is the score of the technology or tactic corresponding to the th node in the threat intelligence, is the total number of nodes in the threat intelligence.

[0009] Optionally, the security data includes system logs, network traffic, IDS / IPS alerts, EDR data, firewall logs, web server logs, and mail server logs.

[0010] Optionally, the threat intelligence includes system security events, behavior patterns, and technical features.

[0011] Optionally, the adversarial knowledge base includes the MITRE ATT&CK framework.

[0012] Optionally, the time-series data includes network traffic metadata, terminal process trees, and identity audit records.

[0013] Optionally, the threat nodes include tactics or technologies.

[0014] In a second aspect, the present invention also provides a rule generation system for APT attack clue detection, including: A data acquisition module, configured to acquire security data and threat intelligence inside the system, and perform tactical association on the threat intelligence based on the adversarial knowledge base to obtain tactical tags; A model construction module, configured to construct a static rule model based on known APT attack chain data, fuse the threat intelligence and time-series data, and construct a dynamic rule model based on the adversarial knowledge base; A rule generation module, configured to extract threat nodes of the security data and generate static detection rules according to the static rule model, obtain the priority of the threat intelligence, and generate dynamic detection rules according to the dynamic rule model; A rule optimization module, configured to optimize the dynamic detection rules based on a feedback learning and intelligence update mechanism. Description of the Drawings

[0015] Figure 1A flowchart showing a method for generating rules for APT attack clue detection provided by an embodiment of the present invention.

[0016] Figure 2 A system diagram for generating rules for APT attack clue detection provided by an embodiment of the present invention.

[0017] Explanation of reference numerals: 100, data acquisition module; 200, model construction module; 300, rule generation module; 400, rule optimization module. Detailed implementation manners

[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art in the field to which the present invention belongs.

[0019] Refer to Figure 1 , the present invention provides a method for generating rules for APT attack clue detection, including the following steps: S1. Obtain the security data and threat intelligence inside the system, and perform tactical association on the threat intelligence based on the adversarial knowledge base to obtain tactical tags; S2. Construct a static rule model based on the known APT attack chain data, fuse the threat intelligence and time-series data, and construct a dynamic rule model based on the adversarial knowledge base; S3. Extract the threat nodes in the security data and generate static detection rules according to the static rule model, obtain the priorities of the threat intelligence, and generate dynamic detection rules according to the dynamic rule model; S4. Optimize the dynamic detection rules based on the feedback learning and intelligence update mechanism.

[0020] In fact, for the rule generation method provided by the present invention, by fusing the adversarial knowledge base and threat intelligence, dynamic detection rules can be generated and the rules can be updated in real time according to actual attack activities and intelligence data, achieving the purpose of accurately and comprehensively detecting APT attack behaviors. Additionally, by introducing an automatic optimization mechanism based on feedback learning, the parameters and matching conditions of the rules can be dynamically adjusted, achieving the purpose of high adaptability and high real-time performance of the detection rules.

[0021] In some embodiments, in step S1, the security data inside the system may be system logs, network traffic, IDS / IPS alerts, EDR data, firewall logs, web server logs, and mail server logs. These data can reflect security events in the system and network and provide detailed behavior records and signs of potential attacks. Threat intelligence may be system security events, behavior patterns, and technical features. These data are used to help identify, predict, and respond to potential or ongoing network threats. The adversarial knowledge base may be the MITRE ATT&CK framework, which provides a standardized attack technique and tactic model covering all stages of APT attacks and the means to counter them, providing a systematic basis for subsequent rule modeling. The above-obtained security data inside the system, threat intelligence, and adversarial knowledge base are used as input data for subsequent APT attack clue detection. In addition, after obtaining the security data inside the system, threat intelligence, and adversarial knowledge base, preprocessing can be performed on the security data, threat intelligence, and adversarial knowledge base, such as data cleaning, data tagging, and other commonly used preprocessing methods in the art.

