Data generation method, device and equipment, computer storage medium and computer program product

By extending the initial sample data and sample expansion for the network attack chain, target sample data covering various scenarios of the entire network attack chain is generated, solving the problem of limited sample generalization ability in the existing technology.

CN120200775APending Publication Date: 2025-06-24SANGFOR TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411780169.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-03
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The samples generated in the prior art cannot cover all kinds of scenarios related to the entire network attack chain, and the generalization ability of the samples is limited.

Method used

By obtaining the initial sample data, performing sample expansion, obtaining the first sample data, and then performing sample expansion for the network attack chain, obtaining the second sample data, and finally determining the target sample data for network security.

Benefits of technology

It solves the problem that the sample cannot cover the entire network attack chain related scenarios, and improves the generalization ability of the sample.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200775A_ABST
    Figure CN120200775A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data generation method. The method comprises the following steps: acquiring initial sample data for network security; performing sample expansion based on the initial sample data to obtain first sample data; performing sample expansion for a network attack chain based on the first sample data to obtain second sample data; and determining target sample data for the network security based on the first sample data and the second sample data. The embodiment of the invention further discloses a data generation device and equipment, a computer readable storage medium and a computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to network security technology in the field of computer technology, and in particular to a data generation method, apparatus, device, computer storage medium, and computer program product. Background Art

[0002] Currently, one of the problems with security large models is the lack of sample training; in related technologies, there are solutions for producing a large number of samples based on the sample production method of the network attack chain. These samples can be used to train security large models to improve the network security detection ability of security large models. However, this solution of constructing "samples" based on "samples" in related technologies has the problems that the constructed samples cannot cover all types of scenarios related to the entire network attack chain, and the generalization ability of the samples is limited. Summary of the Invention

[0003] To solve the above technical problems, embodiments of this application are expected to provide a data generation method, apparatus, device, computer storage medium, and computer program product, which solve the problem that the sample generation solutions in related technologies cannot cover all types of scenarios related to the entire network attack chain, and improve the generalization ability of the samples.

[0004] The technical solution of this application is implemented as follows:

[0005] A data generation method, the method includes:

[0006] Obtain initial sample data for network security;

[0007] Perform sample expansion based on the initial sample data to obtain first sample data;

[0008] Perform sample expansion for the network attack chain based on the first sample data to obtain second sample data;

[0009] Determine target sample data for the network security based on the first sample data and the second sample data.

[0010] In the above solution, the obtaining of the initial sample data for network security includes:

[0011] Obtain first data for network security through target intelligence collection technology, and obtain second data in historical network security events;

[0012] Determine the initial sample data based on the first data and the second data.

[0013] In the above solution, the performing of sample expansion based on the initial sample data to obtain first sample data includes:

[0014] Based on the functions of the functions in the initial sample data, the initial sample data is segmented to obtain multiple sample sub - data;

[0015] Based on the multiple sample sub - data, sample expansion is performed to obtain the first sample data.

[0016] In the above solution, the sample expansion based on the multiple sample sub - data to obtain the first sample data includes:

[0017] Each sample sub - data is vectorized to obtain processed sample sub - data;

[0018] Based on multiple processed sample sub - data, data expansion is performed to obtain multiple target sample sub - data;

[0019] Based on the multiple target sample sub - data, sample expansion is performed to obtain the first sample data.

[0020] In the above solution, the data expansion based on multiple processed sample sub - data to obtain multiple target sample sub - data includes:

[0021] A first security detection model is used to perform generalization processing on multiple processed sample sub - data to obtain the multiple target sample sub - data.

[0022] In the above solution, the sample expansion based on the multiple target sample sub - data to obtain the first sample data includes

[0023] Based on the multiple target sample sub - data, sample data to be processed is generated;

[0024] A second security detection model is used to perform generalization processing on the sample data to be processed to obtain the first sample data. In the above solution, the method further includes:

[0025] The target sample data is used to train an initial security detection model to obtain a target security detection model.

