Network Attack Link Analysis Method, Device, Computer Equipment and Storage Medium

By obtaining the description text of network security events, using the network security knowledge graph and defense coverage threshold, combining the target entity and inputting the pre-trained model, the problem of link identification of complex network attack events is solved, and accurate network attack link analysis and defense is achieved.

CN120185920BActive Publication Date: 2025-08-05PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510593482.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-08-05
Estimated Expiration
2045-05-09

AI Technical Summary

Technical Problem

It is difficult to accurately identify the network attack links of complex cyber attack events, especially those caused by zero-day vulnerabilities and advanced persistent threats.

Method used

By obtaining the description text of the network security event, identifying the key entities, matching them with the preset network security knowledge graph, combining the network attack defense coverage and thresholds, combining the target entities, and inputting the pre-trained network security model to output the complete network attack link.

Benefits of technology

Accurate link analysis of complex cyber attack events is achieved, helping network security personnel to take comprehensive defense measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185920B_ABST
    Figure CN120185920B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a network attack link analysis method, apparatus, computer equipment, and storage medium. The method comprises determining a key entity related to a network attack in a description text corresponding to a network security event; matching the key entity with each entity of a preset network security knowledge graph to determine multiple target entities that match the key entity; determining the network attack defense coverage corresponding to each target entity, and determining a network attack defense coverage threshold corresponding to the network attack defense coverage; combining at least some of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event; inputting each partial network attack link into a pre-trained network security model to output a complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on the preset network security knowledge graph.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and specifically to a network attack link analysis method, apparatus, computer equipment, and storage medium. Background Art

[0002] With the development of computer technology and network technology, various complex network attack scenarios will appear in network security. Network attacks themselves are extremely concealed, and there are complex correlations between multiple network attacks. A complex network attack event may often contain a network attack chain composed of multiple different network attacks. Therefore, accurately identifying the network attack chain corresponding to the network attack event has become a technical problem that needs to be solved urgently.

[0003] In related technologies, when a network security system generates a security alert, the similarity between security alert logs corresponding to the same network attack event is determined. If two security alert logs are found to be similar, the network attacks corresponding to the two security alert logs are determined to be related, thereby identifying the associated attack chain. However, this method only applies to common single network attack events. For more complex network attack events, such as those caused by zero-day vulnerabilities and advanced persistent threats, this method cannot effectively analyze the network attacks and accurately determine the network attack chain corresponding to the network attack event. Summary of the Invention

[0004] The embodiments of the present application provide a network attack link analysis method, apparatus, computer equipment, and storage medium, which can accurately analyze network attack links that can lead to network security incidents.

[0005] To achieve the above objectives, an embodiment of the present application provides a network attack link analysis method, including:

[0006] Obtaining a description text corresponding to a network security event, and determining key entities related to the network attack based on the description text;

[0007] Matching the key entity with each entity of a preset network security knowledge graph to determine a plurality of target entities that match the key entity, wherein the preset network security knowledge graph includes entities corresponding to a plurality of network attack technologies and a plurality of network attack tactics, respectively;

[0008] Determining a network attack defense coverage corresponding to each target entity, and determining a network attack defense coverage threshold corresponding to the network attack defense coverage;

[0009] Combining at least some of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event;

[0010] Each partial network attack link is input into a pre-trained network security model, and a complete network attack link corresponding to the network security event is output, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

[0011] To achieve the above objectives, an embodiment of the present application provides a network attack link analysis device, including:

[0012] An acquisition module is used to obtain a description text corresponding to a network security event and determine key entities related to the network attack based on the description text;

[0013] a matching module, configured to match the key entity with each entity of a preset cybersecurity knowledge graph, and determine a plurality of target entities that match the key entity, wherein the preset cybersecurity knowledge graph includes entities corresponding to a plurality of network attack techniques and a plurality of network attack tactics, respectively;

[0014] a determination module, configured to determine a network attack defense coverage corresponding to each target entity, and determine a network attack defense coverage threshold corresponding to the network attack defense coverage;

[0015] a combining module, configured to combine at least some of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, to obtain at least one partial network attack link corresponding to the network security event;

[0016] A prediction module is used to input each partial network attack link into a pre-trained network security model and output the complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

[0017] In some embodiments, the network attack defense coverage threshold includes a single network attack defense coverage threshold and a joint network attack defense coverage threshold. A combination module is used to:

[0018] Determining a current target entity from the multiple target entities, and determining a network attack defense coverage corresponding to the current target entity;

[0019] When the network attack defense coverage corresponding to the current target entity is less than a single network attack defense coverage threshold, determining a next target entity corresponding to the current target entity from the multiple target entities, and determining the network attack defense coverage corresponding to the next target entity;

[0020] Multiplying the network attack defense coverage corresponding to the current target entity and the network attack defense coverage corresponding to the next target entity to obtain a joint network attack defense coverage;

[0021] When the joint network attack defense coverage is less than the joint network attack defense coverage threshold, determining the current target entity and the next target entity as target entities to be selected;

[0022] The next target entity is updated to the current target entity, and the execution is returned to determine the network attack defense coverage corresponding to the current target entity until the network attack defense coverage corresponding to the current target entity is not less than the single network attack defense coverage threshold, or the joint network attack defense coverage is not less than the joint network attack defense coverage threshold, and the retained target entities to be selected are combined in order to generate partial network attack links.

[0023] In some embodiments, a combination module is provided for:

[0024] After determining a current target entity from the multiple target entities and determining a network attack defense coverage corresponding to the current target entity, when the network attack defense coverage corresponding to the current target entity is not less than a single network attack defense coverage threshold, determining whether there is a target entity to be selected that is retained;

[0025] When there is no remaining target entity to be selected, an updated current target entity is determined from other target entities except the selected current target entity, and the network attack defense coverage corresponding to the updated current target entity is determined.

[0026] In some embodiments, the matching module is configured to:

[0027] Obtaining a first description text corresponding to the key entity, and inputting the first description text into a pre-trained text processing model to output a first feature corresponding to the key entity;

[0028] Obtain a second description text corresponding to each entity in a preset network security knowledge graph, input the second description text into the pre-trained text processing model, and output a second feature corresponding to each entity;

[0029] The similarity between the first feature and each of the second features is determined, and an entity corresponding to a second feature whose similarity is greater than a preset similarity threshold is determined as a target entity matching the key entity.

[0030] In some embodiments, the matching module is configured to:

[0031] Before matching the key entity with each entity of a preset network security knowledge graph and determining a plurality of target entities matching the key entity, obtaining network security attributes corresponding to a plurality of network devices from a network attack chain knowledge base, and generating a plurality of first entities according to each network device and the network security attributes;

[0032] Determining, in the network attack chain knowledge base according to preset network security rules, target technologies, target tactics, network attack defense measures, and defense coverage for each network attack chain, and generating a plurality of second entities according to the target technologies, target tactics, network attack defense measures, and defense coverage for each attack chain;

[0033] Obtaining multiple techniques and multiple tactics from a network attack technique and tactics database, and obtaining constraint conditions corresponding to the multiple techniques and multiple tactics;

[0034] hierarchically associating the plurality of technologies and the plurality of tactics according to the constraint conditions to obtain a plurality of associated technologies and tactics, and generating a plurality of third entities according to the associated technologies and tactics;

[0035] Acquire entity relationships among the plurality of first entities, the plurality of second entities, and the plurality of third entities according to the network attack chain knowledge base and the network attack technique and tactics database;

[0036] A preset network security knowledge graph is constructed based on the entity relationship, the multiple first entities, the multiple second entities and the multiple third entities.

[0037] In some embodiments, the determining module is configured to:

[0038] Obtain multiple defense coverages corresponding to each target entity and determine the weight value corresponding to each defense coverage;

[0039] The weight value corresponding to each defense coverage is multiplied by each defense coverage and then added together to obtain the network attack defense coverage corresponding to each target entity.

