A rule generation method and generation system for APT attack clue detection

By obtaining system data and threat intelligence, using adversarial knowledge base to build static and dynamic rule models, and combining feedback learning to optimize detection rules, the problem of insufficient accuracy, real-time and adaptability of APT attack detection in the existing technology is solved, and efficient APT attack detection is achieved.

CN120074959BActive Publication Date: 2025-07-04GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510541474.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-04
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

The prior art is difficult to effectively and in real time to detect and respond to APT attacks, especially in terms of detection accuracy, real-timeness and adaptability.

Method used

By obtaining security data and threat intelligence within the system, using an adversarial knowledge base for tactical association, building static and dynamic rule models, optimizing detection rules with feedback learning and intelligence update mechanisms, and generating dynamic detection rules to improve detection accuracy and adaptability.

Benefits of technology

It realizes accurate and comprehensive detection of APT attack behavior, improves the adaptability and real-timeness of detection rules, and can dynamically adjust rules to deal with changing attack patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074959B_ABST
    Figure CN120074959B_ABST
Patent Text Reader

Abstract

The present invention provides a method and a generation system for generating rules for detecting APT attack clues, which relate to the field of network information security. The method provided by the present invention includes: obtaining security data and threat intelligence inside the system, and performing tactical association on the threat intelligence based on an adversarial knowledge base to obtain tactical tags; constructing a static rule model based on known APT attack chain data, fusing threat intelligence and time-series data and constructing a dynamic rule model based on the adversarial knowledge base; extracting threat nodes in the security data and generating static detection rules according to the static rule model, obtaining the priority of the threat intelligence and generating dynamic detection rules according to the dynamic rule model; optimizing the dynamic detection rules based on a feedback learning and intelligence update mechanism. The present invention fuses an adversarial knowledge base, threat intelligence and feedback learning technologies to achieve accurate and comprehensive detection of APT attack behaviors, and improves the adaptability and real-time performance of detection rules through an automatic optimization mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network information security, and in particular, to a method and system for generating rules for detecting APT attack clues. Background Art

[0002] With the rapid development of information technology and the increasing complexity of the network environment, APT (Advanced Persistent Threat) attacks have become a major threat in the current network security field. APT attacks usually involve attackers lurking in the target system for a long time through precise target selection and customization means, and carrying out malicious activities such as stealing and destroying. Due to its concealment and complexity, traditional security defense means are difficult to effectively prevent and respond to APT attacks.

[0003] The research on APT attack clue detection has gradually developed from single-stage detection to multi-stage detection methods. Rule-based detection technology can design a large number of rules to identify abnormal behaviors in network traffic. However, this detection technology is difficult to accurately identify in the face of unknown attacks. Detection technology combined with machine learning mainly relies on feature engineering, extracts features from data such as network traffic and system logs, and combines traditional classification algorithms to identify attack behaviors. However, this detection technology is prone to missing complex attack paths and variable attack features, resulting in low accuracy. Detection technology combined with deep learning can automatically extract effective features from a large amount of data, improving the accuracy of detection. However, this detection technology requires a large amount of computing resources and is difficult to adapt to the real-time detection environment. The detection technology of reconstructing the attack chain can identify each stage of the attack and reveal the whole process from the initial penetration of the attacker to the achievement of the final goal. However, this detection technology needs to deeply analyze the attack behaviors at each stage and perform retrospective analysis on the long-term collected data during the reconstruction process of the attack chain, so it cannot respond to attacks in a timely manner. Therefore, there is an urgent need to provide a solution to improve the above problems. Summary of the Invention

[0004] The purpose of the present invention is to provide a method and system for generating rules for detecting APT attack clues, which can improve the problems of low detection accuracy, weak real-time performance, and poor adaptability in the existing APT attack clue detection.

