Network security knowledge graph construction method and device, equipment and storage medium
By building a network security knowledge graph, the network security information source and offensive and defense technology and tactical ontology models are transformed into entities and relationships, and the problem of high cost of network security learning is solved and the integrity and correlation of knowledge is improved.
Patent Information
- Application Number
- CN202311651044.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-06
AI Technical Summary
The learning cost of network security in the prior art is too high, making it difficult for technicians to fully cover the panoramic view of actual offensive and defense technology, and it is difficult to establish a ‘interrelationship’ between attack, defense and evaluation.
By obtaining network security information sources and offensive and defense technology and tactical ontology models, determine the target entity and entity relationship, build a network security knowledge graph, package the network security information content into entities and associate it through entity relationships, and form a structured knowledge graph.
It realizes the connection between network security knowledge, which is convenient for users to view and use, provides convenience for network security learning, and improves the integrity and relevance of network security knowledge.
Smart Images

Figure CN120106186A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security knowledge graph construction method, device, equipment and storage medium. Background Art
[0002] With the development of key technologies such as cloud computing, 5G, the Internet of Things, and the Industrial Internet, cyberspace has become the cornerstone of the digital economy. However, the attack surface of cyberspace has been extended and expanded, and the information asymmetry between the attackers and defenders in cyberspace has been aggravated. The integration of automated and intelligent attack and defense techniques and tactics has become a trend in the development of network security.
[0003] However, the threshold for network security technology is relatively high at present. A mature network security engineer often needs several years of experience to get started with the actual application of network attack and defense techniques and tactics. It can be seen that the network security knowledge system is complicated and intricate, and technical personnel lack effective reference channels. Security research and operation personnel cannot fully cover the panoramic view of actual attack and defense techniques and tactics, and it is difficult to establish the "intercorrelation" between attack, defense and evaluation. Therefore, how to reduce the learning cost of network security has become a technical problem that needs to be solved urgently.
[0004] The above contents are only used to assist in understanding the technical solution of the present invention and do not constitute an admission that the above contents are prior art. Summary of the invention
[0005] The main purpose of the present invention is to provide a method, device, equipment and storage medium for constructing a network security knowledge graph, aiming to solve the technical problem of high learning cost of network security in the prior art.
[0006] To achieve the above object, the present invention provides a method for constructing a network security knowledge graph, the method comprising the following steps: Obtain network security information sources and attack and defense tactics ontology models; Determine the target entity based on the attack and defense technical and tactical ontology model and the network security information source; Determine entity relationships according to the offensive and defensive technical and tactical ontology model and the target entity; Construct a network security knowledge graph based on the target entities and entity relationships.
[0007] Optionally, obtaining the attack and defense skills and tactics ontology model includes: Construct network attack entity class, network defense entity class and entity object attributes; According to the network attack entity class and the network defense entity class configuration attribute items, obtain network attack entity class attribute items and network defense entity class attribute items; An attack and defense technique and tactic ontology model is generated according to the network attack entity class, the network defense entity class, the entity object attribute network attack entity class attribute item and the network defense entity class attribute item.
[0008] Optionally, the network attack entity class includes: attack tactics entity class, attack technology entity class, attack implementation process entity class, asset content entity class, vulnerability entity class, simulated attack script entity class, hacker tool entity class and third-party service entity class.
[0009] Optionally, the network defense entity class includes: a security detection product entity class, a detection data source entity class, and a detection item entity class.
[0010] Optionally, determining the target entity according to the attack and defense techniques and tactics ontology model and the network security information source includes: Matching the network security information source according to the attack and defense technique and tactics ontology model to obtain the corresponding text object; The text object is constructed as a target entity according to the offensive and defensive technical and tactical ontology model.
[0011] Optionally, constructing the text object as a target entity according to the offensive and defensive skills and tactics ontology model includes: Determine the target entity type and the attribute items corresponding to the target entity type according to the offensive and defensive technical and tactical ontology model; The text object is extracted according to the target entity type and the attribute items corresponding to the target entity type to obtain the target entity.
[0012] Optionally, matching the network security information source according to the attack and defense techniques and tactics ontology model to obtain the corresponding text object includes: Determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack tactic entity class or an attack technology entity class, the MITRE ATT&CK knowledge base is determined to be a text object.
[0013] Optionally, matching the network security information source according to the attack and defense techniques and tactics ontology model to obtain the corresponding text object also includes: Determine entity class information according to the offensive and defensive technical and tactical ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack implementation process entity class, the network threat analysis report is determined to be a text object.
[0014] Optionally, matching the network security information source according to the attack and defense techniques and tactics ontology model to obtain the corresponding text object also includes: Determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is a vulnerability entity class or an asset content entity class, the national information security vulnerability database and the national information security vulnerability sharing platform are determined as text objects.
[0015] Optionally, determining the entity relationship according to the attack and defense technique and tactics ontology model and the target entity includes: Determine an entity text sample according to the target entity; Determine the entity pair mapping relationship according to the offensive and defensive technical and tactical ontology model; Entity relationships are extracted from network security information sources based on the entity pair mapping relationship and entity text samples.
[0016] In addition, to achieve the above-mentioned purpose, the present invention also proposes a network security knowledge graph construction device, the network security knowledge graph construction device comprising: The acquisition module is used to obtain network security information sources and attack and defense tactics ontology models; A processing module, used to determine a target entity according to the attack and defense technique and tactics ontology model and a network security information source; The processing module is further used to determine entity relationships according to the attack and defense skills and tactics ontology model and the target entity; The processing module is also used to construct a network security knowledge graph based on the target entity and entity relationship.