[0040] In some embodiments, the network attack link analysis device further includes a training module for:

[0041] Before inputting the at least one partial network attack link into the pre-trained network security model and outputting at least one complete network attack link, determining sample technologies and sample tactics corresponding to the sample network attack link and sample entity relationships between the sample technologies and the sample tactics according to the preset network security knowledge graph;

[0042] Generate sample prompt text according to the sample tactics, the sample technology and the sample entity relationship, input the sample prompt text into a network security model, and output a predicted network attack link;

[0043] The difference between the predicted network attack link and the sample network attack link is determined, and the network security model is trained according to the difference to obtain a trained pre-trained network security model.

[0044] In some embodiments, the prediction module is further configured to:

[0045] Obtaining an attack success rate corresponding to each complete network attack link, and determining a target complete network attack link whose attack success rate is greater than a preset attack success rate;

[0046] A target network attack defense measure corresponding to the target complete network attack link is generated according to the target tactics and target technology corresponding to the target complete network attack link.

[0047] In order to achieve the above-mentioned objectives, an embodiment of the present application provides a computer-readable storage medium on the one hand, which stores multiple instructions, and the instructions are suitable for a processor to load to execute the network attack link analysis method provided by the embodiment of the present application.

[0048] In order to achieve the above-mentioned objectives, an embodiment of the present application provides, on the one hand, a computer device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor executes the computer program, the network attack link analysis method provided in the embodiment of the present application is implemented.

[0049] In an embodiment of the present application, a description text corresponding to a network security event is obtained, and key entities related to the network attack are determined based on the description text; the key entity is matched with each entity of a preset network security knowledge graph, and multiple target entities matching the key entity are determined, wherein the preset network security knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics respectively; the network attack defense coverage corresponding to each target entity is determined, and the network attack defense coverage threshold corresponding to the network attack defense coverage is determined; at least part of the target entities are combined according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, to obtain at least one partial network attack link corresponding to the network security event; each partial network attack link is input into a pre-trained network security model, and a complete network attack link corresponding to the network security event is output, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

[0050] In this way, by determining the key entities related to the network attack in the description text of the network security event, and then matching them with the preset network security knowledge graph, a plurality of target entities matching the key entities are obtained, and then the network attack defense coverage corresponding to each target entity is determined, and the network attack defense coverage threshold corresponding to the network attack defense coverage is determined. At least part of the target entities are combined according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, and at least one partial network attack link corresponding to the network security event is obtained. In this way, the partial network attack link is determined, and then each partial network attack link is input into the pre-trained network security model to output the complete network attack link corresponding to the network security event. Compared with the related art that determines similar attack links by the similarity of alarm logs, the present application can accurately combine at least part of the target entities through the network attack defense coverage and the network attack defense coverage threshold to obtain the partial network attack link corresponding to the network security event, and at the same time input the partial network attack link into the pre-trained network security model to output the complete network attack link corresponding to the network security event, thereby accurately predicting the complete network attack link that can cause network security time, thereby helping network security personnel to take more comprehensive network security defense measures for network security events.

[0051] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0053] Figure 1 This is a schematic diagram of the system framework corresponding to the network attack link analysis method provided in an embodiment of the present application;

[0054] Figure 2 This is a scenario diagram of the network attack link analysis method provided by an embodiment of the present application;

[0055] Figure 3 This is a flow chart of a network attack link analysis method provided by an embodiment of the present application;

[0056] Figure 4 This is another flowchart of the network attack link analysis method provided by an embodiment of the present application;

[0057] Figure 5 This is a schematic diagram of the structure of a network attack link analysis device provided by an embodiment of the present application;

[0058] Figure 6 It is a structural diagram of the computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0059] In order to enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of this application.

[0060] It is understandable that in the specific implementation of this application, network security event data, alarm logs and other related data are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards.

[0061] It should be noted that some processes described in the specification, claims, and figures above include multiple steps that appear in a specific order. However, it should be understood that these steps may be executed in a different order than the order in which they appear herein or in parallel. The step numbers are used solely to distinguish between the different steps and do not themselves represent any order of execution. Furthermore, terms such as "first," "second," or "target" are used herein to distinguish similar objects and are not necessarily used to describe a specific order or precedence.

[0062] The embodiments of the present application provide a network attack link analysis method, device, computer equipment and storage medium. Specifically, the embodiments of the present application will be described from the perspective of the network attack link analysis device, which can be integrated into a computer device, which can be a server or a terminal. Among them, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. Among them, the terminal can be a smart phone, tablet computer, laptop computer, desktop computer, smart speaker, smart watch, smart home appliance, car terminal, intelligent voice interaction device, aircraft, etc., but is not limited to this. The embodiments of the present application can be applied to various scenarios, including but not limited to network security, cloud security scenarios, etc.

[0063] Before further explaining the embodiments of the present application in detail, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are subject to the following interpretations:

[0064] Technique: Attack technology refers to the specific technical means used by attackers in the process of implementing attacks, such as using specific tools, scripts or codes to achieve the attack objectives.

[0065] Tactics: Attack tactics are a higher-level plan. They are a series of strategic actions taken by attackers to achieve their goals (such as obtaining data or destroying systems). They include selecting attack targets, timing, and combining multiple attack techniques.

[0066] Knowledge Graph: A knowledge graph is a semantic network with extremely strong expressive power and modeling flexibility. Essentially, it is a semantic knowledge base that symbolically depicts various real-world concepts and their relationships. Its basic unit is the "entity-relationship-entity" triple. A knowledge graph can be viewed as a graph consisting of nodes and edges. Nodes represent entities or concepts in the physical world, while edges represent the various semantic relationships between entities or concepts. This graph structure clearly demonstrates the complex connections between various entities and integrates fragmented knowledge into an organic whole.

[0067] The above is the definition of the relevant professional terms involved in this application. If other professional terms are involved later, they will be explained later.

[0068] First, let’s describe the technical problems existing in related technologies:

[0069] With the development of computer technology and network technology, various complex network attack scenarios will appear in network security. Network attacks themselves are extremely concealed, and there are complex correlations between multiple network attacks. A complex network attack event may often contain a network attack chain composed of multiple different network attacks. Therefore, accurately identifying the network attack chain corresponding to the network attack event has become a technical problem that needs to be solved urgently.

[0070] In related technologies, when a network security system generates a security alert, the similarity between security alert logs corresponding to the same network attack event is determined. If two security alert logs are found to be similar, the network attacks corresponding to the two security alert logs are determined to be related, thereby identifying the associated attack chain. However, this method only applies to common single network attack events. For more complex network attack events, such as those caused by zero-day vulnerabilities and advanced persistent threats, this method cannot effectively analyze the network attacks and accurately determine the network attack chain corresponding to the network attack event.

[0071] In order to solve the above technical problems, the embodiments of the present application provide a network attack link analysis method, device, computer equipment and storage medium. Among them, by determining the key entities related to the network attack in the description text of the network security event, and then matching with the preset network security knowledge graph, a plurality of target entities matching the key entities are obtained, and then the network attack defense coverage corresponding to each target entity is determined, and the network attack defense coverage threshold corresponding to the network attack defense coverage is determined. According to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, at least part of the target entities are combined to obtain at least one partial network attack link corresponding to the network security event, thereby determining the partial network attack link, and then inputting each partial network attack link into the pre-trained network security model to output the complete network attack link corresponding to the network security event. Compared with the related art of determining similar attack links through the similarity of alarm logs, the present application can accurately combine at least part of the target entities through network attack defense coverage and network attack defense coverage threshold to obtain partial network attack links corresponding to network security events. At the same time, the partial network attack links are input into the pre-trained network security model to output the complete network attack links corresponding to the network security events, thereby accurately predicting the complete network attack links that can cause network security time, so as to help network security personnel take more comprehensive network security defense measures for network security events.

[0072] The network attack link analysis method, apparatus, computer equipment, and storage medium provided in the embodiments of the present application will be described in detail below.

