Network attack analysis method and device based on attack chain and electronic equipment

Through the analysis method based on the attack chain, the alarm data is phased matching and correlation, and the alarm data association diagram is constructed and the attack link is analyzed, which solves the problem of difficulty in accurately determining the success and impact range of the network attack in the existing technology, and achieves more efficient and accurate attack behavior analysis.

CN120200815APending Publication Date: 2025-06-24DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510374692.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art is difficult to accurately determine whether a network attack is successful and its impact range from a large number of alarms, and it is difficult to detect hidden attack behaviors, resulting in high false alarm rates and high analysis costs.

Method used

Using an attack chain-based analysis method, by obtaining the attribute information of the alarm data, and phase-matching and correlation of the alarm data based on the preset attack chain model, an alarm data association diagram is constructed, thereby extracting and analyzing the attack link to determine its authenticity.

Benefits of technology

It improves the accuracy and efficiency of cyber attack behavior analysis, reduces the false alarm rate, can more clearly identify attack methods and targets, and reduces the cost of manual analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200815A_ABST
    Figure CN120200815A_ABST
Patent Text Reader

Abstract

The invention provides a network attack analysis method and device based on an attack chain, and electronic equipment, and the method comprises the steps: carrying out the matching of alarm data based on a predefined attack chain model, dividing an attack stage corresponding to each alarm data, carrying out the association of each alarm data based on the attack stage of each alarm data, and obtaining an alarm data association graph, based on the alarm data association, an attack link containing a complete attack stage is extracted from the first attack stage for analysis, and because the alarm data is usually a large amount of dispersed data, data belonging to the same attack chain can be found from the large amount of dispersed data based on the attack stage by dividing the attack stage. The association between the alarm data can be found, so that the hidden attack behavior can be found, and the attack analysis efficiency and the attack behavior detection rate can be improved. Meanwhile, the alarm data can be identified as the attack behavior only when forming a complete attack stage, so that the false alarm of the attack behavior is reduced, and the analysis accuracy of the attack behavior is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a method, apparatus, and electronic device for analyzing network attacks based on an attack chain. Background Art

[0002] With the rapid development of network technology, network attack means have become increasingly complex and changeable. Traditional network security protection measures often focus on single-layer defense and are difficult to cope with highly complex and concealed network attacks.

[0003] Specifically, it is difficult for the existing technology to accurately determine whether an attack is successful and its impact scope from a large number of alarms, and it requires a large amount of manual verification cost; in addition, due to timeliness and the behavior of attackers forging and simulating real users, it is very difficult to discover relatively concealed attack behaviors, and it is impossible to clearly distinguish information such as the attack methods and attack targets of attackers. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method, apparatus, and electronic device for analyzing network attacks based on an attack chain to improve the accuracy of network attack behavior analysis.

[0005] According to one aspect of the present invention, there is provided a method for analyzing network attacks based on an attack chain, the method comprising:

[0006] Obtaining attribute information of each alarm data, where the attribute information includes the generation time of the alarm data and an attacker identifier;

[0007] Performing stage matching on each alarm data based on the attribute information of each alarm data according to a preset attack chain model, obtaining an attack stage corresponding to each alarm data, the preset attack chain model being preset based on a sequential attack stage, and multiple attack behaviors being included in different attack stages;

[0008] Associating each alarm data based on the attack stage information corresponding to each alarm data to obtain an alarm data association graph, where the alarm data association graph includes multiple nodes and edges between each node, where each node corresponds to each alarm data one by one, and each edge is used to represent the association relationship between nodes, and the association relationship includes a time relationship and an attacker relationship;

[0009] Traversing the alarm data association graph, and extracting multiple attack links from the alarm data in the first attack stage based on the edges between each node; where each attack link includes alarm data of the complete sequential attack stage;

[0010] Analyzing each attack link based on a preset analysis rule to determine whether the attack link is a real attack behavior.

[0011] In a possible embodiment, the attribute information further includes an alarm risk level and an attack source, and the method further includes:

[0012] Based on the risk levels and attack sources of the respective alarm data, screening the respective alarm data according to a preset risk level threshold and / or attack source to obtain the screened alarm data;

[0013] The step of performing stage matching on the respective alarm data based on the preset attack chain model according to the attribute information of the respective alarm data to obtain the attack stage corresponding to each alarm data includes:

[0014] Performing stage matching on the respective alarm data based on the preset attack chain model according to the attribute information of the screened respective alarm data to obtain the attack stage corresponding to each alarm data.

[0015] In a possible embodiment, the step of correlating the respective alarm data according to the attack stage information corresponding to the respective alarm data to obtain an alarm data correlation graph includes:

[0016] Based on the attribute information of the respective alarm data, determining associated alarm data with the same attack source, adjacent time periods, the same attack technique, or the same attack payload;

[0017] Adding edges between the nodes corresponding to the respective associated alarm data, and adding edge attributes to the respective edges according to the association relationships represented by the respective edges.