[0026] A data generation device, the device includes:

[0027] An acquisition unit, configured to acquire initial sample data for network security;

[0028] A first processing unit, configured to perform sample expansion based on the initial sample data to obtain first sample data;

[0029] A second processing unit, configured to perform sample expansion for a network attack chain based on the first sample data to obtain second sample data;

[0030] A determination unit, configured to determine target sample data for the network security based on the first sample data and the second sample data.

[0031] A data generation device, the device comprising: a processor, a memory, and a communication bus;

[0032] The communication bus is used to implement a communication connection between the processor and the memory;

[0033] The processor is configured to execute a data generation program in the memory to implement the steps of the above data generation method.

[0034] A computer-readable storage medium, the computer-readable storage medium storing one or more programs, the one or more programs being executable by one or more processors to implement the steps of the above data generation method.

[0035] A computer program product, the computer program product comprising a computer program, the computer program implementing the above data generation method when executed by a processor.

[0036] The data generation method, apparatus, device, computer storage medium, and computer program product provided by the embodiments of the present application can obtain initial sample data for network security, perform sample expansion based on the initial sample data to obtain first sample data, perform sample expansion for the network attack chain based on the first sample data to obtain second sample data, and determine target sample data for network security based on the first sample data and the second sample data. In this way, sample expansion for the network attack chain can be performed on the first sample data obtained after sample expansion, and then the final sample data can be composed of the obtained first sample data and second sample data, that is, various scenarios of the network attack chain are considered when determining the sample and the sample is expanded, thereby solving the problem that the sample generation solutions in the related art cannot cover all scenarios related to the entire network attack chain, and improving the generalization ability of the sample. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 It is a schematic flowchart of a data generation method provided by an embodiment of the present application;

[0038] Figure 2 It is a schematic flowchart of another data generation method provided by an embodiment of the present application;

[0039] Figure 3 It is a schematic structural diagram of a data generation apparatus provided by an embodiment of the present application;

[0040] Figure 4 It is a schematic structural diagram of a data generation device provided by an embodiment of the present application. Detailed implementation manners

[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application.

[0042] It should be understood that the "embodiments of the present application" or "the foregoing embodiments" mentioned throughout the specification mean that specific features, structures, or characteristics related to the embodiments are included in at least one embodiment of the present application. Therefore, the "in the embodiments of the present application" or "in the foregoing embodiments" that appear throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures, or characteristics can be combined in one or more embodiments in any suitable manner. In various embodiments of the present application, the order of the above processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages and disadvantages of the embodiments.

[0043] Without special instructions, when performing any step in the embodiments of the present application, it can be the processor of the device that executes the step. It is also worth noting that the embodiments of the present application do not limit the order of execution of the following steps by the device. In addition, the methods used to process data in different embodiments can be the same method or different methods. It should also be noted that any step in the embodiments of the present application can be independently executed by the device, that is, when the device executes any step in the following embodiments, it does not depend on the execution of other steps.

[0044] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0045] The embodiments of the present application provide a data generation method, which can be applied to a data generation device. Referring to Figure 1 as shown, the method may include the following steps:

[0046] Step 101, obtain initial sample data for network security.

[0047] Among them, the initial sample data may refer to a large amount of sample data related to network security.

[0048] It should be noted that the initial sample data can be obtained by the data generation device based on the sample data corresponding to historical network security events and the sample data related to network security obtained based on the target intelligence collection technology.

[0049] Step 102, perform sample expansion based on the initial sample data to obtain first sample data.

[0050] In the embodiment of the present application, the data generation device may first segment the initial sample data, and perform sample expansion on the segmented multiple sample sub-data to obtain the first sample data;

[0051] It should be noted that the first sample data may refer to the sample data obtained by performing sample expansion on the initial sample data at the level of minimizing the implementation of network security events.

[0052] Specifically, the data generation device may first perform data segmentation on the initial sample data, and then perform sample expansion on the segmented sample sub-data to obtain the first sample data.

[0053] Step 103: Perform sample expansion on the basis of the first sample data for the network attack chain to obtain the second sample data.