[0073] See also Figure 1 , Figure 1 Schematic diagram of the system framework corresponding to the network attack link analysis method provided in the embodiment of the present application. The network attack link analysis method provided in the embodiment of the present application can be applied to this system framework.

[0074] It includes a terminal 140, the Internet 130, a gateway 120, a server 110, and the like.

[0075] The terminal 140 or the server 110 may be a device for executing the network attack link analysis method.

[0076] Terminal 140 includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, and the like. Embodiments of the present application can be applied in various scenarios, including, but not limited to, cloud office and enterprise management. Furthermore, it can be a single device or a combination of multiple devices. For example, multiple desktop computers connected via a local area network, sharing a common display and working collaboratively, collectively constitute a terminal 140. Terminal 140 can communicate with Internet 130 via wired or wireless means to exchange data.

[0077] Server 110 refers to a computer system that provides certain services to terminal 140. Compared to ordinary terminal 140, server 110 has higher requirements in terms of stability, security, and performance. Server 110 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0078] Gateway 120, also known as a gateway or protocol converter, implements network interconnection at the transport layer and is a computer system or device that performs a conversion function. It acts as a translator between two systems using different communication protocols, data formats, languages, or even completely different architectures. Gateways can also provide filtering and security functions. Messages sent from terminal 140 to server 110 are sent through gateway 120 to the corresponding server 110. Messages sent from server 110 to terminal 140 are also sent through gateway 120 to the corresponding terminal 140.

[0079] The network attack link analysis method in the embodiment of the present application can be applied in a variety of scenarios, such as cloud services, network security, etc. The scenario to which the network attack link analysis method in the present application is applied is not limited here.

[0080] See also Figure 2 , Figure 2 This is a scenario diagram of the network attack link analysis method provided in an embodiment of the present application.

[0081] like Figure 2 As shown, when a network security event is received, the alarm system will generate an alarm log. The object can determine the network security event based on the alarm log and describe the network security event to generate a description text.

[0082] Key entities related to network attacks can be determined based on the description text. For example, keywords related to network security can be extracted, and then the extracted keywords are used as key entities.

[0083] The key entity is then matched with each entity in a preset cybersecurity knowledge graph to determine multiple target entities that match the key entity. The preset cybersecurity knowledge graph includes entities corresponding to multiple cyberattack techniques and multiple cyberattack tactics. For example, similarity calculations can be performed between the key entity and each entity in the preset cybersecurity knowledge graph to obtain multiple target entities that match the key entity.

[0084] Then, the network attack defense coverage corresponding to each target entity is determined, as well as the network attack defense coverage threshold corresponding to the network attack defense coverage. Each target entity can serve as the entity corresponding to the next attack step of the key entity in the attack chain. Therefore, the target entities can be screened by the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold corresponding to the network attack defense coverage.

[0085] Then, at least some of the target entities are combined based on the network attack defense coverage and the network attack defense coverage threshold corresponding to each target entity to obtain at least one partial network attack link corresponding to the network security incident. For example, the selected target entities are combined in a certain order to generate at least one partial network attack link corresponding to the network security incident.

[0086] Finally, each partial network attack chain is input into a pre-trained network security model, which outputs the complete network attack chain corresponding to the network security incident. The pre-trained network security model is trained based on multiple entities and the relationships between them within a pre-set network security knowledge graph. For example, the pre-trained network security model can combine learned network security knowledge to identify potential associated attack chains for each partial network attack chain, thereby predicting and completing the partial attack chain to obtain the complete attack chain. Subsequently, network security personnel can use this complete attack chain to implement defensive measures for the network security incident and ensure network security.

[0087] The network attack link analysis method provided in this application will be introduced in detail later.

[0088] See also Figure 3 , Figure 3 : This is a flow chart of a network attack link analysis method provided by an embodiment of the present application. The network attack link analysis method may include the following steps:

[0089] Step 210: Obtain a description text corresponding to the network security event, and determine key entities related to the network attack based on the description text;

[0090] Step 220: Match the key entity with each entity of a preset cybersecurity knowledge graph to determine multiple target entities that match the key entity, wherein the preset cybersecurity knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics, respectively.

[0091] Step 230: Determine the network attack defense coverage corresponding to each target entity, and determine a network attack defense coverage threshold corresponding to the network attack defense coverage;

[0092] Step 240: Combine at least some of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event;

[0093] Step 250: Input each partial network attack link into a pre-trained network security model, and output a complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on multiple entities contained in a preset network security knowledge graph and the entity relationships between different entities.

[0094] Steps 210 to 250 will be described in detail below.

[0095] In step 210, a description text corresponding to the network security event is obtained, and key entities related to the network attack are determined based on the description text.

[0096] When a network security incident occurs, such as anomalies in network traffic or advanced persistent threats, the security system issues an alert and generates an alert log. Upon receiving the alert, the user can create a descriptive text describing the network security incident based on the description in the alert log. This descriptive text can be understood as a comprehensive description of various attributes, including the time of occurrence, scope of impact, characteristics of the attack, and duration of the attack, objectively describing the network security incident.

[0097] After receiving the descriptive text of a cybersecurity incident from the subject, the computer device can analyze the descriptive text to identify key entities related to the cyberattack. For example, the descriptive text can be segmented to obtain multiple subtexts, each of which contains certain semantic information. The multiple subtexts can then be filtered, such as by filtering for stop words, modal particles, and words without actual semantic meaning, to obtain multiple target subtexts.

[0098] The semantics of each target subtext are then analyzed to determine whether it is related to cyberattacks. For example, if the target subtext is "Technical Number T108," it is related to cyberattacks and is considered a key entity related to cyberattacks. Another example is if the target subtext is "Abnormal Traffic," which is also related to cyberattacks and is considered a key entity related to cyberattacks. This method can filter out key entities related to cyberattacks from multiple target subtexts.

[0099] In some embodiments, before matching the key entity with each entity of the preset network security knowledge graph and determining multiple target entities matching the key entity, the method further includes:

[0100] (1.1) Obtaining network security attributes corresponding to a plurality of network devices from a network attack chain knowledge base, and generating a plurality of first entities based on each network device and the network security attribute;

[0101] (1.2) determining the target technology, target tactics, network attack defense measures, and defense coverage of each network attack chain in the network attack chain knowledge base according to preset network security rules, and generating multiple second entities based on the target technology, target tactics, network attack defense measures, and defense coverage of each attack chain;

[0102] (1.3) Obtaining multiple techniques and tactics from a cyber attack technique and tactic database, and obtaining constraints corresponding to the multiple techniques and tactics;

[0103] (1.4) hierarchically associating the multiple technologies and the multiple tactics according to the constraint conditions to obtain multiple associated technologies and tactics, and generating multiple third entities based on the associated technologies and tactics;

[0104] (1.5) Obtaining entity relationships among the plurality of first entities, the plurality of second entities, and the plurality of third entities based on a cyber attack chain knowledge base and a cyber attack technique and tactics database;

[0105] (1.6) Constructing a preset cybersecurity knowledge graph based on entity relationships, multiple first entities, multiple second entities, and multiple third entities.

[0106] Among them, the network attack chain knowledge base is a knowledge base that collects real network attack chains. It contains multiple effective network attack chains, as well as the network attack techniques and tactics corresponding to the network attack chains. It also includes some security attributes of network devices, such as IP addresses, asset types, domain names, active time, etc.

[0107] The network security attributes corresponding to multiple network devices can be obtained from the network attack chain knowledge base, and multiple first entities can be generated based on each network device and network security attribute. For example, the security attributes of the network device can be confirmed. For example, assets on the Internet include asset type, credibility, domain name, last active time, IP value, vulnerability, and other security attributes. These attributes can be used as the first entity.