[0005] In a first aspect, a method for generating rules for detecting APT attack clues provided by the present invention includes:

[0006] Obtain the security data and threat intelligence inside the system, and perform tactical association on the threat intelligence based on the adversarial knowledge base to obtain tactical tags;

[0007] Construct a static rule model based on known APT attack chain data, fuse the threat intelligence and time-series data, and construct a dynamic rule model based on an adversarial knowledge base;

[0008] Extract threat nodes from the security data and generate static detection rules according to the static rule model, obtain the priority of the threat intelligence, and generate dynamic detection rules according to the dynamic rule model;

[0009] Optimize the dynamic detection rules based on a feedback learning and intelligence update mechanism.

[0010] A method for generating rules for APT attack clue detection provided by the present invention realizes accurate and comprehensive detection of APT attack behaviors by fusing an adversarial knowledge base, threat intelligence, and feedback learning technology, and improves the adaptability and real-time performance of detection rules through an automatic optimization mechanism.

[0011] Optionally, when optimizing the dynamic detection rules based on a feedback learning and intelligence update mechanism, it includes: the system detects the execution feedback of the dynamic detection rules, and optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback; optimizing the matching parameters of the dynamic detection rules based on the threat intelligence and the technical activity of the dynamic detection rules, where the technical activity includes the popularity and activity of attack techniques;

[0012] When the system optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback, define the state of the dynamic detection rules according to the threat intelligence, the attack chain process, and the execution feedback, where the state includes the matching situation of the dynamic detection rules and the technical activity of the threat intelligence;

[0013] According to the state, select the corresponding action to optimize the parameters of the dynamic detection rules, where the actions include increasing the matching time of intrusion indicators and adjusting the sensitivity of attack techniques;

[0014] According to each execution feedback, when the execution feedback is a low false negative rate and a low false positive rate, a positive reward is given, and when the execution feedback is a high false negative rate or a high false positive rate, a negative reward is given;

[0015] Update the strategy of the dynamic detection rules through the Q-learning algorithm in the reinforcement learning according to the positive reward and the negative reward, and the update formula is:

[0016] ,

[0017] where, is the expected return of taking action in state , is the learning rate, is the discount factor, is the immediate reward obtained after executing the action is the next state and is the expected return of the best action that may be taken in

[0018] Optionally, when obtaining the priority of the threat intelligence and generating a dynamic detection rule according to the dynamic rule model, the priority of the threat intelligence includes the credibility, activity, and context relevance of intrusion metrics, and the threat intelligence node includes intrusion metrics and attack phases;

[0019] The formula used is as follows:

[0020] ,

[0021] wherein, is the dynamic detection rule finally generated by the dynamic rule model, is the priority weight of the th node in the threat intelligence, is the score of the technology or tactic corresponding to the th node in the threat intelligence, is the total number of nodes in the threat intelligence.

[0022] Optionally, the security data includes system logs, network traffic, IDS / IPS alerts, EDR data, firewall logs, web server logs, and mail server logs.

[0023] Optionally, the threat intelligence includes system security events, behavior patterns, and technical features.

[0024] Optionally, the adversarial knowledge base includes the MITRE ATT&CK framework.

[0025] Optionally, the time series data includes network traffic metadata, terminal process trees, and identity audit records.

[0026] Optionally, the threat node includes tactics or technologies.

[0027] In a second aspect, the present invention further provides a rule generation system for APT attack clue detection, including:

[0028] A data acquisition module, configured to acquire security data and threat intelligence inside the system, and perform tactical association on the threat intelligence based on the adversarial knowledge base to obtain tactical tags;

[0029] A model construction module constructs a static rule model based on known APT attack chain data, fuses the threat intelligence and time series data, and constructs a dynamic rule model based on an adversarial knowledge base;

[0030] A rule generation module extracts threat nodes from the security data and generates static detection rules according to the static rule model, obtains the priorities of the threat intelligence, and generates dynamic detection rules according to the dynamic rule model;

[0031] A rule optimization module optimizes the dynamic detection rules based on a feedback learning and intelligence update mechanism. Description of the Drawings

[0032] Figure 1 It is a schematic flow chart of a method for generating rules for APT attack clue detection provided by an embodiment of the present invention.