[0054] In the embodiment of the present application, the second sample data may be the sample data obtained by performing sample expansion on the first sample data at the network attack chain level.

[0055] Specifically, the data generation device may perform sample expansion on the first sample data for each attack stage of the network attack chain to obtain the second sample data.

[0056] Step 104: Determine the target sample data for network security based on the first sample data and the second sample data.

[0057] In the embodiment of the present application, the data generation device may perform synthesis processing on the first sample data and the second sample data to obtain the target sample data for network security; in a feasible implementation manner, the first sample data and the second sample data may be directly combined into an overall data to obtain the target sample data.

[0058] It should be noted that in the solution of the present application, during the process of generating samples, sample expansion can be performed at both the level of minimizing the implementation and the level of the network attack chain, which not only ensures the quantity of the generated samples, but also meets the coverage of various scenarios of the entire network attack chain, greatly expanding the applicable range of the generated samples.

[0059] The data generation method provided by the embodiment of the present application can perform sample expansion on the first sample data obtained after sample expansion on the network attack chain, and then form the final sample data according to the obtained first sample data and the second sample data, that is, considering various scenarios of the network attack chain when determining the samples and expanding the samples, thereby solving the problem that the sample generation scheme in the related technology cannot cover various scenarios related to the entire network attack chain, and improving the generalization ability of the samples.

[0060] Based on the foregoing embodiments, an embodiment of the present application provides a data generation method. Referring to Figure 2 as shown, the method may include the following steps:

[0061] Step 201: The data generation device obtains first data for network security through target intelligence collection technology and obtains second data in historical network security events.

[0062] Among them, the target intelligence collection technology may refer to an open-source technology capable of obtaining various network security-related data; specifically, the target intelligence collection technology may refer to open-source intelligence; in a feasible implementation manner, open-source intelligence may refer to websites such as github; then, the first data may be data related to network security collected on websites such as github.

[0063] In addition, historical network security events may be network security events that have occurred in history. In a feasible implementation manner, the second data may be data related to network security collected at the scenes of various different network security events that have occurred.

[0064] Step 202: The data generation device determines initial sample data based on the first data and the second data.

[0065] In the embodiment of the present application, the first data and the second data may be directly and simply combined to obtain the initial sample data.

[0066] Step 203: The data generation device performs segmentation processing on the initial sample data based on the functions of the functions in the initial sample data to obtain multiple sample sub-data.

[0067] Specifically, the initial sample data may be segmented according to the functions that the functions in the initial sample data can achieve. It should be noted that the code in the initial sample data may be segmented based on the principle of minimizing the number of functions included in the code for implementing network security events.

[0068] In a feasible implementation manner, taking the code corresponding to various network security events included in the initial sample data as an example for illustration; if the code corresponding to the functions for implementing various functions is included in the initial sample data, then segmenting the initial sample data based on the principle of minimizing the number of functions included can obtain the function for implementing the HKCU registry self-start function and the function for creating a driver service function.

[0069] In an embodiment of the present application, the data generation device may, at the atomic technology level, perform minimum data segmentation processing on the initial sample data based on the atomic technology corresponding to the cybersecurity event, to obtain multiple sample sub-data at the atomic technology level. It should be noted that the atomic technology corresponding to the cybersecurity event may refer to the code with the fewest functions included in the cybersecurity event; the data generation device may store the multiple sample sub-data obtained by segmentation into the atomic technology reference database.

[0070] In a feasible implementation, the multiple sample sub-data may include data such as registry modification code, external communication code, vulnerability exploitation code, startup item addition code, port scanning code, etc.

[0071] Step 204: The data generation device performs sample expansion based on the multiple sample sub-data to obtain the first sample data.

[0072] Among them, the data generation device may perform sample expansion based on the multiple sample sub-data to obtain the first sample data; specifically, it may first convert the format of each sample sub-data, and perform sample expansion based on the sample sub-data after format conversion to obtain the first sample data.

[0073] It should be noted that the first sample data is the data obtained after sample expansion at the atomic technology level for implementing the cybersecurity event.