[0108] The security attributes of each network device can then be associated and enhanced with the network device to obtain associated first entities. These first entities have certain entity relationships. For example, the entity relationship for a first entity associated with a network device can be represented as follows: the entity type, trustworthiness, asset type, domain name, physical address, vulnerabilities, and weaknesses of network device A. These first entities are associated to form an entity relationship between network device A and the first entity.

[0109] For each network device, these first entities can be associated with the corresponding network device and can accurately express the network security situation of the network device.

[0110] Then, according to the preset network security rules, the target technology, target tactics, network attack defense measures and defense coverage of each network attack chain are determined in the network attack chain knowledge base, and multiple second entities are generated according to the target technology, target tactics, network attack defense measures and defense coverage of each attack chain.

[0111] Among them, the preset network security rules can be rules written by experts in the field of network security. These rules can realize the association between technology and technology, technology and tactics, and tactics and tactics.

[0112] For example, a cyberattack chain includes relevant targeted attack techniques and targeted attack tactics. The corresponding cyberattack defense measures can be determined, along with the defense coverage for each targeted attack technique and tactic. The target techniques, target tactics, cyberattack defense measures, and defense coverage for each attack chain are then considered the second entity.

[0113] For example, consider a pre-set cybersecurity rule that specifies that attack sub-technique a1 is a sub-technique of attack main technique A, which has a corresponding defense coverage of X. The constraint is that the ID prefix of the attack sub-technique must match the attack main technique. This rule enables integration between secondary entities and constraints between different entities. For another example, strict constraints are placed on the numbering of attack main techniques to ensure compliance with standards (for example, ATT&CK numbers begin with a T followed by four digits). Constraints on attack sub-techniques in pre-set cybersecurity rules include: mitigation by a certain defense measure, association with the defense measure's coverage, and the corresponding attack sub-technique.

[0114] Then, based on the constraints, multiple technologies and tactics are hierarchically associated to obtain multiple associated technologies and tactics, and multiple third entities are generated based on the associated technologies and tactics. The constraints may include that attack sub-techniques must be associated with attack main technologies, and that attack tactics must be associated with attack technologies.

[0115] For example, there are corresponding entity relationships between multiple technologies and tactics, such as the target attack technology associated with the target attack tactics, the target attack sub-techniques associated with the target attack technology, the defense coverage associated with the target attack technology, the network attack defense measures associated with the target attack technology, and so on. These entities can be further refined through hierarchical associations. For example, a certain attack sub-technique belongs to a certain main attack technology, and this attack sub-technique corresponds to multiple exploitable network security vulnerabilities. Based on these entity relationships, different entities can be associated, and these associated entities serve as third entities.

[0116] Finally, a preset network security knowledge graph is constructed based on entity relationships, multiple first entities, multiple second entities, and multiple third entities. For example, in the above content, there is an entity relationship between the first entities, an entity relationship between the second entities, and an entity relationship between the third entities. At least some of the first entities, second entities, and third entities are the same. Then, the entity relationships of the multiple first entities, multiple second entities, and multiple third entities can be further sorted out based on the entity relationships to obtain the final entity relationships corresponding to the multiple first entities, multiple second entities, and multiple third entities. The repeated entities in the multiple first entities, multiple second entities, and multiple third entities are merged to obtain multiple entities to be selected. Each entity to be selected can be used as a node, and the entity relationships between the entities to be selected can be used as edges. The preset network security knowledge graph can be constructed through nodes and edges.

[0117] From the above content, it can be seen that in this application, the network security knowledge from different data sources is integrated to generate the final preset network security knowledge graph. Since the preset network security rules and constraints are set in the preset network security knowledge graph, the association between different entities in the preset network security knowledge graph is realized, which can better express the network security knowledge corresponding to different source databases.

[0118] In step 220, the key entity is matched with each entity of a preset network security knowledge graph to determine multiple target entities that match the key entity, wherein the preset network security knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics.

[0119] Among them, the key entity can be matched with each entity in the preset network security knowledge graph to determine the similarity between the key entity and each entity, and then the entity with a similarity greater than a preset similarity threshold is determined as the target entity matching the key entity.

[0120] In some embodiments, the key entity is matched with each entity of a preset network security knowledge graph to determine multiple target entities that match the key entity, including:

[0121] (1.1) Obtain the first description text corresponding to the key entity, input the first description text into the pre-trained text processing model, and output the first feature corresponding to the key entity;

[0122] (1.2) Obtaining a second description text corresponding to each entity in a preset cybersecurity knowledge graph, inputting the second description text into a pre-trained text processing model, and outputting a second feature corresponding to each entity;

[0123] (1.3) Determine the similarity between the first feature and each second feature, and determine the entity corresponding to the second feature whose similarity is greater than a preset similarity threshold as a target entity matching the key entity.

[0124] Here, a first description text corresponding to the key entity can be obtained. The first description text can be related introductory text corresponding to the key entity. The first description text is then input into a pre-trained text processing model to output the first feature corresponding to the key entity. For example, the pre-trained text processing model can encode the first description text to generate a corresponding encoding vector, which is the first feature corresponding to the key entity.

[0125] Then, the second description text corresponding to each entity in the preset cybersecurity knowledge graph is obtained. The second description text can be text that introduces each entity. For example, if an entity is a technology number, the second description text can be the relevant introduction text corresponding to the technology number. Similarly, for entities in the preset cybersecurity knowledge graph, the corresponding second description text is also its relevant introduction text.

[0126] The second description text is then input into the pre-trained text processing model to output the second feature corresponding to each entity. For example, the pre-trained text processing model can encode the second description text to generate a corresponding encoding vector, which is the second feature corresponding to the entity.

[0127] Finally, the similarity between the first feature and each second feature is determined, and the entity corresponding to the second feature whose similarity is greater than a preset similarity threshold is determined as the target entity that matches the key entity. For example, the cosine similarity between the first feature and each second feature can be calculated, and then the cosine similarity can be used as the similarity between the first feature and the second feature. Finally, the entity corresponding to the second feature whose similarity is greater than the preset similarity threshold is determined as the target entity that matches the key entity.

[0128] It should be noted that the preset cybersecurity knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics. The preset cybersecurity knowledge graph can be generated based on multiple cybersecurity knowledge data sources, such as the Attack Technology and Tactics Database (ATT&CK), the network threat database, the network attack chain knowledge base, etc.

[0129] In step 230, the network attack defense coverage corresponding to each target entity is determined, and a network attack defense coverage threshold corresponding to the network attack defense coverage is determined.

[0130] Among them, the network attack defense coverage corresponding to each target entity can be determined based on multiple defense coverages. The defense coverage is a security score for each target entity under different evaluation criteria. When the defense coverage is high, it means that the success rate of the network attack against the target entity is low and the security score is high; when the defense coverage is low, it means that the success rate of the network attack against the target entity is high and the security score is low.

[0131] In some embodiments, determining the network attack defense coverage corresponding to each target entity includes:

[0132] (1.1) Obtain multiple defense coverages corresponding to each target entity and determine the weight value corresponding to each defense coverage;

[0133] (1.2) Multiply the weight value corresponding to each defense coverage by each defense coverage and add the results together to obtain the network attack defense coverage corresponding to each target entity.

[0134] The multiple defense coverage levels for each target entity can be understood as being determined by different cybersecurity experts using different evaluation criteria. Each defense coverage level is assigned a weight, and the sum of these weights equals 1.

[0135] The weighted value for each defense coverage is then multiplied by the corresponding defense coverage, and the resulting sum is added to obtain the network attack defense coverage for each target entity. This integrates the different defense coverages, resulting in a more objective and comprehensive calculation of the network attack defense coverage for each target entity. Network attack defense coverage can be understood as the probability that a target entity can defend against a network attack. The value range of network attack defense coverage is [0, 1].

[0136] Network attack defense coverage corresponds to a network attack defense coverage threshold, which can be understood as the minimum probability of successfully defending against a network attack. This threshold includes a single network attack defense coverage threshold and a combined network attack defense coverage threshold. The single network attack defense coverage threshold represents the minimum probability of successfully defending against a single network attack, while the combined network attack defense coverage threshold represents the minimum probability of successfully defending against multiple network attacks.