[0018] In a possible embodiment, the method further includes: for each attack link, determining the alarm data belonging to the same attack stage in the same attack link;

[0019] Aggregating the alarm data of the same attack stage in the same attack link to obtain each target attack chain.

[0020] According to another aspect of the present invention, there is provided a network attack analysis device based on an attack chain, the device including:

[0021] An acquisition module, configured to acquire the attribute information of each alarm data, where the attribute information includes the generation time of the alarm data and the attacker identifier;

[0022] A matching module, configured to perform stage matching on the respective alarm data based on the preset attack chain model according to the attribute information of the respective alarm data to obtain the attack stage corresponding to each alarm data, where the preset attack chain model is preset based on a sequential attack stage, and multiple attack behaviors are included in different attack stages;

[0023] An association module, configured to associate each piece of the alarm data based on the attack stage information corresponding to each piece of the alarm data, so as to obtain an alarm data association graph, where the alarm data association graph includes a plurality of nodes and edges between the nodes. Each of the nodes corresponds to each piece of the alarm data one by one, and each of the edges is used to represent the association relationship between the nodes, and the association relationship includes a time relationship and an attacker relationship;

[0024] An extraction module, configured to traverse the alarm data association graph, and extract multiple attack chains from the alarm data in the first attack stage based on the edges between the nodes; each of the attack chains includes the alarm data of the complete sequential attack stage;

[0025] An analysis module, configured to analyze each of the attack chains based on a preset analysis rule to determine whether the attack chain is a real attack behavior.

[0026] In a possible embodiment, the attribute information further includes an alarm risk level and an attack source, and the apparatus further includes:

[0027] A screening module, configured to screen each piece of the alarm data based on the risk level and the attack source of each piece of the alarm data, and obtain the screened alarm data according to a preset risk level threshold and / or an attack source;

[0028] The step of performing stage matching on each piece of the alarm data based on the attribute information of each piece of the alarm data according to a preset attack chain model to obtain the attack stage corresponding to each piece of the alarm data includes:

[0029] Performing stage matching on each piece of the screened alarm data based on the attribute information of each piece of the alarm data according to a preset attack chain model to obtain the attack stage corresponding to each piece of the alarm data.

[0030] In a possible embodiment, the step of associating each piece of the alarm data based on the attack stage information corresponding to each piece of the alarm data to obtain an alarm data association graph includes:

[0031] Determining the associated alarm data with the same attack source, adjacent time periods, the same attack method or the same attack payload based on the attribute information of each piece of the alarm data;

[0032] Adding an edge between the nodes corresponding to each piece of the associated alarm data, and adding an edge attribute to each of the edges according to the association relationship represented by each of the edges.

[0033] In a possible embodiment, the apparatus further includes:

[0034] An aggregation module, configured to determine, for each of the attack chains, alarm data belonging to the same attack phase in the same attack chain; aggregate the alarm data of the same attack phase in the same attack chain to obtain each target attack chain.

[0035] According to another aspect of the present invention, there is provided an electronic device, including:

[0036] A processor; and

[0037] A memory storing a program,

[0038] wherein the program includes instructions that, when executed by the processor, cause the processor to execute any one of the above-mentioned attack chain-based network attack analysis methods.

[0039] According to another aspect of the present invention, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute any one of the above-mentioned attack chain-based network attack analysis methods.

[0040] In one or more technical solutions provided in the embodiments of the present invention, by matching alarm data based on a pre-defined attack chain model, the attack phases corresponding to each alarm data are divided, and each alarm data is associated based on the attack phases of each alarm data to obtain an alarm data association graph. Based on this alarm data association, attack chains including complete attack phases are extracted from the first attack phase for analysis. Since alarm data is usually a large amount of scattered data, dividing the attack phases can find data belonging to the same attack chain from a large amount of scattered data based on the attack phases, which helps to discover the association between alarm data and then find hidden attack behaviors, improving the efficiency of attack analysis and the detection rate of attack behaviors. At the same time, since alarm data needs to form a complete attack phase to be recognized as an attack behavior, the false alarm of attack behaviors is reduced, and the accuracy of attack behavior analysis is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In the following description of exemplary embodiments with reference to the accompanying drawings, more details, features, and advantages of the present invention are disclosed. In the drawings:

[0042] Figure 1 is a schematic flowchart of a method for attack chain-based network attack analysis provided by an embodiment of the present invention;

[0043] Figure 2 is another schematic flowchart of a method for attack chain-based network attack analysis provided by an embodiment of the present invention;

[0044] Figure 3 is a schematic logical structure diagram of an attack chain-based network attack analysis device provided by an embodiment of the present invention;

[0045] Figure 4 The block diagram of an exemplary electronic device that can be used to implement the embodiments of the present invention is shown. Detailed implementation manners

[0046] Embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.