[0033] Figure 2 It is a system diagram of a method for generating rules for APT attack clue detection provided by an embodiment of the present invention.

[0034] Description of the Reference Numerals:

[0035] 100, data acquisition module; 200, model construction module; 300, rule generation module; 400, rule optimization module. Detailed Embodiments

[0036] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art to which the present invention pertains.

[0037] Refer to Figure 1 , the present invention provides a method for generating rules for APT attack clue detection, including the following steps:

[0038] S1. Obtain the security data and threat intelligence inside the system, and perform tactical association on the threat intelligence based on an adversarial knowledge base to obtain tactical tags;

[0039] S2. Construct a static rule model based on known APT attack chain data, fuse the threat intelligence and time series data, and construct a dynamic rule model based on an adversarial knowledge base;

[0040] S3. Extract threat nodes from the security data and generate static detection rules according to the static rule model, obtain the priorities of threat intelligence and generate dynamic detection rules according to the dynamic rule model;

[0041] S4. Optimize the dynamic detection rules based on the feedback learning and intelligence update mechanism.

[0042] Actually, the rule generation method provided by the present invention can generate dynamic detection rules and enable the rules to be updated in real time according to actual attack activities and intelligence data by integrating the adversarial knowledge base and threat intelligence, achieving the purpose of accurately and comprehensively detecting APT attack behaviors. Moreover, by introducing an automatic optimization mechanism based on feedback learning, the parameters and matching conditions of the rules can be dynamically adjusted, achieving the purpose of high adaptability and high real-time performance of the detection rules.

[0043] In some embodiments, the security data inside the system in step S1 may be system logs, network traffic, IDS / IPS alerts, EDR data, firewall logs, Web server logs, and mail server logs. These data can reflect security events in the system and network and provide detailed behavior records and potential attack signs; threat intelligence may be system security events, behavior patterns, and technical features. These data are used to help identify, predict, and respond to potential or ongoing network threats; the adversarial knowledge base may be the MITRE ATT&CK framework, which provides a standardized attack technique and tactic model, covering all stages of APT attacks and the means to deal with them, providing a systematic basis for subsequent rule modeling. The security data inside the system, threat intelligence, and adversarial knowledge base obtained above are used as input data for subsequent APT attack clue detection. In addition, after obtaining the security data inside the system, threat intelligence, and adversarial knowledge base, preprocessing can be performed on the security data, threat intelligence, and adversarial knowledge base, such as data cleaning, data tagging, and other commonly used preprocessing methods in the art.

[0044] In some embodiments, in step S1, the tactical tag is to preliminarily associate the TTPs in the threat intelligence with the TTPs in the MITRE ATT&CK framework, preprocess the input data, and help the rule generation work in the subsequent stage.

[0045] In some embodiments, in step S2, the static rule model is constructed based on known APT attack chain templates, providing an effective attack chain matching method for the system. For example, in the attack chain template for APT28 (also known as Fancy Bear), it includes the following stages: Initial Access, Execution, Persistence, Privilege Escalation, and Internal Reconnaissance. In addition, some APT groups will establish some typical attack chain templates based on TTPs for the attack patterns of specific targets with strong regularity and predictability.

[0046] In some embodiments, in step S2, the dynamic rule model is based on the 14 tactics defined in the MITRE ATT&CK framework and integrates threat intelligence and time-series data to identify the multi-stage behavior patterns in the APT attack process. The 14 tactics defined in the MITRE ATT&CK framework represent the goals or intentions of attackers at different stages, covering the complete attack chain from reconnaissance to impact, such as reconnaissance, initial access, privilege escalation, lateral movement, and data exfiltration, etc.; in addition, the techniques under the tactics describe the specific methods to achieve these goals and are further refined into sub-techniques to improve the accuracy and practicality of the description. For example, the phishing attack (T1566) in the initial access stage can be subdivided into "malicious attachment" (T1566.001) and "malicious link" (T1566.002).