[0017] Optionally, the acquisition module is further used to construct a network attack entity class, a network defense entity class, and entity object attributes; According to the network attack entity class and the network defense entity class configuration attribute items, obtain network attack entity class attribute items and network defense entity class attribute items; An attack and defense technique and tactic ontology model is generated according to the network attack entity class, the network defense entity class, the entity object attribute network attack entity class attribute item and the network defense entity class attribute item.
[0018] Optionally, the network attack entity class includes: attack tactics entity class, attack technology entity class, attack implementation process entity class, asset content entity class, vulnerability entity class, simulated attack script entity class, hacker tool entity class and third-party service entity class.
[0019] Optionally, the network defense entity class includes: a security detection product entity class, a detection data source entity class, and a detection item entity class.
[0020] Optionally, the processing module is further used to match the network security information source according to the attack and defense technique and tactics ontology model to obtain a corresponding text object; The text object is constructed as a target entity according to the offensive and defensive technical and tactical ontology model.
[0021] Optionally, the processing module is further used to determine the target entity type and the attribute items corresponding to the target entity type according to the offensive and defensive technical and tactical ontology model; The text object is extracted according to the target entity type and the attribute items corresponding to the target entity type to obtain the target entity.
[0022] Optionally, the processing module is further used to determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack tactic entity class or an attack technology entity class, the MITRE ATT&CK knowledge base is determined to be a text object.
[0023] Optionally, the processing module is further used to determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack implementation process entity class, the network threat analysis report is determined to be a text object.
[0024] In addition, to achieve the above-mentioned purpose, the present invention also proposes a network security knowledge graph construction device, which includes: a memory, a processor, and a network security knowledge graph construction program stored on the memory and executable on the processor, and the network security knowledge graph construction program is configured to implement the steps of the network security knowledge graph construction method described above.
[0025] In addition, to achieve the above-mentioned purpose, the present invention also proposes a storage medium, on which a network security knowledge graph construction program is stored, and when the network security knowledge graph construction program is executed by a processor, the steps of the network security knowledge graph construction method described above are implemented.
[0026] The present invention obtains a network security information source and an attack and defense technique and tactics ontology model; determines a target entity based on the attack and defense technique and tactics ontology model and the network security information source; determines an entity relationship based on the attack and defense technique and tactics ontology model and the target entity; and constructs a network security knowledge graph based on the target entity and the entity relationship. Through the above-mentioned method, it is realized that the network security information content is packaged into entities, and they are associated with entity relationships to form a structured network security knowledge graph. The network security knowledge is linked together to facilitate users to consult and use, provide convenience for network security learning, and improve the integrity and relevance of network security knowledge. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 It is a schematic diagram of the structure of a network security knowledge graph construction device for a hardware operating environment involved in an embodiment of the present invention; Figure 2 This is a flow chart of the first embodiment of the method for constructing a network security knowledge graph of the present invention; Figure 3 This is a flow chart of the second embodiment of the method for constructing a network security knowledge graph according to the present invention; Figure 4 This is a structural block diagram of the first embodiment of the network security knowledge graph construction device of the present invention.
[0028] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0029] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0030] Reference Figure 1 , Figure 1 A schematic diagram of the device structure is provided for constructing a network security knowledge graph of the hardware operating environment involved in the embodiment of the present invention.
[0031] like Figure 1As shown, the network security knowledge graph construction device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (Wireless-Fidelity, Wi-Fi) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM) memory, or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0032] Those skilled in the art will understand that Figure 1 The structure shown in does not constitute a limitation on the network security knowledge graph construction device, and may include more or fewer components than shown in the figure, or a combination of certain components, or a different arrangement of components.
[0033] like Figure 1 As shown, the memory 1005 as a storage medium may include an operating system, a network communication module, a user interface module, and a network security knowledge graph construction program.
[0034] exist Figure 1 In the network security knowledge graph construction device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the network security knowledge graph construction device of the present invention can be set in the network security knowledge graph construction device, and the network security knowledge graph construction device calls the network security knowledge graph construction program stored in the memory 1005 through the processor 1001, and executes the network security knowledge graph construction method provided by the embodiment of the present invention.
[0035] The embodiment of the present invention provides a method for constructing a network security knowledge graph, referring to Figure 2 , Figure 2 This is a flow chart of a first embodiment of a method for constructing a network security knowledge graph according to the present invention.
[0036] In this embodiment, the network security knowledge graph construction method includes the following steps: Step S10: Obtain network security information sources and attack and defense techniques and tactics ontology models.
[0037] It should be noted that the executor of this embodiment is a smart terminal, which may be a server, a computer, or other devices with the same or similar functions as a server. This embodiment does not limit this and only takes the server as an example for explanation.