[0047] It should be understood that the various steps recorded in the method embodiments of the present invention can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.

[0048] The term "including" and its variants used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order of functions executed by these devices, modules or units or their interdependent relationships.

[0049] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly stated in the context, it should be understood as "one or more".

[0050] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0051] In the related art, common network alarm analysis methods are divided into three categories:

[0052] 1. Analysis methods based on a single alarm: The alarm itself contains some information sources such as attacker information, attack behavior, time, target, etc. By analyzing the information in the alarm, analysts can make reasonable judgments on the alarm.

[0053] 2. Analysis method based on multi-alarm association: For attackers, a single attack behavior often generates more than one alarm. Therefore, when conducting alarm analysis, a large number of abnormal alarms within adjacent time periods or alarms of the same type are often combined to judge the attack behavior.

[0054] 3. Analysis method based on attack effectiveness: Attackers usually launch attacks with specific purposes, such as stealing data, account passwords, uploading backdoors, etc. Alarm analysis can also be carried out by judging whether the attacker has subsequent behaviors of successful attacks to analyze the attacks in a timely manner and take response measures.

[0055] The above methods are difficult to accurately determine whether the attack is successful and the scope of influence from a large number of alarms, and they require a large amount of manual verification costs. In addition, due to timeliness and the attacker's forgery and simulation of real user behaviors, it is difficult to detect relatively hidden attack behaviors, and it is impossible to clearly distinguish information such as the attacker's attack methods and attack targets.

[0056] Based on this, the embodiments of the present invention provide a network attack analysis method, device, and electronic device based on an attack chain. The network attack analysis method based on an attack chain provided by the embodiments of the present invention can be applied to any electronic device with network attack analysis functions. The electronic device can be a server, a computer, a mobile terminal, etc. The solution of the present invention will be described below with reference to the accompanying drawings:

[0057] Figure 1 FIG. is a schematic flow chart of a network attack analysis method based on an attack chain provided by an embodiment of the present invention, which may include the following steps:

[0058] S101. Obtain the attribute information of each alarm data, where the attribute information includes the generation time of the alarm data and the attacker identifier;

[0059] S102. Based on a preset attack chain model, perform stage matching on each alarm data based on the attribute information of each alarm data to obtain the attack stage corresponding to each alarm data. The preset attack chain model is preset based on the sequential attack stages, and multiple attack behaviors are included in different attack stages;

[0060] S103. Based on the attack stage information corresponding to each alarm data, associate each alarm data to obtain an alarm data association graph. The alarm data association graph includes multiple nodes and edges between the nodes. Among them, each node corresponds to each alarm data one by one, and each edge is used to represent the association relationship between the nodes. The association relationship includes a time relationship and an attacker relationship;

[0061] S104. Traverse the alarm data association graph, and extract multiple attack chains from the alarm data in the first attack stage based on the edges between nodes; wherein, each of the attack chains contains the alarm data of the complete timing attack stage.

[0062] S105. Analyze each of the attack chains based on a preset analysis rule to determine whether the attack chain is a real attack behavior.

[0063] Applying the embodiments of the present invention, by matching alarm data based on a pre-defined attack chain model, dividing the attack stages corresponding to each alarm data, and associating each alarm data based on the attack stages of each alarm data, an alarm data association graph is obtained. Based on this alarm data association, attack chains containing complete attack stages are extracted from the first attack stage for analysis. Since alarm data is usually a large amount of scattered data, by dividing the attack stages, it is possible to find the data belonging to the same attack chain from a large amount of scattered data based on the attack stages, which helps to discover the association between alarm data and then find hidden attack behaviors, improving the efficiency of attack analysis and the detection rate of attack behaviors. At the same time, since alarm data needs to form a complete attack stage to be recognized as an attack behavior, false alarms of attack behaviors are reduced, and the accuracy of attack behavior analysis is improved.

[0064] The following is an exemplary description of S101 - S105:

[0065] In a possible embodiment, the network attack behavior analysis method based on an attack chain provided by the embodiments of the present invention can be applied to a distributed cluster. A distributed cluster is a system composed of a group of interconnected computers or servers, which are regarded as a whole and work together to provide services with high performance, high availability, and scalability. In the distributed cluster, various alarm data generated within the cluster can be monitored through a monitoring tool, and the above monitoring tool can be Prometheus, Nagio, etc.

[0066] Correspondingly, in S101, the alarm data and the attribute information of the alarm data can be obtained through the monitoring tool. Exemplarily, the alarm data can be obtained through a preset interface of the monitoring tool, and the preset interface is used to interact with the alarm data collected by the monitoring tool. As another possible implementation manner, the monitoring tool can store the collected alarm data in a preset database, and correspondingly, the alarm data and the attribute information of the alarm data can be obtained from the preset database. In a possible embodiment, the above alarm data can also be obtained by pre-writing scripts, monitoring logs, etc., and the present invention does not make specific limitations thereto.