[0137] In step 240, at least some of the target entities are combined according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event.

[0138] Among them, one entity can be selected from multiple target entities as the current target entity, and then a next target entity can be selected from the remaining multiple target entities. The current target entity can be understood as the entity corresponding to the current network attack step, which can be a network attack technology or a network attack tactic; the next target entity can be understood as the entity corresponding to the next network attack step, which can be a network attack technology or a network attack tactic.

[0139] If the network attack defense coverage corresponding to the next target entity is less than the single network attack defense coverage threshold, then the network attack corresponding to the next target entity has a higher probability of success. If the network attack defense coverage corresponding to the next target entity is not less than the single network attack defense coverage threshold, then the network attack corresponding to the next target entity has a lower probability of success.

[0140] Similarly, according to the selection order of the target entities, multiple target entities can be determined and combined to obtain at least one partial network attack link corresponding to the network security event.

[0141] In some embodiments, combining at least some of the target entities according to the network attack defense coverage and the network attack defense coverage threshold corresponding to each target entity to obtain at least one partial network attack link corresponding to the network security event includes:

[0142] (1.1) Identify a current target entity among multiple target entities and determine the network attack defense coverage corresponding to the current target entity;

[0143] (1.2) When the network attack defense coverage corresponding to the current target entity is less than a single network attack defense coverage threshold, determining the next target entity corresponding to the current target entity from among multiple target entities, and determining the network attack defense coverage corresponding to the next target entity;

[0144] (1.3) Multiply the network attack defense coverage corresponding to the current target entity and the network attack defense coverage corresponding to the next target entity to obtain the joint network attack defense coverage;

[0145] (1.4) When the joint network attack defense coverage is less than the joint network attack defense coverage threshold, the current target entity and the next target entity are determined as target entities to be selected;

[0146] (1.5) The next target entity is updated to the current target entity, and the process returns to determine the network attack defense coverage corresponding to the current target entity. When the network attack defense coverage corresponding to the current target entity is not less than the single network attack defense coverage threshold, or the joint network attack defense coverage is not less than the joint network attack defense coverage threshold, the remaining target entities to be selected are combined in order to generate a partial network attack link.

[0147] For example, a current target entity is determined among multiple target entities, and is used as the entity corresponding to the initial attack step. The network attack defense coverage corresponding to the current target entity is determined, which can be expressed as C(pi).

[0148] When the network attack defense coverage C(pi) corresponding to the current target entity is less than the single network attack defense coverage threshold α, it means that the network attack corresponding to the current target entity has a high probability of success, and the current target entity is retained.

[0149] Then, the next target entity corresponding to the current target entity is determined among multiple target entities, and the network attack defense coverage corresponding to the next target entity is determined. For example, the network attack defense coverage corresponding to the next target entity is C(pi+1).

[0150] Then multiply the network attack defense coverage corresponding to the current target entity and the network attack defense coverage corresponding to the next target entity to obtain the joint network attack defense coverage, that is, C(pi) multiplied by C(pi+1) to obtain the joint network attack defense coverage JC(pi, pi+1).

[0151] When the joint network attack defense coverage JC(pi, pi+1) is less than the joint network attack defense coverage threshold β, the current target entity and the next target entity are determined as the target entities to be selected.

[0152] The next target entity is then updated to the current target entity, and the process returns to determine the network attack defense coverage corresponding to the current target entity. This process continues until the network attack defense coverage C(pi) corresponding to the current target entity is no less than the single network attack defense coverage threshold α, or the joint network attack defense coverage JC(pi, pi+1) is no less than the joint network attack defense coverage threshold β. The remaining target entities to be selected are then combined in order to generate a partial network attack chain. For example, the target entities are combined in the order in which they were selected to form a partial network attack chain.

[0153] In some embodiments, after determining a current target entity from a plurality of target entities and determining the network attack defense coverage corresponding to the current target entity, the method further includes:

[0154] (2.1) When the network attack defense coverage corresponding to the current target entity is not less than the single network attack defense coverage threshold, determine whether there is a target entity to be selected;

[0155] (2.2) When there is no remaining target entity to be selected, an updated current target entity is determined from among target entities other than the selected current target entity, and the network attack defense coverage corresponding to the updated current target entity is determined.

[0156] When the network attack defense coverage corresponding to the current target entity is not less than the single network attack defense coverage threshold, and when there are no remaining target entities to be selected, the network attack corresponding to the current target entity cannot succeed. At this time, a target entity corresponding to the initial network attack step is reselected from the multiple target entities. That is, an updated current target entity is determined from the target entities other than the selected current target entity, and the network attack defense coverage corresponding to the updated current target entity is determined. Then, the above target entity screening step (1.2) is executed again until a partial network attack link is obtained.

[0157] It should be noted that in this application, the single network attack defense coverage threshold and the joint network attack defense coverage threshold can be dynamically adjusted to adjust the number of partial network attack links obtained. Adjusting the single network attack defense coverage threshold α will affect the number of partial network attack links ultimately generated. Increasing the single network attack defense coverage threshold α means that more target entities will be considered as part of a potential valid network attack path, and therefore more partial network attack links may be generated.

[0158] For example, suppose three consecutive target entities A, B, and C are found based on a pre-defined cybersecurity knowledge graph. Their corresponding network attack defense coverage is C(A) = 0.25, C(B) = 0.4, and C(C) = 0.6, respectively. Let the single network attack defense coverage threshold α be 0.3, and the joint network attack defense coverage threshold β be 0.15.

[0159] Since C(A) < α, it is selected as the target entity. Calculating the product of the network attack defense coverage of A and B yields the joint network attack defense coverage JC(A, B) = 0.25 × 0.4 = 0.1. Since 0.1 < β, A and B are selected as the target entities.

[0160] Next, we check the joint network attack defense coverage from B to C, JC(B,C) = 0.4×0.6=0.24. Since 0.24>β, the network attack process from B to C is not established, and the target entity C is not retained.

[0161] Ultimately, based on the set α and β, we may obtain a partial network attack link that includes A and B but does not include C.

[0162] From the above content, it can be seen that by setting a single network attack defense coverage threshold and a joint network attack defense coverage threshold, and determining the network attack defense coverage of each target entity, it is possible to accurately screen out some network attack links consisting of target entities that can carry out network attacks.

[0163] In some embodiments, before inputting at least one partial network attack link into a pre-trained network security model and outputting at least one complete network attack link, the method further includes:

[0164] (1.1) Determine the sample technologies and sample tactics corresponding to the sample network attack links, as well as the sample entity relationships between the sample technologies and sample tactics, based on the preset network security knowledge graph;

[0165] (1.2) Generate sample prompt text based on sample tactics, sample techniques, and sample entity relationships, and input the sample prompt text into the network security model to output the predicted network attack link;

[0166] (1.3) Determine the difference between the predicted network attack link and the sample network attack link, and train the network security model based on the difference to obtain a pre-trained network security model.

[0167] Among them, the pre-trained network security model is trained based on the preset network security knowledge graph, and multiple sample network attack links can be determined first. Since the preset network security knowledge graph contains multiple network attack tactics and multiple network attack technologies and the relationship between them, the sample technology, sample tactics and sample entity relationship between sample technologies and sample tactics corresponding to each sample network attack link can be determined according to the preset network security knowledge graph.

[0168] Based on the sample tactics, sample techniques, and sample entity relationships, sample prompt text is generated and fed into the network security model to output a predicted network attack chain. For example, multiple sample prompt texts can be generated using different prompt templates. Each sample prompt text is then fed into the network security model, which then outputs the corresponding predicted network attack chain.