[0047] In some embodiments, in step S2, the time-series data can be network traffic metadata, terminal process trees, and identity audit records. Through in-depth analysis of this time-series data, the dynamic rule model can use methods such as dynamic time window statistics and behavior chain modeling to capture the evolutionary trajectory of attacker activities in the time dimension, thereby more accurately revealing the internal connections and changing trends of multi-stage attack patterns, and ultimately realizing the effective characterization and restoration of the complete attack chain.

[0048] In some embodiments, in step S3, the threat nodes can be tactics or techniques, which reflect the important behavior patterns of attackers during the attack and provide data support for generating static detection rules. After extracting the threat nodes and combining them with the static rule model to generate static detection rules, the static detection rules can adapt to most common attack scenarios and provide support for basic detection. For example, if we want to detect the attack technique of "Phishing", the static detection rules will be created based on known phishing email characteristics (such as email subject, attachment type, URL address, etc.). The following is part of the code for phishing email detection:

[0049] “if (email.hasAttachment() and

[0050] (attachment.type == \".exe\" or attachment.type == \".vbs\"))

[0051] or

[0052] (email.hasURL() and isMaliciousDomain(email.URL)):

[0053] triggerDetection(\"Suspicious email detected with malicious attachment or URL\")”.

[0054] In some embodiments, in step S3, the priority of threat intelligence can be the credibility, activity, and context relevance of intrusion indicators. The system will dynamically adjust the weights generated by the dynamic detection rules according to the priority of the obtained threat intelligence, and give priority to processing intelligence with high credibility and strong activity. The dynamic detection rules will be generated based on the priority of the obtained threat intelligence and according to the dynamic rule model.

[0055] The formula used is as follows:

[0056] ,

[0057] where is the dynamic detection rule finally generated by the dynamic rule model, is the priority weight of the th node in the threat intelligence, is the score of the technology or tactic corresponding to the th node in the threat intelligence, is the total number of nodes in the threat intelligence.

[0058] In some embodiments, in step S3, when the dynamic detection rules are dealing with attacks by attackers using unique attack techniques, they will be generated and adjusted according to these new threat features. For example, assume that a certain APT organization (such as APT28) uses a new attack method, using a malicious PowerShell script as a payload and injecting malicious code using a memory vulnerability. Based on this dynamic intelligence, the generated dynamic detection rules will include the following to detect suspicious PowerShell script commands execution:

[0059] “if (script.isPowerShell() and

[0060] script.hasCommand("Invoke-Expression") and

[0061] not isExpectedProcess(script.targetProcess)):

[0062] triggerDetection("Suspicious PowerShell execution detected")”。

[0063] In addition, the dynamic detection rule can also automatically generate targeted rules for ongoing attacks through real-time intrusion metric data sources. For example, in a certain APT attack, the attacker uses a specific domain name for data exfiltration. At this time, the dynamic detection rule will detect whether there is traffic accessing these domain names based on this domain name.

[0064] In some embodiments, when optimizing the dynamic detection rule in step S4, first based on feedback learning, by continuously collecting the detection results triggered by the dynamic detection rule and analyzing its false alarm rate and missed alarm rate, and then optimizing the accuracy of the dynamic detection rule. For example, when the dynamic detection rule generates a false alarm, the system will adjust the dynamic detection rule parameters by analyzing the specific scenario of the false alarm (such as the attack pattern or environmental characteristics of the false trigger) to reduce unnecessary alarms. At the same time, the situation of missed alarms will also be marked and analyzed by the system, and the dynamic detection rule will be further adjusted to improve the coverage rate. The system adopts a reinforcement learning algorithm to achieve the purpose of automatically adjusting the parameters and behaviors of the dynamic detection rule. Reinforcement learning is a technology that optimizes the decision-making process through a reward and punishment mechanism, and is particularly suitable for dynamic and ever-changing environments. During the optimization process of the dynamic detection rule, the system will simulate attack scenarios and execute feedback and optimize the parameters in the dynamic detection rule based on reinforcement learning to ensure high accuracy in different threat environments.