[0038] It should be noted that this embodiment is applied to the process of constructing network security knowledge into a knowledge graph. Based on the knowledge graph technology, this solution continuously presents the newly added attack techniques and tactics and implementation process (TTP), attack tools, attacker organization information, asset types involved, data sources involved, detection rules, defense solutions and other information in actual combat attack and defense confrontation, as well as the relationship between them on a visual graph, so that security researchers and operators can fully cover the panoramic view of actual combat attack and defense techniques and tactics, and establish the "interrelationship" between attack, defense and evaluation, so as to provide clear action guidance for combating known threats and even unknown threats. By establishing an attack and defense technique and tactical knowledge graph, multi-source heterogeneous security data can be efficiently integrated to realize knowledge visualization, relationalization and systematization, and provide an intuitive modeling method for threat analysis. By establishing an attack and defense technique and tactical knowledge graph with its own security semantics, the layer-by-layer reasoning and analysis capabilities built around the knowledge graph provide key input elements and strategy construction frameworks for achieving decision-making intelligence in specified scenarios.
[0039] It should be noted that the sources of network security information are some website databases that are loaded with network information-related knowledge, such as: National Information Security Vulnerability Database (CNNVD), National Information Security Vulnerability Sharing Platform (CNVD), National Vulnerability Database, corporate experience accumulation, web page information crawled by web crawlers, and MITRE ATT&CK, etc.
[0040] It can be understood that the attack and defense tactics ontology model is an ontology model constructed according to the network knowledge structure. In the knowledge graph, the ontology model is a structured model used to describe and organize domain knowledge. The ontology model defines the concepts, attributes and relationships of a domain and provides a formal way to represent and reason about this knowledge. The ontology model usually uses a semantic-based description language, such as OWL (Web Ontology Language) or RDF (Resource Description Framework), to define the hierarchy and constraints between concepts, attributes and relationships. It can include concepts such as class, property, instance, and the relationships between them, such as subclass relationship, attribute relationship, etc. Through the ontology model, the entities and relationships in the knowledge graph can be semantically described and reasoned. The ontology model can help understand and interpret the data in the knowledge graph, support ontology-based query and reasoning, and data integration and interaction between different knowledge graphs. The ontology model plays a key role in the knowledge graph. It provides a way to share and communicate domain knowledge and provides a basis for the construction, maintenance and application of the knowledge graph. In this embodiment, the ontology model is used to define and constrain entities, their corresponding attributes, and the relationships between entities, so as to form a template to construct the knowledge graph. The attack and defense techniques and tactics ontology model is the application of the ontology concept in the field of information security. It mainly starts from the perspective of network security and contains a security domain model that abstracts the conceptual knowledge related to network attacks and security defenses, that is, it gives a normalized, abstract, and reasonable attack and defense techniques and tactics ontology paradigm. The ontology model is mainly used to provide formalized and unified terms and relationships between terms in the security field, and has the ability of ontology reasoning and query.
[0041] In some embodiments, a network attack entity class, a network defense entity class, and entity object attributes are constructed; network attack entity class attribute items and network defense entity class attribute items are obtained based on the network attack entity class and network defense entity class configuration attribute items; an attack and defense technique and tactics ontology model is generated based on the network attack entity class, network defense entity class, entity object attributes, network attack entity class attribute items, and network defense entity class attribute items.
[0042] It should be noted that if the network security knowledge graph structure needs to be efficient and reasonable, how to construct the ontology model will be very important. This embodiment proposes a preferred solution to divide the entity types in the ontology model into network attack entity class, network defense entity class and entity object attributes, where the network attack entity class contains multiple network attack content entities. This is because the attack and defense techniques and tactics in network security can be divided according to network attack and network defense. The knowledge of attack and defense classes are closely related to the knowledge in their own types. Dividing into major categories is more conducive to summarizing and dividing the knowledge system. The attribute items are generally contained in each entity. For example: in the network attack entity class, it may contain entities of attack technology. Then the attribute items that each entity in the attack technology subclass should contain may be: ID: technology number, String type (data type); name: technology name, String type; description: technology description, String type; operating platform: platform for implementing attack technology, String type; attack assets: attack targets of attack technology, String type; authority requirements: authority required for implementing attack technology, String type; authority acquisition: authority that can be obtained after the implementation of attack technology, String type.
[0043] In the specific implementation, common network security knowledge can be summarized into network attack entity classes to obtain many network attack entity subclasses, such as: Attack type: describes different types of network attacks, such as service attacks, malware, social engineering, etc. Attacker: refers to the individual, organization or source of malicious behavior that launches a network attack. It can include virus authors or other malicious actors. Victim: refers to the target of a network attack, which may be an individual, organization, system or network. The victim may suffer data leakage, system paralysis, information loss or other damage. Vulnerability: refers to a security weakness in software, system or network that may be exploited by attackers. Vulnerabilities can be operating system vulnerabilities, application vulnerabilities, configuration errors, etc. Attack tools: refers to software, tools or scripts used to launch network attacks. These tools can include penetration testing tools, vulnerability exploitation tools, password cracking tools, etc. Malware: refers to malicious software programs, including viruses, worms, Trojan horses, etc. Malware is used for malicious activities such as invading systems, stealing information, and destroying data. Security protection measures: refers to measures used to protect systems and networks from attacks. Including firewalls, intrusion detection systems (IDS), encryption technology, access control, etc. Attack event: refers to a specific event or instance of a network attack. Attack events may include information such as attack time, attack method, attack path, and attack consequences. Vulnerability exploitation: refers to the process by which an attacker exploits a known vulnerability in a system or application to launch an attack. Vulnerability exploitation may lead to system intrusion, data leakage, or other damage.