[0074] In other embodiments of the present application, step 204 may be implemented in the following manner:

[0075] Step 204a: The data generation device performs vectorization processing on each sample sub-data to obtain processed sample sub-data.

[0076] Among them, the format of each sample sub-data may be converted into a vector format, that is, vectorization processing of each sample sub-data is realized, and then processed sample sub-data in vector format is obtained.

[0077] Step 204b: The data generation device performs data expansion based on the multiple processed sample sub-data to obtain multiple target sample sub-data.

[0078] Among them, the data generation device may perform sample generalization expansion on the multiple processed sample sub-data at the atomic technology level to obtain multiple target sample sub-data; specifically, it may be realized by the first security detection model for sample generalization of the multiple processed sample sub-data.

[0079] In other embodiments of the present application, the above step 204b may be implemented in the following manner:

[0080] Generalize multiple processed sample sub - data using the first security detection model to obtain multiple target sample sub - data.

[0081] Among them, the first security detection model can refer to the large - scale security detection model; specifically, the data generation device can use multiple processed sample sub - data as the input information of the first security detection model and input multiple processed sample sub - data into the first security detection model. Then, the first security detection model can process the multiple processed sample sub - data (i.e., generalize the multiple processed sample sub - data) to generate multiple target sample sub - data. It should be noted that the multiple generated target sample sub - data can be stored in the atomic technology database.

[0082] In a feasible implementation, data such as registry modification code, external communication code, vulnerability exploitation code, startup item addition code, port scanning code, etc. can be input into the large - scale security detection model, and the large - scale security detection model can perform data training and generalization on data such as registry modification code, external communication code, vulnerability exploitation code, startup item addition code, port scanning code, etc. to generate multiple target sample sub - data at the atomic technology level.

[0083] Step 204c: The data generation device performs sample expansion based on multiple target sample sub - data to obtain the first sample data.

[0084] Among them, the data generation device can perform sample expansion on multiple processed sample sub - data to obtain the first sample data; specifically, it can first obtain the sample data to be processed according to multiple target sample sub - data and perform sample expansion on the sample data to be processed to generate the first sample data.

[0085] In other embodiments of the present application, the above - mentioned step 204c can be implemented in the following manner:

[0086] c1: Generate the sample data to be processed based on multiple target sample sub - data.

[0087] Among them, the data generation device can retrieve multiple target sample sub - data from the atomic technology database and perform permutation and combination on the multiple target samples to generate the sample data to be processed.

[0088] c2: Use the second security detection model to generalize the sample data to be processed to obtain the first sample data.

[0089] Among them, the second security detection model can also refer to the large security detection model. Specifically, the data generation device can use the sample data to be processed as the input information of the second security detection model, and input the sample data to be processed into the second security detection model. Then, the second security detection model can process the sample data to be processed (i.e., perform generalization processing on the sample data to be processed), and generate the first sample data. It should be noted that the generated first sample data can be stored in the sample database.

[0090] In a feasible implementation, the sample data to be processed can be input into the large security detection model, and the large security detection model can perform data training and generalization on the sample data to be processed to generate the first sample data.

[0091] Step 205: The data generation device uses the target security attack chain model to perform generalization processing on the first sample data for each stage of the network attack chain, and obtains the second sample data.

[0092] Among them, the target security attack chain model can refer to the large network security attack chain model. Specifically, the data generation device can use the first sample data as the input information of the target security attack chain model, and input the first sample data into the target security attack chain model. Then, the target security attack chain model can process the first sample data at each stage of the network attack chain (i.e., perform generalization processing on the first sample data), and generate the second sample data. It should be noted that the generated second sample data can be stored in the sample database.

[0093] In a feasible implementation, the first sample data can be input into the large network security attack chain model, and the large network security attack chain model can perform sample generalization on the first sample data respectively for the 7 stages of reconnaissance, weaponization, delivery, vulnerability exploitation, installation and communication, extension and data leakage, and generate the second sample data.