[0169] The difference between the predicted network attack chain and the sample network attack chain is then determined, and the network security model is trained based on this difference, resulting in a pre-trained network security model. For example, if the difference between the predicted network attack chain and the sample network attack chain is significant, the prompt text can be adjusted to achieve more accurate information input, allowing the network model to learn more about the network attack techniques and tactics in the pre-set network security knowledge graph. This is done until the difference between the predicted network attack chain and the sample network attack chain output by the network security model in subsequent training is small. This completes the network security model training, resulting in a trained network security model.

[0170] In step 250, each partial network attack link is input into a pre-trained network security model, and a complete network attack link corresponding to the network security event is output, wherein the pre-trained network security model is trained based on multiple entities contained in a preset network security knowledge graph and the entity relationships between different entities.

[0171] In this application, the pre-trained network security model is trained based on multiple entities contained in a preset network security knowledge graph and the entity relationships between different entities. Therefore, the pre-trained network attack model has learned relevant knowledge about the network attack link in the preset network security knowledge graph.

[0172] By inputting each partial network attack link into the pre-trained network security model, the complete network attack link corresponding to the network security incident is output. In this way, multiple predicted complete network attack links corresponding to the network security incident are obtained.

[0173] The pre-trained cybersecurity model is trained based on multiple entities and the relationships between them within a pre-set cybersecurity knowledge graph. Because the pre-set cybersecurity knowledge graph includes knowledge about different cyberattack techniques and tactics, as well as knowledge about known cyberattack links, the cybersecurity model can learn from this knowledge, resulting in a pre-trained cybersecurity model capable of predicting cyberattack links.

[0174] In some embodiments, after inputting at least one partial network attack link into a pre-trained network security model and outputting at least one complete network attack link, the method further includes:

[0175] (1.1) Obtain the attack success rate corresponding to each complete network attack link, and determine the target complete network attack link whose attack success rate is greater than the preset attack success rate;

[0176] (1.2) Generate target network attack defense measures corresponding to the target complete network attack chain based on the target tactics and target technologies corresponding to the target complete network attack chain.

[0177] Among them, the attack success rate corresponding to each complete network attack link can be obtained. For example, the network attack defense coverage of the entity corresponding to each network attack step in each complete network attack link can be determined, denoted as C, and the network attack success rate of the entity corresponding to each network attack step can be obtained by 1-C. Then, the network attack success rates of the entities corresponding to each network attack step are added to obtain the added result, and then the added result is divided by the number of attack steps corresponding to each complete network attack link to obtain the attack success rate corresponding to each complete network attack link.

[0178] Then determine the target complete network attack link with an attack success rate greater than the preset attack success rate, for example, the attack success rate must be greater than 70%.

[0179] Finally, based on the target tactics and target technologies corresponding to the complete network attack chain, the target network attack defense measures corresponding to the complete network attack chain are generated. For example, the complete network attack chain can be sent to network security experts for security assessment to determine the target network attack defense measures corresponding to the complete network attack chain. Alternatively, the complete network attack chain can be input into a pre-trained network attack defense model to output the target network attack defense measures corresponding to the complete network attack chain.

[0180] In an embodiment of the present application, a description text corresponding to a network security event is obtained, and key entities related to the network attack are determined based on the description text; the key entity is matched with each entity of a preset network security knowledge graph, and multiple target entities matching the key entity are determined, wherein the preset network security knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics respectively; the network attack defense coverage corresponding to each target entity is determined, and the network attack defense coverage threshold corresponding to the network attack defense coverage is determined; at least part of the target entities are combined according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, to obtain at least one partial network attack link corresponding to the network security event; each partial network attack link is input into a pre-trained network security model, and a complete network attack link corresponding to the network security event is output, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

[0181] In this way, by determining the key entities related to the network attack in the description text of the network security event, and then matching them with the preset network security knowledge graph, a plurality of target entities matching the key entities are obtained, and then the network attack defense coverage corresponding to each target entity is determined, and the network attack defense coverage threshold corresponding to the network attack defense coverage is determined. At least part of the target entities are combined according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, and at least one partial network attack link corresponding to the network security event is obtained. In this way, the partial network attack link is determined, and then each partial network attack link is input into the pre-trained network security model to output the complete network attack link corresponding to the network security event. Compared with the related art that determines similar attack links by the similarity of alarm logs, the present application can accurately combine at least part of the target entities through the network attack defense coverage and the network attack defense coverage threshold to obtain the partial network attack link corresponding to the network security event, and at the same time input the partial network attack link into the pre-trained network security model to output the complete network attack link corresponding to the network security event, thereby accurately predicting the complete network attack link that can cause network security time, thereby helping network security personnel to take more comprehensive network security defense measures for network security events.

[0182] See also Figure 4 , Figure 4 This is another flow chart of the network attack link analysis method provided by an embodiment of the present application. The network attack link analysis method may include the following steps:

[0183] Step 301: Match the key entity with each entity of a preset network security knowledge graph to determine multiple target entities that match the key entity, wherein the preset network security knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics.

[0184] Step 302: Determine the network attack defense coverage corresponding to each target entity, and determine the network attack defense coverage threshold corresponding to the network attack defense coverage;

[0185] Step 303: Determine a current target entity from among multiple target entities, and determine the network attack defense coverage corresponding to the current target entity;

[0186] Step 304: When the network attack defense coverage corresponding to the current target entity is less than the single network attack defense coverage threshold, a next target entity corresponding to the current target entity is determined from among the multiple target entities, and the network attack defense coverage corresponding to the next target entity is determined;

[0187] Step 305: Multiply the network attack defense coverage corresponding to the current target entity and the network attack defense coverage corresponding to the next target entity to obtain a joint network attack defense coverage;

[0188] Step 306: When the joint network attack defense coverage is less than the joint network attack defense coverage threshold, the current target entity and the next target entity are determined as target entities to be selected;

[0189] Step 307: Update the next target entity to the current target entity, and return to determine the network attack defense coverage corresponding to the current target entity. When the network attack defense coverage corresponding to the current target entity is not less than the single network attack defense coverage threshold, or when the joint network attack defense coverage is not less than the joint network attack defense coverage threshold, the retained target entities to be selected are combined in order to generate a partial network attack link.

[0190] Step 308: Input each partial network attack link into a pre-trained network security model to output a complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on multiple entities included in a preset network security knowledge graph and the entity relationships between different entities;

[0191] Step 309: Obtain the attack success rate corresponding to each complete network attack link, and determine the target complete network attack link whose attack success rate is greater than the preset attack success rate;

[0192] Step 310: Generate target network attack defense measures corresponding to the target complete network attack link based on the target tactics and target technologies corresponding to the target complete network attack link.

[0193] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, please refer to the detailed description of the above network attack link analysis method, which will not be repeated here.

[0194] See also Figure 5 , Figure 5 FIG1 is a schematic diagram of the structure of a network attack link analysis device provided by an embodiment of the present application. The network attack link analysis device can execute the above-mentioned network attack link analysis method.

[0195] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or portion of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal. It can be implemented in whole or in part using software, hardware (such as processing circuits or memory), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the functionality of the module or unit.

[0196] The network attack link analysis device 400 includes:

[0197] An acquisition module 410 is configured to acquire a description text corresponding to a network security event and determine key entities related to the network attack based on the description text;

[0198] a matching module 420 for matching the key entity with each entity of a preset cybersecurity knowledge graph, and determining a plurality of target entities that match the key entity, wherein the preset cybersecurity knowledge graph includes entities corresponding to a plurality of cyberattack techniques and a plurality of cyberattack tactics, respectively;

[0199] a determination module 430 for determining a network attack defense coverage corresponding to each target entity and determining a network attack defense coverage threshold corresponding to the network attack defense coverage;

[0200] a combining module 440 for combining at least some of the target entities according to the network attack defense coverage and the network attack defense coverage threshold corresponding to each target entity to obtain at least one partial network attack link corresponding to the network security event;

[0201] The prediction module 450 is used to input each partial network attack link into a pre-trained network security model and output a complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on multiple entities contained in a preset network security knowledge graph and the entity relationships between different entities.