[0022] In some embodiments, in step S1, the tactical tag is to preliminarily associate the TTPs in the threat intelligence with the TTPs in the MITRE ATT&CK framework, preprocess the input data, and help with the rule generation work in the subsequent stage.

[0023] In some embodiments, in step S2, the static rule model is constructed based on known APT attack chain templates, providing an effective attack chain matching method for the system. For example, in the attack chain template for APT28 (also known as Fancy Bear), it includes the following stages: Initial Access, Execution, Persistence, Privilege Escalation, Internal Reconnaissance. In addition, some APT organizations will establish some typical attack chain templates based on the attack patterns of specific targets with strong regularity and predictability based on TTPs.

[0024] In some embodiments, in step S2, the dynamic rule model is based on the 14 tactics defined in the MITRE ATT&CK framework and integrates threat intelligence and time-series data to identify the multi-stage behavior patterns in the APT attack process. The 14 tactics defined in the MITRE ATT&CK framework represent the goals or intentions of attackers at different stages, covering the complete attack chain from reconnaissance to impact, such as reconnaissance, initial access, privilege escalation, lateral movement, and data exfiltration, etc.; in addition, the techniques under the tactics describe the specific methods to achieve these goals and are further refined into sub-techniques to improve the accuracy and practicality of the description. For example, the phishing attack (T1566) in the initial access stage can be refined into "malicious attachment" (T1566.001) and "malicious link" (T1566.002).

[0025] In some embodiments, in step S2, the time-series data can be network traffic metadata, terminal process trees, and identity audit records. By deeply analyzing these time-series data, the dynamic rule model can use methods such as dynamic time window statistics and behavior chain modeling to capture the evolution trajectory of attacker activities in the time dimension, thereby more accurately revealing the internal connections and changing trends of the multi-stage attack patterns, and ultimately realizing the effective characterization and restoration of the complete attack chain.

[0026] In some embodiments, in step S3, the threat nodes can be tactics or techniques, which reflect the important behavior patterns of attackers during the attack and provide data support for generating static detection rules. After extracting the threat nodes and combining them with the static rule model to generate static detection rules, the static detection rules can adapt to most common attack scenarios and provide support for basic detection. For example, if we want to detect the attack technique of "Phishing", the static detection rules will be created based on the known characteristics of phishing emails (such as email subject, attachment type, URL address, etc.). The following is part of the code for phishing email detection: “if (email.hasAttachment() and (attachment.type == ".exe" or attachment.type == ".vbs")) or (email.hasURL() and isMaliciousDomain(email.URL)): triggerDetection("Suspicious email detected with malicious attachmentor URL")”.

[0027] In some embodiments, in step S3, the priority of threat intelligence may be the credibility, activity, and context relevance of intrusion indicators. The system dynamically adjusts the weights generated by the dynamic detection rules according to the priority of the obtained threat intelligence, and preferentially processes intelligence with high credibility and strong activity. The dynamic detection rules are generated based on the priority of the obtained threat intelligence and according to the dynamic rule model.

[0028] The formula used is as follows: , where, is the dynamic detection rule finally generated by the dynamic rule model, is the priority weight of the th node in the threat intelligence, is the score of the technology or tactic corresponding to the th node in the threat intelligence, is the total number of nodes in the threat intelligence.

[0029] In some embodiments, in step S3, when the dynamic detection rules are dealing with an attacker using unique attack techniques for an attack, they are generated and adjusted according to these new threat characteristics. For example, assume that a certain APT organization (such as APT28) uses a new attack method, taking a malicious PowerShell script as a payload and injecting malicious code using a memory vulnerability. Based on this dynamic intelligence, the generated dynamic detection rules will include the following content to detect suspicious PowerShell script commands execution: “if (script.isPowerShell() and script.hasCommand("Invoke-Expression") and not isExpectedProcess(script.targetProcess)): triggerDetection("Suspicious PowerShell execution detected")”.

[0030] In addition, the dynamic detection rules can also automatically generate targeted rules for ongoing attacks through real-time intrusion indicator data sources. For example, in a certain APT attack, the attacker uses a specific domain name for data exfiltration. At this time, the dynamic detection rules will detect whether there is traffic accessing these domain names based on this domain name.