[0044] In the specific implementation, common network security knowledge can be summarized into network defense entity classes to obtain many network defense entity subclasses, which can be, for example, firewall: a device or software used to monitor and control network traffic, which can filter inbound and outbound data packets to protect the network from unauthorized access and attacks. Intrusion Detection System (IDS): a system used to monitor abnormal activities and attack behaviors in the network. IDS can detect potential intrusion behaviors based on predefined rules or behavior patterns. Intrusion Prevention System (IPS): similar to IDS, but IPS can not only detect potential intrusion behaviors, but also actively block and defend against intrusion behaviors to protect the security of the network. Anti-virus software: a software tool used to detect, block and remove malware (such as viruses, worms, Trojan horses, etc.) in computer systems. Security Information and Event Management System (SIEM): used to collect, analyze and report information from various security devices and logs to timely discover and respond to potential security incidents. Honeypot: a false system deliberately placed in the network to attract attackers and monitor their attack behaviors. Honeypots can help security teams understand the techniques and strategies of attackers and take corresponding defensive measures. Security authentication and access control: mechanisms used to verify user identities and control their access rights to systems or resources, such as passwords, two-factor authentication, access control lists, etc.
[0045] In some embodiments, the network attack entity class includes: attack tactics entity class, attack technology entity class, attack implementation process entity class, asset content entity class, vulnerability entity class, simulated attack script entity class, hacker tool entity class and third-party service entity class.
[0046] It should be noted that this embodiment proposes a preferred composition scheme for each subclass in a network attack entity class. Since the knowledge graph in this embodiment is mainly used to enhance the relevance of attack and defense techniques and tactics, this embodiment proposes an entity structure around attack and defense techniques and tactics and their connections, as follows: The network attack entity class includes: attack tactics entity class, attack technology entity class, attack implementation process entity class, asset content entity class, vulnerability entity class, simulated attack script entity class, hacker tool entity class and third-party service entity class.
[0047] Among them, the attack tactics entity class: describes the tactical methods and strategies of network attacks, including different attack tactics focusing on infiltration, evasion of detection, persistent access, data theft, etc. Attack technology entity class: describes the specific technologies and methods used in network attacks, such as vulnerability exploitation, password cracking, social engineering, man-in-the-middle attacks, etc. Attack implementation process entity class: describes the implementation process and steps of network attacks, including target selection, reconnaissance, intrusion, lateral movement, data theft, etc. Asset content entity class: describes various assets and content in the network, such as data, files, databases, applications, etc., which may become the target of attackers. Vulnerability entity class: describes security vulnerabilities in software, systems or networks, including known vulnerabilities, zero-day vulnerabilities, etc., which attackers can exploit to attack. Simulated attack script entity class: describes the scripts and scenarios of simulated attacks, which are used to test and evaluate the effectiveness and weaknesses of network security defense measures. Hacker tool entity class: describes the tools, software or equipment used to conduct network attacks, such as port scanners, vulnerability scanners, password cracking tools, etc. Third-party service entity class: describes network security-related services provided externally, such as security consulting, vulnerability reporting, incident response, etc.
[0048] In some embodiments, the network defense entity class includes: a security detection product entity class, a detection data source entity class, and a detection item entity class.
[0049] It should be noted that the network defense entity class is mainly used to include entities that play a role in the network defense security process, such as: security detection product entity class, detection data source entity class and detection item entity class.
[0050] Specifically, the security detection product entity class: describes the software, hardware or service products used for security detection and monitoring. These products can help organizations detect potential security threats, monitor network activities, discover abnormal behaviors, etc. The detection data source entity class: describes the data source used by security detection products. These data sources can include network traffic data, system logs, intrusion detection system (IDS) alarms, honeypot data, etc. Security detection products will obtain information from these data sources to analyze and detect potential security incidents. The detection item entity class: describes the specific items or rules used for detection and analysis in security detection products. These detection items can be based on specific threat intelligence, behavioral analysis, vulnerability scanning and other methods to identify potential security threats. For example, detection items can include malware detection, abnormal login detection, port scan detection, etc.
[0051] Step S20: determining the target entity according to the attack and defense technique and tactics ontology model and the network security information source.
[0052] It should be noted that after the ontology model is established, it is necessary to extract the required information from the massive data according to the attack and defense tactics ontology model to form entities. Specify the goals and scope of the entity according to the ontology model, and then determine the entity categories in the ontology model according to the goals and scope. For example, in the cybersecurity knowledge graph, entity categories such as attack techniques, security tools, and vulnerabilities may be defined. Fill in entity data based on cybersecurity information sources, and fill in entity data in the ontology model based on needs and available data. This can include extracting data from existing databases, documents, or other sources and mapping them to entities and attributes defined in the ontology model.
[0053] It is understandable that the specific process can be, for example: Determine what data needs to be collected to populate the entity. This can include obtaining data from various sources, such as documents, databases, APIs, web crawlers, etc. Ensure that the data source is reliable, accurate, and relevant to the ontology model goals and entity categories. Preprocess the collected data to adapt it to the requirements of the ontology model. This may include data cleaning, deduplication, format conversion, etc. Ensure the consistency and availability of the data. Map the preprocessed data to the corresponding entities and attributes in the ontology model. According to the definition of the ontology model, correspond specific fields or attributes in the data to the entities and attributes in the ontology model. This can be achieved through programming scripts or data conversion tools. Import the populated and cleaned data into the ontology model. This can be achieved through ontology modeling tools or programming scripts. Ensure the correct import of the data and verify the correctness and completeness of the data in the ontology model to obtain a complete entity.