[0202] In some embodiments, the network attack defense coverage threshold includes a single network attack defense coverage threshold and a joint network attack defense coverage threshold. The combining module 440 is configured to:

[0203] Determine a current target entity among multiple target entities, and determine the network attack defense coverage corresponding to the current target entity;

[0204] When the network attack defense coverage corresponding to the current target entity is less than a single network attack defense coverage threshold, determining a next target entity corresponding to the current target entity from multiple target entities, and determining the network attack defense coverage corresponding to the next target entity;

[0205] Multiply the network attack defense coverage corresponding to the current target entity and the network attack defense coverage corresponding to the next target entity to obtain the joint network attack defense coverage;

[0206] When the joint network attack defense coverage is less than the joint network attack defense coverage threshold, the current target entity and the next target entity are determined as target entities to be selected;

[0207] Update the next target entity to the current target entity, and return to execute to determine the network attack defense coverage corresponding to the current target entity, until the network attack defense coverage corresponding to the current target entity is not less than the single network attack defense coverage threshold, or the joint network attack defense coverage is not less than the joint network attack defense coverage threshold, the retained target entities to be selected will be combined in order to generate partial network attack links.

[0208] In some embodiments, the combination module 440 is configured to:

[0209] After determining a current target entity from among multiple target entities and determining a network attack defense coverage corresponding to the current target entity, when the network attack defense coverage corresponding to the current target entity is not less than a single network attack defense coverage threshold, determining whether there is a target entity to be selected that is retained;

[0210] When there is no remaining target entity to be selected, an updated current target entity is determined from other target entities except the selected current target entity, and the network attack defense coverage corresponding to the updated current target entity is determined.

[0211] In some implementations, the matching module 420 is configured to:

[0212] Obtain a first description text corresponding to the key entity, input the first description text into a pre-trained text processing model, and output a first feature corresponding to the key entity;

[0213] Obtain the second description text corresponding to each entity in the preset network security knowledge graph, input the second description text into the pre-trained text processing model, and output the second feature corresponding to each entity;

[0214] The similarity between the first feature and each second feature is determined, and the entity corresponding to the second feature whose similarity is greater than a preset similarity threshold is determined as a target entity matching the key entity.

[0215] In some implementations, the matching module 420 is configured to:

[0216] Before matching the key entity with each entity of a preset network security knowledge graph and determining multiple target entities that match the key entity, obtaining network security attributes corresponding to multiple network devices in a network attack chain knowledge base, and generating multiple first entities based on each network device and the network security attribute;

[0217] Determining the target technology, target tactics, network attack defense measures, and defense coverage of each network attack chain in a network attack chain knowledge base according to preset network security rules, and generating a plurality of second entities according to the target technology, target tactics, network attack defense measures, and defense coverage of each attack chain;

[0218] Obtain multiple techniques and tactics from a network attack technique and tactics database, and obtain corresponding constraints for the multiple techniques and tactics;

[0219] hierarchically associating the plurality of technologies and the plurality of tactics according to the constraint conditions to obtain a plurality of associated technologies and tactics, and generating a plurality of third entities according to the associated technologies and tactics;

[0220] Obtain entity relationships among a plurality of first entities, a plurality of second entities, and a plurality of third entities according to a network attack chain knowledge base and a network attack technique and tactics database;

[0221] A preset network security knowledge graph is constructed based on entity relationships, multiple first entities, multiple second entities and multiple third entities.

[0222] In some implementations, the determination module 430 is configured to:

[0223] Obtain multiple defense coverages corresponding to each target entity and determine the weight value corresponding to each defense coverage;

[0224] The weight value corresponding to each defense coverage is multiplied by each defense coverage and then added together to obtain the network attack defense coverage corresponding to each target entity.

[0225] In some embodiments, the network attack link analysis device further includes a training module for:

[0226] Before inputting at least one partial network attack link into a pre-trained network security model and outputting at least one complete network attack link, determining sample technologies, sample tactics, and sample entity relationships between the sample technologies and the sample tactics corresponding to the sample network attack link based on a preset network security knowledge graph;

[0227] Generate sample prompt text based on sample tactics, sample techniques, and sample entity relationships, and input the sample prompt text into the network security model to output the predicted network attack link;

[0228] The difference between the predicted network attack link and the sample network attack link is determined, and the network security model is trained according to the difference to obtain a pre-trained network security model.

[0229] In some embodiments, the prediction module 450 is further configured to:

[0230] Obtaining the attack success rate corresponding to each complete network attack link, and determining the target complete network attack link whose attack success rate is greater than the preset attack success rate;

[0231] The target network attack defense measures corresponding to the target complete network attack link are generated according to the target tactics and target technologies corresponding to the target complete network attack link.

[0232] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, please refer to the detailed description of the above network attack link analysis method, which will not be repeated here.

[0233] In an embodiment of the present application, the acquisition module 410 acquires the descriptive text corresponding to the network security event, and determines the key entities related to the network attack based on the descriptive text; the matching module 420 matches the key entity with each entity of the preset network security knowledge graph, and determines multiple target entities that match the key entity, wherein the preset network security knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics respectively; the determination module 430 determines the network attack defense coverage corresponding to each target entity, and determines the network attack defense coverage threshold corresponding to the network attack defense coverage; the combination module 440 combines at least part of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event; the prediction module 450 inputs each partial network attack link into the pre-trained network security model, and outputs the complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

[0234] In this way, by determining the key entities related to the network attack in the description text of the network security event, and then matching them with the preset network security knowledge graph, a plurality of target entities matching the key entities are obtained, and then the network attack defense coverage corresponding to each target entity is determined, and the network attack defense coverage threshold corresponding to the network attack defense coverage is determined. At least part of the target entities are combined according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, and at least one partial network attack link corresponding to the network security event is obtained. In this way, the partial network attack link is determined, and then each partial network attack link is input into the pre-trained network security model to output the complete network attack link corresponding to the network security event. Compared with the related art that determines similar attack links by the similarity of alarm logs, the present application can accurately combine at least part of the target entities through the network attack defense coverage and the network attack defense coverage threshold to obtain the partial network attack link corresponding to the network security event, and at the same time input the partial network attack link into the pre-trained network security model to output the complete network attack link corresponding to the network security event, thereby accurately predicting the complete network attack link that can cause network security time, thereby helping network security personnel to take more comprehensive network security defense measures for network security events.

[0235] An embodiment of the present application also provides a computer device, which includes a memory and a processor. The memory stores a computer program, and the processor implements the above-mentioned network attack link analysis method when executing the computer program.

[0236] See also Figure 6 , Figure 6 The hardware structure of a computer device according to another embodiment is shown. The computer device includes:

[0237] The processor 501 may be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.

[0238] The memory 502 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 502 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 502 and is called by the processor 501 to execute the network attack link analysis method of the embodiments of this application;

[0239] Input / output interface 503, used to implement information input and output;

[0240] Communication interface 504, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);

[0241] Bus 505 , which transmits information between various components of the device (e.g., processor 501 , memory 502 , input / output interface 503 , and communication interface 504 );

[0242] The processor 501 , the memory 502 , the input / output interface 503 and the communication interface 504 are connected to each other in communication within the device via a bus 505 .

[0243] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned network attack link analysis method.