[0067] The attribute information of the above alarm data is used to identify the basic information of the alarm data. The attribute information may include the generation time, source, attacker identifier, attack target, and risk level of the alarm, etc. Among them, the generation time of the alarm data refers to the time node when the monitoring tool detects suspicious activities or attack behaviors and generates an alarm. This time node can be generated based on the custom time within the monitoring tool or according to the geographical time. The source of the alarm data refers to the specific device, system, application program, or network location that triggers the alarm. These sources can be servers, firewalls, intrusion detection systems (IDSs), antivirus software, log management systems, etc. The attacker identifier refers to the unique identifier or description of the entity that initiates the attack behavior. This can be the IP address, domain name, username, email address, phone number, etc. of the attacker, or the characteristics of the tools, techniques, or methods used by the attacker. The attack target refers to the system, network resource, data, or service that the attacker attempts to violate or damage. This can be a specific server, database, website, application program, user account, etc.

[0068] The risk level of the alarm can be obtained according to a pre-trained alarm classification model or according to preset alarm classification rules. Exemplarily, an alarm classification model can be pre-trained based on information such as the alarm source, attacker identifier, and attack target, and information such as the generation time, source, attacker identifier, and attack target of the alarm data can be input into the alarm classification model to obtain the corresponding alarm risk level output. For another example, different risk levels can also be divided for different alarm types. The above alarm types can include network attack types, system failure types, and application security types, etc.

[0069] In a possible embodiment, after obtaining the attribute information of the alarm data, the alarm data can be filtered based on the attribute information. Specifically, the alarm data can be filtered based on the risk level and attack source of each alarm data according to a preset risk level threshold and / or attack source to obtain the filtered alarm data.

[0070] After obtaining the attribute information of the alarm data, the stage matching of each alarm data can be performed based on the attribute information and a predefined attack chain model. The above attack chain model is predefined according to different stages of the attack. Exemplarily, the attack stages included in the attack chain can include the reconnaissance stage, attack attempt stage, vulnerability exploitation stage, defense bypass stage, lateral movement stage, and post-exploitation stage, etc.

[0071] Among them, the reconnaissance stage is the process in which attackers collect information about the target system. Attackers will use various means, such as active scanning, passive sniffing, social engineering, etc., to obtain detailed information about the target system and prepare for subsequent attacks. In the attack attempt stage, attackers will use the information collected in the reconnaissance stage to launch preliminary attack attempts on the target system. These attempts usually include scanning for common vulnerabilities, guessing weak passwords, checking default configurations, etc. The vulnerability exploitation stage is the process in which attackers use security vulnerabilities in the target system to execute malicious code or commands to obtain higher privileges or control the target system. In the defense bypass stage, attackers will try to bypass the security defense mechanisms of the target system, such as firewalls, intrusion detection systems (IDS), antivirus software, etc., to continue the attack. The lateral movement stage is the process in which attackers expand within the internal network of the target system. Attackers will use the obtained access rights and control capabilities to further explore and penetrate other devices or systems in the target network. The post-exploitation stage is the process in which attackers achieve their ultimate attack goals. Attackers will choose appropriate ways to use the obtained access rights and control capabilities according to their purposes and requirements.

[0072] The different attack stages in the attack chain model can include the attack behaviors corresponding to the attack stages. Exemplarily, the main activities in the reconnaissance stage include port scanning, service version detection, operating system identification, domain name and IP address collection, and network topology analysis, etc. Therefore, the alarm data corresponding to such attack behaviors can be stored corresponding to the reconnaissance stage as an attack behavior set. Specifically, information such as the corresponding alarm source and attack target can be stored, and in actual applications, the attribute information of the alarm data can be matched based on this information to determine whether the alarm data is related to the reconnaissance stage.

[0073] The main activities in the attack attempt stage include: vulnerability scanning, weak password guessing, default configuration checking, privilege testing, etc. Among them, weak password guessing refers to trying to guess the weak passwords of the target system through means such as dictionary attacks and brute force cracking. Default configuration checking refers to checking whether the target system has default accounts, unchanged default passwords, unnecessary services, etc. Privilege testing refers to attackers trying to elevate their privileges in the target system, such as through directory traversal, file upload, etc. Correspondingly, the alarm data information corresponding to the above attack means can be stored corresponding to the attack attempt stage to detect the alarm data belonging to the attack attempt stage.

[0074] The exploitation phase includes the following activities: Buffer overflow attack: Taking advantage of the insufficient length limit of the program for input data, sending a large amount of data to the program, causing a buffer overflow and executing malicious code. Kernel exploitation: By exploiting vulnerabilities in the operating system kernel, such as privilege escalation vulnerabilities, arbitrary code execution vulnerabilities, etc., to obtain advanced permissions of the system. Web application exploitation: Taking advantage of vulnerabilities in web applications, such as SQL injection (taking advantage of the improper handling of user input data by the application to inject malicious code into the database to achieve the purpose of attacking the database), cross-site scripting attack (XSS), file inclusion vulnerability, etc., to execute malicious operations or obtain sensitive information.