[0054] Step S30: determining entity relationships according to the attack and defense technique and tactics ontology model and the target entity.
[0055] It should be noted that entity relationships are relationships between entities. For example, in the ontology model, there may be a certain entity relationship between the attack technology entity class and the operating platform entity class. In the entity relationship extraction process, it can be expressed as attack technology - [platform requirements] -> operating platform, where the platform requirements are entity relationships. Specifically, when the entity of the attack technology entity class is "Remote Desktop Protocol", its relationship with the "Windows" entity in the operating platform entity class is determined. At this time, the relationship between this pair of entities can be learned and extracted in the data source, and the relationship "Remote Desktop Protocol - [Platform Requirements] -> Windows" can be extracted to determine the entity relationship. It can also be illustrated by the following cases, for example: Attack technology - [Service requirements] -> Service status, such as: Remote Desktop Protocol - [Service requirements] -> rdp:running; Attack technology - [Achieved] -> Attack tactics, such as: Remote Desktop Protocol - [Achieved] -> Lateral movement; Attack technology - [Permission requirements] -> Permissions, such as: Remote Desktop Protocol - [Permission requirements] -> RDP users; Attack technology - [Permission acquisition] -> Permissions, such as: UAC bypass - [Permission acquisition] -> Administrator permissions; Detection data source - [Provided] -> Detection data items, such as: Registry - [Provided] -> Registry modification; Detection data items - [Detection] -> Attack technology, such as: Registry modification - [Detection] -> Registry Run key value / startup directory; Security product - [Provided] -> Detection data items, such as: EDR - [Provided] -> Registry modification; Attack implementation process - [Attack] -> Assets, such as: A certain attack implementation process - [Attack] -> Windows operating system; Attack implementation process - [Use] ->Simulated attack script, such as: an attack implementation process - [Use] ->A simulated attack script; vulnerability - [Attack] ->Assets, such as: CVE-2022-41040 - [Attack] ->microsoft:exchange_server.
[0056] In some embodiments, an entity text sample is determined based on the target entity; an entity pair mapping relationship is determined based on the attack and defense techniques and tactics ontology model; and an entity relationship is extracted from a network security information source based on the entity pair mapping relationship and the entity text sample.
[0057] It should be noted that graph construction is a key step in the research and application of offensive and defensive technical and tactical knowledge graphs after determining the application scenarios of the offensive and defensive technical and tactical knowledge graphs and building the corresponding ontology model. How to select data sources, data preprocessing technology, and apply natural language processing technology to mine and integrate knowledge determines the accuracy, completeness, consistency, and comprehensibility of the knowledge graph.
[0058] It should be noted that in order to improve the efficiency of entity extraction, the entity text sample can be determined based on the target entity, that is, the source of the data source can be determined based on the entity type. For example, the entity text sample can be the content of a certain chapter, a certain paragraph or a certain article. The relationship between different entities is extracted according to the ontology model. This avoids traversing the entire data and improves the efficiency of extracting entity relationships.
[0059] Step S40: Construct a network security knowledge graph based on the target entities and entity relationships.
[0060] In the specific implementation, a basic network security knowledge graph can be obtained by mapping a large number of entities and entity relationships into the knowledge graph, such as filling the collected data into the knowledge graph according to the ontology model. This includes mapping the entities in the data to the entity types in the ontology model and establishing connections between entities based on entity relationships. Finally, the knowledge graph is inferred and deduced using an inference engine or rule system to derive new knowledge from existing entities, attributes, and relationships. This can help fill in gaps or missing parts in the knowledge graph and discover hidden associations and patterns.
[0061] This embodiment obtains a network security information source and an attack and defense technique and tactics ontology model; determines a target entity based on the attack and defense technique and tactics ontology model and the network security information source; determines an entity relationship based on the attack and defense technique and tactics ontology model and the target entity; and constructs a network security knowledge graph based on the target entity and the entity relationship. Through the above method, it is realized to package the network security information content into entities, and associate them with entity relationships to form a structured network security knowledge graph. The network security knowledge is linked together to facilitate users to consult and use, provide convenience for network security learning, and improve the integrity and relevance of network security knowledge.
[0062] refer to Figure 3 , Figure 3 This is a flow chart of the second embodiment of a method for constructing a network security knowledge graph according to the present invention.
[0063] Based on the first embodiment described above, the network security knowledge graph construction method of this embodiment further includes, in step S20: Step S21: matching the network security information source according to the attack and defense technique and tactics ontology model to obtain the corresponding text object.
[0064] It should be noted that the network security information source is matched according to the attack and defense tactics ontology model to obtain the corresponding text object. For example: attack tactics entity class, attack technology entity class: use MITRE ATT&CK, and supplement a large amount of attack tactics data from the enterprise itself. Determining text by differentiating data sources can effectively improve the efficiency and accuracy of the knowledge extraction process.
[0065] In some embodiments, entity class information is determined based on the attack and defense techniques and tactics ontology model; a network security information source is queried based on the entity class information; and when the entity class information is an attack tactics entity class or an attack technology entity class, the MITRE ATT&CK knowledge base is determined to be a text object.