[0244] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0245] The embodiments of the present application provide a network attack link analysis method, a network attack link analysis device, a computer device, and a storage medium. The methods obtain a description text corresponding to a network security event and determine a key entity related to the network attack based on the description text; match the key entity with each entity of a preset network security knowledge graph to determine multiple target entities that match the key entity, wherein the preset network security knowledge graph includes entities corresponding to multiple network attack technologies and multiple network attack tactics; determine the network attack defense coverage corresponding to each target entity, and determine a network attack defense coverage threshold corresponding to the network attack defense coverage; combine at least some of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event; input each partial network attack link into a pre-trained network security model to output a complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

[0246] In this way, by determining the key entities related to the network attack in the description text of the network security event, and then matching them with the preset network security knowledge graph, a plurality of target entities matching the key entities are obtained, and then the network attack defense coverage corresponding to each target entity is determined, and the network attack defense coverage threshold corresponding to the network attack defense coverage is determined. At least part of the target entities are combined according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, and at least one partial network attack link corresponding to the network security event is obtained. In this way, the partial network attack link is determined, and then each partial network attack link is input into the pre-trained network security model to output the complete network attack link corresponding to the network security event. Compared with the related art that determines similar attack links by the similarity of alarm logs, the present application can accurately combine at least part of the target entities through the network attack defense coverage and the network attack defense coverage threshold to obtain the partial network attack link corresponding to the network security event, and at the same time input the partial network attack link into the pre-trained network security model to output the complete network attack link corresponding to the network security event, thereby accurately predicting the complete network attack link that can cause network security time, thereby helping network security personnel to take more comprehensive network security defense measures for network security events.

[0247] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0248] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0249] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0250] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.

[0251] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0252] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0253] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0254] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0255] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0256] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0257] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.

Claims

1. A network attack link analysis method, characterized in that: include: Obtaining a description text corresponding to a network security event, and determining key entities related to the network attack based on the description text; Matching the key entity with each entity of a preset network security knowledge graph to determine a plurality of target entities that match the key entity, wherein the preset network security knowledge graph includes entities corresponding to a plurality of network attack technologies and a plurality of network attack tactics, respectively; Determining a network attack defense coverage corresponding to each target entity, and determining a network attack defense coverage threshold corresponding to the network attack defense coverage; Combining at least some of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event; Each partial network attack link is input into a pre-trained network security model, and a complete network attack link corresponding to the network security event is output, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

2. The network attack link analysis method according to claim 1, characterized in that: The network attack defense coverage threshold includes a single network attack defense coverage threshold and a joint network attack defense coverage threshold; The combining the at least some target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold to obtain at least one partial network attack link corresponding to the network security event includes: Determining a current target entity from the multiple target entities, and determining a network attack defense coverage corresponding to the current target entity; When the network attack defense coverage corresponding to the current target entity is less than a single network attack defense coverage threshold, determining a next target entity corresponding to the current target entity from the multiple target entities, and determining the network attack defense coverage corresponding to the next target entity; Multiplying the network attack defense coverage corresponding to the current target entity and the network attack defense coverage corresponding to the next target entity to obtain a joint network attack defense coverage; When the joint network attack defense coverage is less than the joint network attack defense coverage threshold, determining the current target entity and the next target entity as target entities to be selected; The next target entity is updated to the current target entity, and the execution is returned to determine the network attack defense coverage corresponding to the current target entity until the network attack defense coverage corresponding to the current target entity is not less than the single network attack defense coverage threshold, or the joint network attack defense coverage is not less than the joint network attack defense coverage threshold, and the retained target entities to be selected are combined in order to generate partial network attack links.

3. The network attack link analysis method according to claim 2, characterized in that: After determining a current target entity from the multiple target entities and determining the network attack defense coverage corresponding to the current target entity, the method further includes: When the network attack defense coverage corresponding to the current target entity is not less than a single network attack defense coverage threshold, determining whether there is a target entity to be selected that is retained; When there is no remaining target entity to be selected, an updated current target entity is determined from other target entities except the selected current target entity, and the network attack defense coverage corresponding to the updated current target entity is determined.

4. The network attack link analysis method according to claim 1, characterized in that: The step of matching the key entity with each entity of a preset network security knowledge graph to determine a plurality of target entities matching the key entity includes: Obtaining a first description text corresponding to the key entity, and inputting the first description text into a pre-trained text processing model to output a first feature corresponding to the key entity; Obtain a second description text corresponding to each entity in a preset network security knowledge graph, input the second description text into the pre-trained text processing model, and output a second feature corresponding to each entity; The similarity between the first feature and each of the second features is determined, and an entity corresponding to a second feature whose similarity is greater than a preset similarity threshold is determined as a target entity matching the key entity.

5. The network attack link analysis method according to claim 1, characterized in that: Before matching the key entity with each entity of a preset network security knowledge graph and determining a plurality of target entities matching the key entity, the method further includes: Obtain network security attributes corresponding to a plurality of network devices in a network attack chain knowledge base, and generate a plurality of first entities according to each network device and the network security attributes; Determining, in the network attack chain knowledge base according to preset network security rules, target technologies, target tactics, network attack defense measures, and defense coverage for each network attack chain, and generating a plurality of second entities according to the target technologies, target tactics, network attack defense measures, and defense coverage for each network attack chain; Obtaining multiple techniques and multiple tactics from a network attack technique and tactics database, and obtaining constraint conditions corresponding to the multiple techniques and multiple tactics; hierarchically associating the plurality of technologies and the plurality of tactics according to the constraint conditions to obtain a plurality of associated technologies and tactics, and generating a plurality of third entities according to the associated technologies and tactics; Acquire entity relationships among the plurality of first entities, the plurality of second entities, and the plurality of third entities according to the network attack chain knowledge base and the network attack technique and tactics database; A preset network security knowledge graph is constructed based on the entity relationship, the multiple first entities, the multiple second entities and the multiple third entities.

6. The network attack link analysis method according to claim 1, characterized in that: Determining the network attack defense coverage corresponding to each target entity includes: Obtain multiple defense coverages corresponding to each target entity and determine the weight value corresponding to each defense coverage; The weight value corresponding to each defense coverage is multiplied by each defense coverage and then added together to obtain the network attack defense coverage corresponding to each target entity.

7. The network attack link analysis method according to claim 1, characterized in that: Before inputting the at least one partial network attack link into the pre-trained network security model and outputting at least one complete network attack link, the method further includes: Determine, based on the preset network security knowledge graph, sample technologies and sample tactics corresponding to the sample network attack links, as well as sample entity relationships between the sample technologies and the sample tactics; Generate sample prompt text according to the sample tactics, the sample technology and the sample entity relationship, input the sample prompt text into a network security model, and output a predicted network attack link; The difference between the predicted network attack link and the sample network attack link is determined, and the network security model is trained according to the difference to obtain a trained pre-trained network security model.

8. The network attack link analysis method according to claim 1, characterized in that: After inputting the at least one partial network attack link into the pre-trained network security model and outputting at least one complete network attack link, the method further includes: Obtaining an attack success rate corresponding to each complete network attack link, and determining a target complete network attack link whose attack success rate is greater than a preset attack success rate; A target network attack defense measure corresponding to the target complete network attack link is generated according to the target tactics and target technology corresponding to the target complete network attack link.

9. A network attack link analysis device, characterized in that: include: An acquisition module is used to obtain a description text corresponding to a network security event and determine key entities related to the network attack based on the description text; a matching module, configured to match the key entity with each entity of a preset cybersecurity knowledge graph, and determine a plurality of target entities that match the key entity, wherein the preset cybersecurity knowledge graph includes entities corresponding to a plurality of network attack techniques and a plurality of network attack tactics, respectively; a determination module, configured to determine a network attack defense coverage corresponding to each target entity, and determine a network attack defense coverage threshold corresponding to the network attack defense coverage; a combining module, configured to combine at least some of the target entities according to the network attack defense coverage corresponding to each target entity and the network attack defense coverage threshold, to obtain at least one partial network attack link corresponding to the network security event; A prediction module is used to input each partial network attack link into a pre-trained network security model and output the complete network attack link corresponding to the network security event, wherein the pre-trained network security model is trained based on multiple entities contained in the preset network security knowledge graph and the entity relationships between different entities.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, which are suitable for loading by a processor to execute the network attack link analysis method according to any one of claims 1 to 8.

11. A computer device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor executes the computer program, the network attack link analysis method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Knowledge graph construction method and device, electronic equipment and storage medium

    CN116756330A

  • Network security analysis method and device, electronic equipment and readable storage medium

    CN117749534A