[0075] The defense bypass phase includes Port hiding: Using means such as custom ports and dynamic ports to avoid the rule restrictions of the firewall. Encrypted communication: Utilizing SSL / TLS encrypted communication to bypass the detection rules of the IDS (Intrusion Detection System). Signature tampering: Modifying the signature or characteristics of malicious code to avoid being recognized by antivirus software. Protocol attack: Taking advantage of protocol vulnerabilities or design flaws, such as fragmentation attack, overlapping sliding window attack, etc., to bypass network defense mechanisms.

[0076] The lateral movement phase includes Network scanning: Scanning the internal network to discover live hosts and running services. Credential hijacking: Utilizing the obtained credentials (such as usernames and passwords, tokens, etc.) to access other systems or resources. Remote Desktop Protocol (RDP) exploitation: Connecting to other Windows systems through the RDP protocol and accessing them using the existing credentials or vulnerabilities. Ingress tunneling: Utilizing means such as proxy servers and tunneling technologies to bypass the internal network restrictions and access other systems or the Internet.

[0077] The post-exploitation phase includes Data theft: Stealing sensitive information from the target system. Software installation: Installing software in the target system to encrypt important files. Long-term latency: implanting a backdoor or malicious program in the target system to maintain long-term control and monitoring of the system. Sabotage activities: Tampering with, deleting, or destroying the data of the target system, resulting in business interruption or data loss.

[0078] In a possible embodiment, the attack behaviors included in each attack phase can be an AND relationship or an OR relationship. Among them, the AND relationship means that the attribute information of the alarm data needs to match all the attack behaviors included in the attack phase to determine that the alarm data belongs to this phase. The OR relationship means that as long as the attribute information of the alarm data matches at least one of the attack behaviors included in the attack phase, it can be determined that the alarm data belongs to this phase.

[0079] In a possible embodiment, the above attack chain model may include sequential attack phases, that is, each attack phase may include a timing identifier for marking the order of the attack phase in a complete attack chain. As a possible implementation, after matching each alarm data based on the attack chain model and determining the attack phase to which each alarm data belongs, a timing identifier may be added to each alarm data to mark the order of the alarm data in the attack chain.

[0080] After completing the division of the attack phases of each alarm data, each alarm data may be imported into a graph database for relationship association to obtain an alarm data association graph. The alarm data association graph includes multiple nodes and edges between the nodes. Among them, each of the nodes corresponds to each of the alarm data one by one, and each of the edges is used to represent the association relationship between the nodes. The association relationship includes a time relationship and an attacker relationship.

[0081] The edges between the above nodes may be determined based on the attribute information of the alarm data corresponding to the nodes. Specifically, the association between each alarm data may be determined based on the attribute information. The association may include the same attacker, adjacent time periods, the same attack method, the same attack payload, etc. Among them, the same attacker may be determined through the attacker identifier, the adjacent time period may be determined through the generation time of the alarm data, and the same attack method and the same attack payload may both be determined through the alarm type.

[0082] After obtaining the alarm data association graph, each attack chain may be identified based on the association graph. In a possible embodiment, the alarm data association graph may be traversed to determine each predefined first attack phase. The first attack phase refers to the attack phase that is the first in terms of timing in the attack chain. For example, it may be the above reconnaissance phase. Then, starting from the first attack phase, the alarm data that has an edge with the alarm data of the first attack phase and belongs to different attack phases may be extracted as the same attack chain according to the edges between the nodes. Exemplarily, for nodes A, B, C, and D, A belongs to the first attack phase, B and C belong to the second attack phase, D belongs to the third attack phase, and there is an edge between A and B, and an edge between B and D. Therefore, the attack chain A - B - D may be obtained.

[0083] In a possible embodiment, during the process of the associated nodes determining the attack chain, it is possible to determine whether two alarm data belong to the same attack chain based on the dependency strength represented by the edge. As described above, the edge attributes of the edge are determined based on the dependency relationship represented by the edge. There may be various dependency relationships between two alarm data, such as the two alarm data belonging to the same attacker, adjacent time periods, the same attack method, the same attack payload, etc. Therefore, a dependency strength threshold can be set in advance. The dependency strength threshold can be that the dependency relationship between the alarm data includes three or more. Correspondingly, only the alarm data connected by an edge with a dependency strength higher than the dependency strength threshold can be classified into the same attack chain. Exemplarily, the alarm data can be considered to belong to the same attack chain only when they satisfy three or more relationships among the same attacker, adjacent time periods, the same attack method, and the same attack payload.