[0094] Step 206: The data generation device determines the target sample data for network security based on the first sample data and the second sample data.

[0095] It should be noted that after merging the first sample data and the second sample data, the target sample data for network security is obtained, and the obtained sample data is richer and more comprehensive. In this way, when using the target sample data to train the subsequent network security model, the accuracy of the trained model is ensured.

[0096] In other embodiments of the present application, the method may further include:

[0097] Step 207: The data generation device uses the target sample data to train the initial security detection model, and obtains the target security detection model.

[0098] In an embodiment of the present application, target sample data can be obtained from a sample database, and the target sample data is used as input information of an initial security detection model and input into the initial security detection model, and the target sample data is processed by the initial security detection model; further, the parameters of the initial security detection model are updated according to the processing result, and the target sample data is continuously processed by the initial security detection model with updated parameters, and this is cyclically executed until finally a target security detection model that meets the requirements is trained.

[0099] It should be noted that the network security detection ability of the target security detection model trained by using the target sample data generated by the present application is stronger, and thus the security of network data can be better guaranteed, and network security problems can be avoided.

[0100] It should be noted that for the descriptions of the same steps and the same content in this embodiment and other embodiments, reference can be made to the descriptions in other embodiments, and details are not described herein again.

[0101] The data generation method provided by the embodiment of the present application can perform sample expansion on the first sample data obtained after sample expansion, and then form the final sample data according to the obtained first sample data and second sample data, that is, each scenario of the network attack chain is considered when determining the sample and the sample is expanded, thereby solving the problem that the sample generation scheme in the related art cannot cover all scenarios related to the entire network attack chain, and improving the generalization ability of the sample.

[0102] Based on the foregoing embodiments, an embodiment of the present application provides a data generation device, which can be applied to Figure 1 and Figure 2 In the data generation method provided by the corresponding embodiment, referring to Figure 3 As shown, the data generation device 3 may include: an acquisition unit 31, a first processing unit 32, a second processing unit 33, and a determination unit 34, where:

[0103] The acquisition unit 31 is configured to acquire initial sample data for network security;

[0104] The first processing unit 32 is configured to perform sample expansion based on the initial sample data to obtain first sample data;

[0105] The second processing unit 33 is configured to perform sample expansion for the network attack chain based on the first sample data to obtain second sample data;

[0106] The determination unit 34 is configured to determine target sample data for network security based on the first sample data and the second sample data.

[0107] In other embodiments of the present application, the obtaining unit 31 is further configured to perform the following steps:

[0108] Obtain first data for network security through target intelligence collection technology, and obtain second data in historical network security events;

[0109] Determine initial sample data based on the first data and the second data.

[0110] In other embodiments of the present application, the first processing unit 32 is further configured to perform the following steps:

[0111] Based on the functions of the functions in the initial sample data, perform segmentation processing on the initial sample data to obtain multiple sample sub-data;

[0112] Perform sample expansion based on the multiple sample sub-data to obtain first sample data.

[0113] In other embodiments of the present application, the first processing unit 32 is further configured to perform the following steps:

[0114] Perform vectorization processing on each sample sub-data to obtain processed sample sub-data;

[0115] Perform data expansion based on the multiple processed sample sub-data to obtain multiple target sample sub-data;

[0116] Perform sample expansion based on the multiple target sample sub-data to obtain first sample data.

[0117] In other embodiments of the present application, the first processing unit 32 is further configured to perform generalization processing on the multiple processed sample sub-data by using a first security detection model to obtain multiple target sample sub-data.

[0118] In other embodiments of the present application, the first processing unit 32 is further configured to perform the following steps:

[0119] Generate sample data to be processed based on the multiple target sample sub-data;

[0120] Perform generalization processing on the sample data to be processed by using a second security detection model to obtain first sample data.

[0121] In other embodiments of the present application, the second processing unit 33 is further configured to perform generalization processing on the first sample data for each stage of the network attack chain by using a target security attack chain model to obtain second sample data.

[0122] In other embodiments of the present application, the determination unit 34 is further configured to train an initial security detection model by using target sample data to obtain a target security detection model.