[0066] This embodiment proposes that when the entity class information is an attack tactic entity class or an attack technology entity class, it is preferred to determine that the MITRE ATT&CK knowledge base is a text object. It is a widely used open knowledge base that aims to describe and classify threat behaviors and attack techniques against computer systems and networks. It is developed and maintained by MITRE Corporation and provides a way for security professionals, researchers, and organizations to share and understand threat intelligence. The MITRE ATT&CK framework is based on the study and analysis of real attack activities, decomposing attack behaviors into multiple stages and techniques, and organizing them into a structured classification system. The framework provides a common language and standards that enable the security community to better understand and share information about threat behaviors.
[0067] In some embodiments, entity class information is determined based on the attack and defense techniques and tactics ontology model; a network security information source is queried based on the entity class information; and when the entity class information is an attack implementation process entity class, a network threat analysis report is determined to be a text object.
[0068] It can be understood that when the entity class information is an attack implementation process entity class, the attack implementation process and related entities are extracted by obtaining a network threat analysis report from the Internet and extracting TTP from an unstructured network attack report through a pre-trained language model.
[0069] It should be noted that the network threat analysis report is a document that describes and analyzes network threat events in detail. It is usually written by security experts, threat intelligence analysts or security companies, and is intended to provide in-depth insights and understanding of specific threat activities. Network threat analysis reports usually contain multiple key knowledge, such as: a detailed description of a specific threat activity, including the attacker's goals, attack methods and tools or technologies used; analysis and description of the implementation process of the attack, including the attacker's action chain, attack phases and specific technologies used; description of the attacked entity, such as the attacked organization, system, application or network equipment; providing relevant intelligence about the attack activity, such as the attacker's identity, the background of the attack organization, the pattern of the attack target, etc.; describing the impact and consequences of the attack on the affected entity, such as data leakage, service interruption, system damage, etc.; providing defense recommendations and security measures for the threat activity to help organizations enhance security protection and mitigate attack risks; network threat analysis reports are usually based on the study and analysis of real attack events, and are intended to provide detailed information and insights about specific threat activities. These reports are valuable resources for security teams, network administrators and decision makers, helping them better understand and respond to threats and improve network security defense capabilities.
[0070] In some embodiments, entity class information is determined based on the attack and defense techniques and tactics ontology model; network security information sources are queried based on the entity class information; and when the entity class information is a vulnerability entity class or an asset content entity class, the national information security vulnerability database and the national information security vulnerability sharing platform are determined as text objects.
[0071] It should be noted that when the entity class information is a vulnerability entity class or an asset content entity class, the National Information Security Vulnerability Database (CNNVD), the National Information Security Vulnerability Sharing Platform (CNVD) or other national vulnerability databases (NVD) are used, and the consistency of the data is ensured through knowledge fusion technology. For example: The National Information Security Vulnerability Database (CNNVD) is China's national information security vulnerability sharing platform, which is operated and maintained by the National Internet Emergency Center (CNCERT). The goal of CNNVD is to collect, organize and publish relevant information about information security vulnerabilities to provide users and organizations for vulnerability management and security protection. It has the most comprehensive vulnerability information and provides a good data content for the vulnerability entity of the knowledge graph.
[0072] Step S22: constructing the text object as a target entity according to the offensive and defensive techniques and tactics ontology model.
[0073] It should be noted that after the ontology model is established, it is necessary to extract the required information from the massive data according to the attack and defense tactics ontology model to form entities. According to the ontology model, the objectives and scope of the entity are specified, and according to the objectives and scope of the entity, the entity categories in the ontology model are determined. For example, in the cybersecurity knowledge graph, entity categories such as attack techniques, security tools, and vulnerabilities may be defined. According to the cybersecurity information source, fill in the entity data, and fill in the entity data in the ontology model according to the needs and available data. This can include extracting data from existing databases, documents, or other sources, and mapping them to the entities and attributes defined in the ontology model.
[0074] In some embodiments, the target entity type and the attribute items corresponding to the target entity type are determined according to the offensive and defensive technical and tactical ontology model; the text object is extracted according to the target entity type and the attribute items corresponding to the target entity type to obtain the target entity.
[0075] It is understandable that after determining the entity, the attribute content of the entity must also be determined. For example, in the entity of the "detection data source" type, some attributes must be filled in, such as: "ID: detection data source number, String type; Name: detection data source name, String type; Description: detection data source description, String type", and the text object is extracted according to the above target entity type and the attribute items corresponding to the target entity type. The specific extraction process can be: the rule-based method uses predefined rules and patterns to match and extract entity attributes. These rules can be defined based on keywords, grammatical structures, contexts, etc. For example, the attribute value of the entity is extracted by matching specific words or phrases. Alternatively, based on the machine learning method, a machine learning algorithm is used to train the model to learn and identify entity attributes from the text. This method usually requires well-labeled training data, as well as feature engineering and model training processes. Commonly used machine learning algorithms include conditional random fields (CRF), support vector machines (SVM), and deep learning models.
[0076] This embodiment matches the network security information source according to the attack and defense technique and tactics ontology model to obtain the corresponding text object; and constructs the text object as the target entity according to the attack and defense technique and tactics ontology model. Through the above method, the network security information source is matched, the data extraction object is screened, and the efficiency of entity extraction is improved.
[0077] In addition, an embodiment of the present invention also proposes a storage medium, on which a network security knowledge graph construction program is stored. When the network security knowledge graph construction program is executed by a processor, the steps of the network security knowledge graph construction method described above are implemented.
[0078] Reference Figure 4 , Figure 4 This is a structural block diagram of the first embodiment of the network security knowledge graph construction device of the present invention.