[0084] Through the above technical solution, strongly associated alarm data are classified into the same attack chain, avoiding classifying different attack behaviors into the same attack chain, which may affect the accuracy of the supply analysis or cause supply omission, and improving the attack detection rate and accuracy.

[0085] In a possible embodiment, for the alarm data in the same first attack stage, multiple alarm data belonging to the same attack stage may be determined. This may be caused by the same attacker making multiple attempts during this attack, and it is not necessary to analyze all the alarm data generated during this process. Therefore, in order to reduce the amount of data to be analyzed and thus improve the attack analysis efficiency, the above method may further include the following steps:

[0086] For each of the attack links, determine the alarm data in the same attack stage belonging to the same attack link; aggregate the alarm data in the same attack stage in the same attack link to obtain each target attack chain.

[0087] Exemplarily, for nodes A, B, C, and D, A belongs to the first attack stage, B and C belong to the second attack stage, D belongs to the third attack stage, and there are edges between A and B, C, and between B, C and D. Therefore, the attack chains A - B and C - D can be obtained. In this case, nodes B and C can be aggregated in this attack chain, and only one alarm data in the second attack stage is retained. The above aggregation can be to randomly select alarm data for retention in the same attack stage of the same attack chain, or to screen the attribute information of the alarm data belonging to the same stage and retain the attribute information that appears most frequently in each item of attribute information.

[0088] After obtaining each attack chain, attack behavior analysis can be performed on each attack chain. Specifically, based on a preset analysis rule, each of the above-mentioned attack links is analyzed to determine whether the attack link is a real attack behavior. The above-mentioned preset analysis rule can include the timing characteristics of attack behaviors, that is, the attack chain can be compared with the timing characteristics of preset attack behaviors to determine whether the attack chain generates real attack behaviors. In a possible embodiment, since the number of attack chains obtained through the above technical solution is small, the attack chains can be sent to a preset client so that relevant personnel can analyze the attack chains based on the preset client to determine whether the attack behavior is a real attack behavior and the response measures for the attack behavior.

[0089] In a possible embodiment, the attack chains can be sent to a pre-trained attack behavior analysis model, which can be pre-trained based on historical attack chain records and the corresponding attack results of the historical attack chain records. Inputting the obtained above-mentioned attack chains into the attack behavior analysis model can obtain the attack prediction results output by the attack behavior analysis model. Based on the attack prediction results, a work order can be generated to enable relevant personnel to repair the corresponding vulnerabilities.

[0090] As Figure 2 shown, Figure 2 FIG. is another flowchart of the network attack warning correlation analysis method based on attack chains provided by the embodiment of the present invention, which may include the following steps:

[0091] Alarm collection. In this step, the existing alarm data can be classified and graded. For example, the importance level, source, and attacker information of the alarm data can be marked, and an importance level threshold, source, and attacker whitelist can be set to filter each alarm data, only retaining the alarm data with an importance level higher than the threshold and the source and attacker identifiers not in the whitelist to reduce the amount of data for subsequent analysis.

[0092] Phase division. In this step, each alarm data can be divided into phases according to a predefined attack chain model. The above-mentioned attack chain model can be divided according to the predefined attack phases, which can include a reconnaissance phase, an attack attempt phase, a vulnerability exploitation phase, a defense bypass phase, a lateral movement phase, and a post-exploitation phase, etc. Each attack phase of the attack chain model contains an alarm data set for identifying the attack phase. By matching the alarm data sets included in each attack phase of the attack chain model and the alarm data collected in the previous step, each alarm data can be divided into phases, and an attack phase identifier can be added to each alarm data.

[0093] Association matching: Import the alarms that have been divided into stages into the graph database for relationship association. Among them, the association types between alarms need to be defined, such as the same attacker, adjacent time periods, the same attack method, the same attack payload, etc., and different alarms are chained together.

[0094] Chained attack behavior extraction and identification: In the graph database, through graph traversal operations, different alarms in the first stage are used as starting points, and the connected alarms belonging to the same stage in the whole graph are extracted, and the alarms with close association relationships are regarded as alarms in the same attack chain for processing.

[0095] Result analysis: Analyze the extracted alarms to determine whether they are real attack behaviors, and promptly take corresponding response measures according to the attack behaviors.

[0096] Applying the embodiments of the present invention, classifying and grading all security alarms based on the attack chain model, and at the same time tracking the paths of strongly associated alarms to extract hidden attack behaviors therein, overcoming the characteristics of single alarm timeliness, attacker attack method diversity, etc., improving the efficiency of alarm analysis and processing and the detection rate of real attack behaviors, and reducing the processing cost of manually analyzing a large number of alarms.