[0123] It should be noted that for the specific descriptions of the steps executed by each unit, reference can be made to Figure 1 and Figure 2 the data generation methods provided in the corresponding embodiments, which will not be elaborated here.

[0124] The data generation device provided by the embodiments of the present application can perform sample expansion on the first sample data obtained after sample expansion, and then form the final sample data based on the obtained first sample data and second sample data. That is, when determining the sample, various scenarios of the network attack chain are considered and the sample is expanded, thereby solving the problem that the sample generation solutions in the related art cannot cover all types of scenarios related to the entire network attack chain, and improving the generalization ability of the sample.

[0125] Based on the foregoing embodiments, the embodiments of the present application provide a data generation device, which can be applied to Figure 1 and Figure 2 the data generation methods provided in the corresponding embodiments, with reference to Figure 4 shown, the data generation device 4 may include: a processor 41, a memory 42, and a communication bus 43, where:

[0126] The communication bus 43 is used to implement the communication connection between the processor 41 and the memory 42;

[0127] The processor 41 is used to execute the data generation program in the memory 42 to implement the following steps:

[0128] Obtain initial sample data for network security;

[0129] Perform sample expansion based on the initial sample data to obtain first sample data;

[0130] Perform sample expansion for the network attack chain based on the first sample data to obtain second sample data;

[0131] Determine the target sample data for network security based on the first sample data and the second sample data.

[0132] In other embodiments of the present application, the processor 41 is used to execute the step of obtaining the initial sample data for network security in the data generation program in the memory 42 to implement the following steps:

[0133] Obtain the first data for network security through the target intelligence collection technology, and obtain the second data in the historical network security events;

[0134] Determine the initial sample data based on the first data and the second data.

[0135] In other embodiments of the present application, the processor 41 is configured to execute the data generation program in the memory 42 to perform sample expansion based on the initial sample data to obtain first sample data, so as to implement the following steps:

[0136] Based on the functions of the functions in the initial sample data, the initial sample data is segmented to obtain a plurality of sample sub-data;

[0137] Based on the plurality of sample sub-data, sample expansion is performed to obtain first sample data.

[0138] In other embodiments of the present application, the processor 41 is configured to execute the data generation program in the memory 42 to perform sample expansion based on the plurality of sample sub-data to obtain first sample data, so as to implement the following steps:

[0139] Perform vectorization processing on each sample sub-data to obtain processed sample sub-data;

[0140] Based on the plurality of processed sample sub-data, data expansion is performed to obtain a plurality of target sample sub-data;

[0141] Based on the plurality of target sample sub-data, sample expansion is performed to obtain first sample data.

[0142] In other embodiments of the present application, the processor 41 is configured to execute the data generation program in the memory 42 to perform data expansion based on the plurality of processed sample sub-data to obtain a plurality of target sample sub-data, so as to implement the following steps:

[0143] Use the first security detection model to perform generalization processing on the plurality of processed sample sub-data to obtain a plurality of target sample sub-data.

[0144] In other embodiments of the present application, the processor 41 is configured to execute the data generation program in the memory 42 to perform sample expansion based on the plurality of target sample sub-data to obtain first sample data, so as to implement the following steps:

[0145] Generate sample data to be processed based on the plurality of target sample sub-data;

[0146] Use the second security detection model to perform generalization processing on the sample data to be processed to obtain first sample data.

[0147] In other embodiments of the present application, the processor 41 is configured to execute the data generation program in the memory 42 to perform sample expansion for the network attack chain based on the first sample data to obtain second sample data, so as to implement the following steps:

[0148] Use the target security attack chain model to perform generalization processing on each stage of the network attack chain for the first sample data to obtain second sample data.

[0149] In other embodiments of the present application, the processor 41 is used to execute the data generation program in the memory 42, and the following steps can also be implemented:

[0150] Train the initial security detection model with the target sample data to obtain the target security detection model.