[0079] like Figure 4 As shown, the network security knowledge graph construction device proposed in the embodiment of the present invention includes: An acquisition module 10 is used to acquire network security information sources and attack and defense tactics ontology models; A processing module 20, configured to determine a target entity according to the attack and defense technique and tactics ontology model and a network security information source; The processing module 20 is further used to determine entity relationships according to the attack and defense technique and tactics ontology model and the target entity; The processing module 20 is further used to construct a network security knowledge graph according to the target entity and entity relationship.
[0080] It should be understood that the above is only an example and does not constitute any limitation on the technical solution of the present invention. In specific applications, technicians in this field can make settings as needed, and the present invention does not limit this.
[0081] In this embodiment, the acquisition module 10 acquires the network security information source and the attack and defense technique and tactics ontology model; the processing module 20 determines the target entity according to the attack and defense technique and tactics ontology model and the network security information source; the processing module 20 determines the entity relationship according to the attack and defense technique and tactics ontology model and the target entity; the processing module 20 constructs a network security knowledge graph according to the target entity and the entity relationship. Through the above method, it is realized to package the network security information content into entities, and associate them with entity relationships to form a structured network security knowledge graph. The network security knowledge is linked together to facilitate users to consult and use, provide convenience for network security learning, and improve the integrity and relevance of network security knowledge.
[0082] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of the present invention. In practical applications, technicians in this field can select part or all of them according to actual needs to achieve the purpose of the present embodiment, and no limitation is made here.
[0083] In addition, for technical details not described in detail in this embodiment, please refer to the network security knowledge graph construction method provided in any embodiment of the present invention, which will not be repeated here.
[0084] The present invention also provides a method for constructing a network security knowledge graph. A1: The method for constructing a network security knowledge graph comprises: Obtain network security information sources and attack and defense tactics ontology models; Determine the target entity based on the attack and defense technical and tactical ontology model and the network security information source; Determine entity relationships according to the offensive and defensive technical and tactical ontology model and the target entity; Construct a network security knowledge graph based on the target entities and entity relationships.
[0085] A2. The method described in A1, wherein obtaining the attack and defense technique and tactics ontology model comprises: Construct network attack entity class, network defense entity class and entity object attributes; According to the network attack entity class and the network defense entity class configuration attribute items, obtain network attack entity class attribute items and network defense entity class attribute items; An attack and defense technique and tactic ontology model is generated according to the network attack entity class, the network defense entity class, the entity object attribute network attack entity class attribute item and the network defense entity class attribute item.
[0086] A3. As described in A2, the network attack entity class includes: attack tactics entity class, attack technology entity class, attack implementation process entity class, asset content entity class, vulnerability entity class, simulated attack script entity class, hacker tool entity class and third-party service entity class.
[0087] A4. As described in A2, the network defense entity class includes: a security detection product entity class, a detection data source entity class, and a detection item entity class.
[0088] A5. The method described in A1, wherein determining the target entity based on the attack and defense technique and tactics ontology model and the network security information source comprises: Matching the network security information source according to the attack and defense technique and tactics ontology model to obtain the corresponding text object; The text object is constructed as a target entity according to the offensive and defensive technical and tactical ontology model.
[0089] A6. The method described in A5, wherein the text object is constructed as a target entity according to the offensive and defensive techniques and tactics ontology model, comprising: Determine the target entity type and the attribute items corresponding to the target entity type according to the offensive and defensive technical and tactical ontology model; The text object is extracted according to the target entity type and the attribute items corresponding to the target entity type to obtain the target entity.
[0090] A7. The method described in A5, wherein the network security information source is matched according to the attack and defense technique and tactics ontology model to obtain the corresponding text object, including: Determine entity class information according to the offensive and defensive technical and tactical ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack tactic entity class or an attack technology entity class, the MITRE ATT&CK knowledge base is determined to be a text object.
[0091] A8. The method as described in A5, wherein the network security information source is matched according to the attack and defense technique and tactics ontology model to obtain the corresponding text object, further comprising: Determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack implementation process entity class, the network threat analysis report is determined to be a text object.
[0092] A9. The method as described in A5, wherein the network security information source is matched according to the attack and defense technique and tactics ontology model to obtain the corresponding text object, further comprising: Determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is a vulnerability entity class or an asset content entity class, the national information security vulnerability database and the national information security vulnerability sharing platform are determined as text objects.
[0093] A10. The method described in A1, wherein determining the entity relationship based on the attack and defense technique and tactics ontology model and the target entity comprises: Determine an entity text sample according to the target entity; Determine the entity pair mapping relationship according to the offensive and defensive technical and tactical ontology model; Entity relationships are extracted from network security information sources based on the entity pair mapping relationship and entity text samples.
[0094] The present invention also provides a network security knowledge graph construction device, B11, the network security knowledge graph construction device comprises: The acquisition module is used to obtain network security information sources and attack and defense tactics ontology models; A processing module, used to determine a target entity according to the attack and defense technique and tactics ontology model and a network security information source; The processing module is further used to determine entity relationships according to the attack and defense skills and tactics ontology model and the target entity; The processing module is also used to construct a network security knowledge graph based on the target entity and entity relationship.