[0031] In some embodiments, when optimizing the dynamic detection rules in step S4, first based on feedback learning, by continuously collecting the detection results triggered by the dynamic detection rules and analyzing their false alarm rate and missed alarm rate, the accuracy of the dynamic detection rules is further optimized. For example, when the dynamic detection rules generate false alarms, the system will adjust the parameters of the dynamic detection rules by analyzing the specific scenarios of the false alarms (such as the attack patterns or environmental characteristics that are falsely triggered), reducing unnecessary alarms. At the same time, the cases of missed alarms will also be marked and analyzed by the system, and the dynamic detection rules will be further adjusted to improve the coverage rate. The system adopts a reinforcement learning algorithm to achieve the purpose of automatically adjusting the parameters and behaviors of the dynamic detection rules. Reinforcement learning is a technique that optimizes the decision-making process through a reward and punishment mechanism, and is particularly suitable for dynamic and ever-changing environments. During the optimization process of the dynamic detection rules, the system will optimize the parameters in the dynamic detection rules by simulating attack scenarios and performing feedback and based on reinforcement learning to ensure high accuracy in different threat environments.

[0032] Specifically, the system uses the following steps to optimize the rules using the reinforcement learning algorithm: First, define the state of the dynamic detection rules according to the current threat intelligence, the progress of the attack chain, and the execution feedback of the rules, where the state can be the matching situation of the dynamic detection rules and the technical activity of the current threat intelligence; Secondly, according to the state, select the corresponding action to optimize the parameters of the dynamic detection rules, where the action can be to increase the matching time of intrusion metrics, adjust the sensitivity of attack techniques; Then, according to the execution feedback each time, when the execution feedback is a low missed alarm rate and a low false alarm rate, a positive reward is given, and when the execution feedback is a high missed alarm rate or a high false alarm rate, a negative reward is given. For example, assuming that the false alarm rate of a certain rule is 0.1 and the missed alarm rate is 0.05, the system can define the following reward function : , Finally, update the policy of the dynamic detection rules through the Q-learning algorithm in reinforcement learning according to the positive reward and negative reward. The update formula is: , where, is the expected return of taking action in state , is the learning rate, is the discount factor, is the immediate reward obtained after executing action , is the expected return of the best action that may be taken in the next state .

[0033] In some embodiments, in step S4, the intelligence update mechanism further enhances the adaptability of the dynamic detection rule by dynamically adjusting the matching parameters of the dynamic detection rule. For example, the system automatically updates the expiration time of the intrusion metrics based on the latest threat intelligence to ensure that the detection can reflect the current threat situation in real time. At the same time, the technical activity in the dynamic detection rule is continuously tracked and adjusted to ensure that the dynamic detection rule preferentially matches the current active attack patterns and avoids ineffective matching of outdated or inactive threats.

[0034] See Figure 2 , the present invention provides a rule generation system for APT attack clue detection, including the following steps: A data acquisition module 100, configured to acquire the internal security data and threat intelligence of the system, and obtain tactical tags through tactical association of the threat intelligence based on the adversarial knowledge base; A model construction module 200, which constructs a static rule model based on the known APT attack chain data, fuses threat intelligence and time-series data, and constructs a dynamic rule model based on the adversarial knowledge base; A rule generation module 300, which extracts the threat nodes of the security data and generates static detection rules according to the static rule model, obtains the priority of the threat intelligence, and generates dynamic detection rules according to the dynamic rule model; A rule optimization module 400, which optimizes the dynamic detection rules based on the feedback learning and the intelligence update mechanism.

[0035] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention described in the claims. Moreover, the present invention described herein can have other embodiments and can be implemented or realized in various ways.