[0097] Based on the same inventive concept, the embodiments of the present invention also provide a network attack analysis device based on an attack chain, as Figure 3 shown. The device 300 may include:

[0098] An acquisition module 301, configured to acquire attribute information of each alarm data, where the attribute information includes the generation time of the alarm data and the attacker identifier;

[0099] A matching module 302, configured to perform stage matching on each alarm data based on the attribute information of each alarm data based on a preset attack chain model, to obtain the attack stage corresponding to each alarm data. The preset attack chain model is preset based on the timing attack stage, and multiple attack behaviors are included in different attack stages;

[0100] An association module 303, configured to associate each alarm data based on the attack stage information corresponding to each alarm data, to obtain an alarm data association graph. The alarm data association graph includes multiple nodes and edges between each node. Among them, each node corresponds to each alarm data one by one, and each edge is used to represent the association relationship between nodes. The association relationship includes a time relationship and an attacker relationship;

[0101] An extraction module 304, configured to traverse the alarm data association graph, and extract multiple attack links starting from the alarm data in the first attack stage based on the edges between each node; among them, each attack link includes the alarm data of the complete timing attack stage.

[0102] An analysis module 305, configured to analyze each of the attack chains based on a preset analysis rule to determine whether the attack chain is a real attack behavior.

[0103] In a possible embodiment, the attribute information further includes an alarm risk level and an attack source, and the device further includes:

[0104] A screening module, configured to screen each of the alarm data based on the risk level and attack source of each of the alarm data, according to a preset risk level threshold and / or attack source, to obtain the screened alarm data;

[0105] The step of performing phase matching on each of the alarm data based on the attribute information of each of the alarm data according to a preset attack chain model to obtain the attack phase corresponding to each of the alarm data includes:

[0106] Performing phase matching on each of the screened alarm data based on the attribute information of each of the screened alarm data according to a preset attack chain model to obtain the attack phase corresponding to each of the alarm data.

[0107] In a possible embodiment, the step of associating each of the alarm data based on the attack phase information corresponding to each of the alarm data to obtain an alarm data association graph includes:

[0108] Based on the attribute information of each of the alarm data, determining the associated alarm data with the same attack source, adjacent time periods, the same attack method, or the same attack payload;

[0109] Adding edges between the nodes corresponding to each of the associated alarm data, and adding edge attributes to each of the edges according to the association relationship represented by each of the edges.

[0110] In a possible embodiment, the device further includes:

[0111] An aggregation module, configured to, for each of the attack chains, determine the alarm data belonging to the same attack phase in the same attack chain; aggregating the alarm data of the same attack phase in the same attack chain to obtain each target attack chain.

[0112] Wherein, in the present invention, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0113] An exemplary embodiment of the present invention also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, it is configured to cause the electronic device to execute the method according to the embodiment of the present invention.

[0114] An exemplary embodiment of the present invention also provides a non-transitory computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor of a computer, it is configured to cause the computer to execute the method according to the embodiment of the present invention.

[0115] An exemplary embodiment of the present invention also provides a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is configured to cause the computer to execute the method according to the embodiment of the present invention.

[0116] Referring to Figure 4 , a block diagram of an electronic device 400 that can be a server or a client of the present invention will now be described. It is an example of a hardware device applicable to various aspects of the present invention. The electronic device is intended to represent various forms of digital electronic computer devices, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0117] As Figure 4 shown, the electronic device 400 includes a computing unit 401, which can execute various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 can also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0118] Multiple components in the electronic device 400 are connected to the I / O interface 405, including: an input unit 406, an output unit 407, a storage unit 408, and a communication unit 409. The input unit 406 can be any type of device capable of inputting information into the electronic device 400. The input unit 406 can receive input digital or character information, and generate key signal inputs related to user settings and / or function controls of the electronic device. The output unit 407 can be any type of device capable of presenting information, and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 408 can include, but is not limited to, magnetic disks and optical disks. The communication unit 409 allows the electronic device 400 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks, and can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a BluetoothTM device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0119] The computing unit 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 401 executes the various methods and processes described above. For example, in some embodiments, any of the above-described network attack analysis methods based on the attack chain can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 400 via the ROM 402 and / or the communication unit 409. In some embodiments, the computing unit 401 can be configured to execute any of the above-described network attack analysis methods based on the attack chain by any other suitable means (e.g., by means of firmware).

[0120] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine and partially on a remote machine as an independent software package, or executed entirely on a remote machine or server.

[0121] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0122] As used in the present invention, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., a disk, an optical disk, a memory, a programmable logic device (PLD)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.

[0123] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0124] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0125] A computer system can include clients and servers. The clients and servers are generally remote from each other and typically interact through a communication network. The client - server relationship is created by computer programs that run on the respective computers and have a client - server relationship with each other.