[0095] B12. In the device as described in B11, the acquisition module is further used to construct a network attack entity class, a network defense entity class and entity object attributes; According to the network attack entity class and the network defense entity class configuration attribute items, obtain network attack entity class attribute items and network defense entity class attribute items; An attack and defense technique and tactic ontology model is generated according to the network attack entity class, the network defense entity class, the entity object attribute network attack entity class attribute item and the network defense entity class attribute item.
[0096] B13. In the device as described in B12, the network attack entity class includes: attack tactics entity class, attack technology entity class, attack implementation process entity class, asset content entity class, vulnerability entity class, simulated attack script entity class, hacker tool entity class and third-party service entity class.
[0097] B14. In the device as described in B12, the network defense entity class includes: a security detection product entity class, a detection data source entity class, and a detection item entity class.
[0098] B15. The device as described in B11, wherein the processing module is further used to match the network security information source according to the attack and defense technique and tactics ontology model to obtain a corresponding text object; The text object is constructed as a target entity according to the offensive and defensive technical and tactical ontology model.
[0099] B16. In the device as described in B15, the processing module is further used to determine the target entity type and the attribute items corresponding to the target entity type according to the attack and defense skills and tactics ontology model; The text object is extracted according to the target entity type and the attribute items corresponding to the target entity type to obtain the target entity.
[0100] B17, as described in B15, the processing module is further used to determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack tactic entity class or an attack technology entity class, the MITRE ATT&CK knowledge base is determined to be a text object.
[0101] B18. The device as described in B15, wherein the processing module is further used to determine entity class information according to the offensive and defensive technical and tactical ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack implementation process entity class, the network threat analysis report is determined to be a text object.
[0102] The present invention also provides a network security knowledge graph construction device, C19, the device includes: a memory, a processor, and a network security knowledge graph construction program stored in the memory and executable on the processor, the network security knowledge graph construction program is configured to implement the steps of the network security knowledge graph construction method described in any one of A1 to A10.
[0103] The present invention also provides a storage medium, D20, on which a network security knowledge graph construction program is stored. When the network security knowledge graph construction program is executed by a processor, the steps of the network security knowledge graph construction method as described in any one of A1 to A10 are implemented.
[0104] In addition, it should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.
[0105] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0106] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory (ROM) / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present invention.
[0107] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A method for constructing a network security knowledge graph. It is characterized in that The network security knowledge graph construction method comprises: Obtain network security information sources and attack and defense tactics ontology models; Determine the target entity based on the attack and defense technical and tactical ontology model and the network security information source; Determine entity relationships according to the offensive and defensive technical and tactical ontology model and the target entity; Construct a network security knowledge graph based on the target entities and entity relationships.
2. The method according to claim 1, It is characterized in that The obtaining of the attack and defense tactics ontology model includes: Construct network attack entity class, network defense entity class and entity object attributes; According to the network attack entity class and the network defense entity class configuration attribute items, obtain network attack entity class attribute items and network defense entity class attribute items; An attack and defense technique and tactic ontology model is generated according to the network attack entity class, the network defense entity class, the entity object attribute network attack entity class attribute item and the network defense entity class attribute item.
3. The method according to claim 2, It is characterized in that The network attack entity class includes: attack tactics entity class, attack technology entity class, attack implementation process entity class, asset content entity class, vulnerability entity class, simulated attack script entity class, hacker tool entity class and third-party service entity class.
4. The method according to claim 2, It is characterized in that The network defense entity class includes: a security detection product entity class, a detection data source entity class and a detection item entity class.
5. The method according to claim 1, It is characterized in that Determining the target entity according to the attack and defense technical and tactical ontology model and the network security information source includes: Matching the network security information source according to the attack and defense technique and tactics ontology model to obtain the corresponding text object; The text object is constructed as a target entity according to the offensive and defensive technical and tactical ontology model.
6. The method according to claim 5, It is characterized in that The step of constructing the text object as a target entity according to the offensive and defensive technical and tactical ontology model includes: Determine the target entity type and the attribute items corresponding to the target entity type according to the offensive and defensive technical and tactical ontology model; The text object is extracted according to the target entity type and the attribute items corresponding to the target entity type to obtain the target entity.
7. The method according to claim 5, It is characterized in that The network security information source is matched according to the attack and defense technique and tactics ontology model to obtain the corresponding text object, including: Determine entity class information according to the offensive and defensive skills and tactics ontology model; Querying a network security information source according to the entity information; When the entity class information is an attack tactic entity class or an attack technology entity class, the MITRE ATT&CK knowledge base is determined to be a text object.
8. A network security knowledge graph construction device, It is characterized in that The network security knowledge graph construction device comprises: The acquisition module is used to obtain network security information sources and attack and defense tactics ontology models; A processing module, used to determine a target entity according to the attack and defense technique and tactics ontology model and a network security information source; The processing module is further used to determine entity relationships according to the attack and defense skills and tactics ontology model and the target entity; The processing module is also used to construct a network security knowledge graph based on the target entity and entity relationship.
9. A network security knowledge graph construction device, It is characterized in that The device includes: a memory, a processor, and a network security knowledge graph construction program stored in the memory and executable on the processor, wherein the network security knowledge graph construction program is configured to implement the steps of the network security knowledge graph construction method as described in any one of claims 1 to 7.
10. A storage medium, It is characterized in that The storage medium stores a network security knowledge graph construction program, and when the network security knowledge graph construction program is executed by the processor, the steps of the network security knowledge graph construction method according to any one of claims 1 to 7 are implemented.