Claims

1. A rule generation method for APT attack clue detection, characterized in that: include: Obtain security data and threat intelligence within the system, and perform tactical association on the threat intelligence based on the adversarial knowledge base to obtain tactical labels; Building a static rule model based on known APT attack chain data, integrating the threat intelligence with time series data and building a dynamic rule model based on an adversarial knowledge base; Extracting threat nodes from the security data and generating static detection rules according to a static rule model, obtaining the priority of the threat intelligence and generating dynamic detection rules according to the dynamic rule model; The dynamic detection rules are optimized based on feedback learning and intelligence updating mechanisms.

2. The rule generation method according to claim 1, characterized in that: When the dynamic detection rule is optimized based on the feedback learning and intelligence update mechanism, it includes: the system detects the execution feedback of the dynamic detection rule, and optimizes the parameters and behavior of the dynamic detection rule based on reinforcement learning and the execution feedback; optimizes the matching parameters of the dynamic detection rule based on the threat intelligence and the technical activity of the dynamic detection rule, and the technical activity includes the popularity and activity of the attack technology; When the system optimizes the parameters and behaviors of the dynamic detection rule based on reinforcement learning and the execution feedback, the system defines the state of the dynamic detection rule according to the threat intelligence, the attack chain process, and the execution feedback, wherein the state includes the matching status of the dynamic detection rule and the technical activity of the threat intelligence; According to the state, selecting a corresponding action to optimize the parameters of the dynamic detection rule, the action including increasing the matching time of the intrusion indicator and adjusting the sensitivity of the attack technology; According to the execution feedback each time, when the execution feedback is a low false negative rate and a low false positive rate, a positive reward is given, and when the execution feedback is a high false negative rate or a high false positive rate, a negative reward is given; The strategy of the dynamic detection rule is updated according to the positive reward and the negative reward through the Q-learning algorithm in the reinforcement learning, and the updating formula is: , in, is in state Take action Expected return, is the learning rate, is the discount factor, Is to perform an action After receiving the instant reward, The next state The expected reward of the best possible action.

3. The rule generation method according to claim 1, characterized in that: When obtaining the priority of the threat intelligence and generating a dynamic detection rule according to the dynamic rule model, the priority of the threat intelligence includes the credibility, activity and context relevance of the intrusion indicator, and the threat intelligence node includes the intrusion indicator and the attack stage; The formula used is as follows: , in, The dynamic detection rules finally generated by the dynamic rule model, The threat intelligence The priority weight of each node, The threat intelligence The technical or tactical score corresponding to each node, is the total number of nodes in the threat intelligence.

4. The rule generation method according to claim 1, characterized in that: The security data includes system log network traffic, IDS / IPS alerts, EDR data, firewall logs, web server logs, and mail server logs.

5. The rule generation method according to claim 1, characterized in that: The threat intelligence includes system security events, behavior patterns, and technical features.

6. The rule generation method according to claim 1, characterized in that: The adversarial knowledge base includes the MITRE ATT&CK framework.

7. The rule generation method according to claim 1, characterized in that: The time series data includes network traffic metadata, terminal process tree, and identity audit records.

8. The rule generation method according to claim 1, characterized in that: The threat nodes include tactics or techniques.

9. A rule generation system for APT attack clue detection, characterized in that: include: A data acquisition module is used to acquire security data and threat intelligence within the system, and to obtain tactical labels by tactically associating the threat intelligence based on the adversarial knowledge base; A model building module, which builds a static rule model based on known APT attack chain data, integrates the threat intelligence with time series data, and builds a dynamic rule model based on an adversarial knowledge base; A rule generation module extracts the threat nodes of the security data and generates static detection rules according to the static rule model, obtains the priority of the threat intelligence and generates dynamic detection rules according to the dynamic rule model; The rule optimization module optimizes the dynamic detection rules based on feedback learning and intelligence update mechanism.

Citation Information

Patent Citations

  • Threat response method and device based on threat intelligence and ATT&CK

    CN112769821A

  • Network security detection method and system

    CN118101250A

  • Automatic attack script library updating method, system and equipment based on machine learning

    CN118199952A

  • Industrial control system threat trapping method based on machine learning algorithm

    CN119135401A