[0151] It should be noted that the specific description of the steps executed by the processor can be referred to Figure 1 and Figure 2 In the data generation method provided in the corresponding embodiments, it will not be elaborated here.

[0152] The data generation device provided by the embodiments of the present application can perform sample expansion on the first sample data obtained after sample expansion on the network attack chain, and then form the final sample data according to the obtained first sample data and the second sample data, that is, when determining the sample, various scenarios of the network attack chain are considered and the sample is expanded, thus solving the problem that the sample generation scheme in the related technology cannot cover various scenarios related to the entire network attack chain, and improving the generalization ability of the sample.

[0153] Based on the foregoing embodiments, the embodiments of the present application provide a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement Figure 1 and Figure 2 The steps of the data generation method provided in the corresponding embodiments.

[0154] Based on the foregoing embodiments, the embodiments of the present application provide a computer program product, including a computer program, and the computer program can be executed by the processor 41 to complete Figure 1 and Figure 2 The steps of the data generation method provided in the corresponding embodiments.

[0155] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.

[0156] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices produce means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0157] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0158] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0159] As mentioned above, it is only a preferred embodiment of the present application and is not used to limit the protection scope of the present application.

Claims

1. A data generation method, characterized in that: The method comprises: Obtain initial sample data for network security; Perform sample expansion based on the initial sample data to obtain first sample data; Performing sample expansion for the network attack chain based on the first sample data to obtain second sample data; Based on the first sample data and the second sample data, target sample data for network security is determined.

2. The method according to claim 1, characterized in that The obtaining of initial sample data for network security includes: Acquire first data on network security through targeted intelligence collection technology, and acquire second data on historical network security events; The initial sample data is determined based on the first data and the second data.

3. The method according to claim 1, characterized in that The performing sample expansion based on the initial sample data to obtain first sample data includes: Based on the function of the function in the initial sample data, the initial sample data is segmented to obtain a plurality of sample sub-data; Sample expansion is performed based on the multiple sample sub-data to obtain the first sample data.

4. The method according to claim 3, characterized in that The performing sample expansion based on the plurality of sample sub-data to obtain the first sample data includes: Performing vectorization processing on each sample sub-data to obtain processed sample sub-data; Performing data expansion based on the plurality of processed sample sub-data to obtain a plurality of target sample sub-data; Sample expansion is performed based on the multiple target sample sub-data to obtain the first sample data.

5. The method according to claim 4, characterized in that The data expansion is performed based on the plurality of processed sample sub-data to obtain a plurality of target sample sub-data, including: The first security detection model is used to perform generalization processing on the plurality of processed sample sub-data to obtain the plurality of target sample sub-data.

6. The method according to claim 4, characterized in that The performing sample expansion based on the plurality of target sample sub-data to obtain the first sample data includes: Generate sample data to be processed based on the multiple target sample sub-data; The second security detection model is used to generalize the sample data to be processed to obtain the first sample data.

7. The method according to claim 1, characterized in that The step of performing sample expansion for the network attack chain based on the first sample data to obtain second sample data includes: The target security attack chain model is used to generalize the first sample data for each stage of the network attack chain to obtain the second sample data.

8. The method according to claim 1, characterized in that The method further comprises: The target sample data is used to train the initial security detection model to obtain a target security detection model.

9. A data generating device, characterized in that: The device comprises: An acquisition unit, used for acquiring initial sample data for network security; A first processing unit, configured to perform sample expansion based on the initial sample data to obtain first sample data; A second processing unit, configured to perform sample expansion for the network attack chain based on the first sample data to obtain second sample data; A determining unit is used to determine target sample data for the network security based on the first sample data and the second sample data.

10. A data generating device, characterized in that: The device comprises: a processor, a memory and a communication bus; The communication bus is used to realize the communication connection between the processor and the memory; The processor is used to execute the data generation program in the memory to implement the steps of the data generation method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the data generation method according to any one of claims 1 to 8.

12. A computer program product, comprising a computer program, characterized in that: When the computer program is executed by a processor, the computer program implements the data generation method according to any one of claims 1 to 8.