[0065] Specifically, the system optimizes the rule by the following steps using the reinforcement learning algorithm:

[0066] First, define the state of the dynamic detection rule according to the current threat intelligence, attack chain process, and the execution feedback of the rule, where the state can be the matching situation of the dynamic detection rule, the technical activity of the current threat intelligence;

[0067] Secondly, according to the state, select the corresponding action to optimize the parameters of the dynamic detection rule, where the action can be to increase the matching time of the intrusion metric, adjust the sensitivity of the attack technology;

[0068] Then, according to the execution feedback each time, when the execution feedback is a low false negative rate and a low false positive rate, a positive reward is given; when the execution feedback is a high false negative rate or a high false positive rate, a negative reward is given. For example, assuming that the false positive rate of a certain rule is 0.1 and the false negative rate is 0.05, the system can define the following reward function :

[0069] ,

[0070] Finally, according to the positive and negative rewards, the strategy of the dynamic detection rule is updated through the Q-learning algorithm in reinforcement learning, and the update formula is:

[0071] ,

[0072] where is the expected return of taking action in state , is the learning rate, is the discount factor, is the immediate reward obtained after executing action , is the expected return of the best action that may be taken in the next state .

[0073] In some embodiments, in step S4, the intelligence update mechanism further enhances the adaptability of the dynamic detection rule by dynamically adjusting the matching parameters of the dynamic detection rule. For example, the system automatically updates the expiration time of the intrusion metrics based on the latest threat intelligence to ensure that the detection can reflect the current threat situation in real time. At the same time, the technical activity in the dynamic detection rule is continuously tracked and adjusted to ensure that the dynamic detection rule preferentially matches the current active attack patterns and avoids ineffective matching of outdated or inactive threats.

[0074] Referring to Figure 2 , the present invention provides a rule generation system for APT attack clue detection, including the following steps:

[0075] A data acquisition module 100, configured to acquire security data and threat intelligence inside the system, and obtain tactical labels through tactical association of the threat intelligence based on an adversarial knowledge base;

[0076] A model construction module 200, configured to construct a static rule model based on known APT attack chain data, fuse threat intelligence and time series data, and construct a dynamic rule model based on an adversarial knowledge base;

[0077] The rule generation module 300 extracts threat nodes of security data and generates static detection rules according to the static rule model, obtains the priorities of threat intelligence, and generates dynamic detection rules according to the dynamic rule model;

[0078] The rule optimization module 400 optimizes the dynamic detection rules based on the feedback learning and intelligence update mechanism.

[0079] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention described in the claims. Moreover, the present invention described herein can have other embodiments and can be implemented or realized in various ways.