Claims

1. A network attack analysis method based on attack chain, characterized in that: The method comprises: Acquire attribute information of each alarm data, wherein the attribute information includes a generation time of the alarm data and an attacker identifier; Based on a preset attack chain model, each of the alarm data is stage matched based on the attribute information of each of the alarm data to obtain an attack stage corresponding to each of the alarm data, wherein the preset attack chain model is pre-set based on a time-series attack stage, and different attack stages contain multiple attack behaviors; Associating each of the alarm data based on the attack stage information corresponding to each of the alarm data to obtain an alarm data association graph, wherein the alarm data association graph includes a plurality of nodes and edges between the nodes, wherein each of the nodes corresponds one-to-one to each of the alarm data, and each of the edges is used to represent an association relationship between the nodes, wherein the association relationship includes a time relationship and an attacker relationship; Traversing the alarm data association graph, extracting multiple attack links based on the edges between nodes starting from the alarm data of the first attack stage; wherein each of the attack links contains complete alarm data of the timing attack stage; Each of the attack links is analyzed based on preset analysis rules to determine whether the attack link is a real attack behavior.

2. The method according to claim 1, characterized in that The attribute information also includes an alarm risk level and an attack source. The method further includes: Based on the risk level and attack source of each of the alarm data, each of the alarm data is screened according to a preset risk level threshold and / or attack source to obtain screened alarm data; The step of performing stage matching on each of the alarm data based on the attribute information of each of the alarm data based on the preset attack chain model to obtain the attack stage corresponding to each of the alarm data includes: Based on the preset attack chain model and based on the attribute information of each of the screened alarm data, stage matching is performed on each of the alarm data to obtain the attack stage corresponding to each of the alarm data.

3. The method according to claim 1, characterized in that The step of associating each of the alarm data based on the attack stage information corresponding to each of the alarm data to obtain an alarm data association graph includes: Based on the attribute information of each of the alarm data, determining the associated alarm data of the same attack source, adjacent time periods, the same attack method or the same attack payload; Edges are added between the nodes corresponding to the associated alarm data, and edge attributes are added to the edges according to the associated relationships represented by the edges.

4. The method according to claim 1, characterized in that: The method further comprises: For each of the attack links, determining alarm data belonging to the same attack stage in the same attack link; The alarm data of the same attack stage in the same attack link are aggregated to obtain each target attack chain.

5. A network attack analysis device based on attack chain, characterized in that: The device comprises: An acquisition module, used to acquire attribute information of each alarm data, wherein the attribute information includes a generation time of the alarm data and an attacker identifier; A matching module, configured to perform stage matching on each of the alarm data based on the attribute information of each of the alarm data based on a preset attack chain model, so as to obtain an attack stage corresponding to each of the alarm data, wherein the preset attack chain model is pre-set based on a time-series attack stage, and different attack stages contain multiple attack behaviors; an association module, configured to associate each of the alarm data based on the attack stage information corresponding to each of the alarm data, to obtain an alarm data association graph, wherein the alarm data association graph includes a plurality of nodes and edges between the nodes, wherein each of the nodes corresponds one-to-one to each of the alarm data, and each of the edges is used to represent an association relationship between the nodes, wherein the association relationship includes a time relationship and an attacker relationship; An extraction module, used to traverse the alarm data association graph, and extract multiple attack links based on the edges between nodes starting from the alarm data of the first attack stage; wherein each of the attack links contains complete alarm data of the timing attack stage; The analysis module is used to analyze each of the attack links based on preset analysis rules to determine whether the attack link is a real attack behavior.

6. The device according to claim 5, characterized in that The attribute information also includes an alarm risk level and an attack source, and the device also includes: A screening module, for screening each of the alarm data according to a preset risk level threshold and / or attack source based on the risk level and attack source of each of the alarm data, to obtain screened alarm data; The step of performing stage matching on each of the alarm data based on the attribute information of each of the alarm data based on the preset attack chain model to obtain the attack stage corresponding to each of the alarm data includes: Based on the preset attack chain model and based on the attribute information of each of the screened alarm data, stage matching is performed on each of the alarm data to obtain the attack stage corresponding to each of the alarm data.

7. The device according to claim 5, characterized in that The step of associating each of the alarm data based on the attack stage information corresponding to each of the alarm data to obtain an alarm data association graph includes: Based on the attribute information of each of the alarm data, determining the associated alarm data of the same attack source, adjacent time periods, the same attack method or the same attack payload; Edges are added between the nodes corresponding to the associated alarm data, and edge attributes are added to the edges according to the associated relationships represented by the edges.

8. The device according to claim 5, characterized in that The device also includes: The aggregation module is used to determine the alarm data belonging to the same attack stage in the same attack link for each of the attack links; and aggregate the alarm data of the same attack stage in the same attack link to obtain each target attack chain.

9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 4.

10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to make a computer execute the method according to any one of claims 1-4.

Citation Information

Cited By

  • Alarm feature extraction method for business risk control and related device

    CN120979900A

  • Vehicle-mounted network cross-subsystem attack chain reconstruction method based on IDS alarm tracing

    CN121690831A