Claims

1. A method for generating rules for detecting clues of APT attacks, characterized in that, Including: Obtain the security data and threat intelligence inside the system, and perform tactical association on the threat intelligence based on the adversarial knowledge base to obtain tactical tags; Construct a static rule model based on the known APT attack chain data, fuse the threat intelligence and time-series data, and construct a dynamic rule model based on the adversarial knowledge base; Extract the threat nodes in the security data and generate static detection rules according to the static rule model, obtain the priority of the threat intelligence, and generate dynamic detection rules according to the dynamic rule model; Optimize the dynamic detection rules based on the feedback learning and intelligence update mechanism, including: the system detects the execution feedback of the dynamic detection rules, and optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback; optimize the matching parameters of the dynamic detection rules based on the threat intelligence and the technical activity of the dynamic detection rules, and the technical activity includes the popularity and activity of the attack techniques; When the system optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback, define the state of the dynamic detection rules according to the threat intelligence, the attack chain process, and the execution feedback, and the state includes the matching situation of the dynamic detection rules and the technical activity of the threat intelligence; According to the state, select the corresponding actions to optimize the parameters of the dynamic detection rules, and the actions include increasing the matching time of the intrusion indicators and adjusting the sensitivity of the attack techniques; According to each execution feedback, when the execution feedback is a low false negative rate and a low false positive rate, a positive reward is given, and when the execution feedback is a high false negative rate or a high false positive rate, a negative reward is given; Update the strategy of the dynamic detection rules through the Q-learning algorithm in the reinforcement learning according to the positive reward and the negative reward, and the update formula is: , wherein, is the expected return for taking action in state , is the learning rate, is the discount factor, is the immediate reward obtained after executing action , is the next state and is the expected return of the best action that may be taken in 2. The rule generation method according to claim 1, characterized in that When obtaining the priority of the threat intelligence and generating dynamic detection rules according to the dynamic rule model, the priority of the threat intelligence includes the credibility, activity, and context relevance of the intrusion indicators, and the threat intelligence nodes include intrusion indicators and attack stages; The formula used is as follows: , Among them, is the dynamically detected rule finally generated by the dynamic rule model, is the priority weight of the th node in the threat intelligence, is the score of the technology or tactic corresponding to the th node in the threat intelligence, is the total number of nodes in the threat intelligence.

3. The rule generation method according to claim 1, characterized in that, The security data includes system logs, network traffic, IDS / IPS alerts, EDR data, firewall logs, web server logs, and mail server logs.

4. The rule generation method according to claim 1, wherein The threat intelligence includes system security events, behavior patterns, and technical features.

5. The rule generation method according to claim 1, characterized in that, The adversarial knowledge base includes the MITRE ATT&CK framework.

6. The rule generation method according to claim 1, characterized in that The time-series data includes network traffic metadata, terminal process trees, and identity audit records.

7. The method for generating rules according to claim 1, wherein The threat nodes include tactics or techniques.

8. A rule generation system for APT attack clue detection, characterized in that Including: A data acquisition module, configured to obtain the security data and threat intelligence inside the system, and perform tactical association on the threat intelligence based on the adversarial knowledge base to obtain tactical tags; A model construction module, which constructs a static rule model based on the known APT attack chain data, fuses the threat intelligence and time-series data, and constructs a dynamic rule model based on the adversarial knowledge base; A rule generation module extracts threat nodes from the security data and generates static detection rules according to a static rule model, obtains the priority of the threat intelligence, and generates dynamic detection rules according to the dynamic rule model; A rule optimization module optimizes the dynamic detection rules based on a feedback learning and intelligence update mechanism, including: the system detects the execution feedback of the dynamic detection rules, and optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback; optimizing the matching parameters of the dynamic detection rules based on the threat intelligence and the technical activity of the dynamic detection rules, where the technical activity includes the popularity and activity of attack techniques; When the system optimizes the parameters and behaviors of the dynamic detection rules based on reinforcement learning and the execution feedback, it defines the state of the dynamic detection rules according to the threat intelligence, the attack chain process, and the execution feedback, where the state includes the matching situation of the dynamic detection rules and the technical activity of the threat intelligence; According to the state, select the corresponding action to optimize the parameters of the dynamic detection rules, where the actions include increasing the matching time of intrusion indicators and adjusting the sensitivity of attack techniques; According to each execution feedback, when the execution feedback is a low false negative rate and a low false positive rate, a positive reward is given, and when the execution feedback is a high false negative rate or a high false positive rate, a negative reward is given; Update the strategy of the dynamic detection rules through the Q-learning algorithm in the reinforcement learning according to the positive reward and the negative reward, and the update formula is: , wherein, is the expected return for taking action in state , is the learning rate, is the discount factor, is the immediate reward obtained after executing action , is the next state and is the expected return of the best action that may be taken in​

Citation Information

Patent Citations

  • Threat response method and device based on threat intelligence and ATT&CK

    CN112769821A

  • Network security detection method and system

    CN118101250A