Network attack perception induction method
By constructing APT malware gene model and graph neural network predicting attack paths, guiding the attack to migrate to bait, the problem of lack of initiative and traceability in power system network attack defense is solved, and active identification and defense of complex threats is achieved.
Patent Information
- Application Number
- CN202510451410.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, the power system's cyberattack defense lacks initiative and traceability capabilities, and cannot effectively induce attack behavior, resulting in frequent security incidents.
By building APT malware gene models, obtaining and analyzing malware behavior, establishing an APT family gene library, using graph neural networks to predict attack paths, and guiding the attacks to migrate to bait to attract attackers to detect and attack.
It realizes active identification and defense of complex threats, improves the defense capabilities of network attacks, and enhances the initiative and response speed of network security.
Smart Images

Figure CN120263493A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security attacks, and particularly to a network attack perception and induction method. Background Art
[0002] At present, the power grid is evolving towards intelligence and interconnection. The construction of a new power system depends on information technology as a support to ensure the visibility and controllability of the power grid, which further deepens the degree of cross-integration of power and information. Modern information technologies such as communication, big data, flexible control, and intelligent optimization in the new power system efficiently realize the all-round data connection and acquisition of the power source, network, and load. This construction process is accompanied by the access of a large number of electronic devices and information software, and data transmission and transformation are carried out through new type current transformers. While greatly improving the informatization, automation, and interactivity of the power system, it also leads to a profound change in the security threats faced by the power system. The vulnerability of the information network makes the power system infrastructure more vulnerable to illegal access from outside the network. Attacks on the power system network emerge in an endless stream, the security problems faced are becoming increasingly severe, security incidents occur frequently, and the power system has been attacked by ransomware.
[0003] Previous network attacks used a passive defense method, waiting for the active initiation of network attacks and performing passive interception of network attacks. They could not induce attack behaviors and had problems of lack of initiative and lack of traceability ability.
[0004] Chinese Patent "CN114157450A Network Attack Induction Method and Device Based on Internet of Things Honeypot" discloses a network attack induction method and device based on an Internet of Things honeypot. The method includes: constructing a virtual environment of the Internet of Things honeypot, detecting attack behaviors against the virtual environment, determining attack information according to the attack behaviors, where the attack information includes the target attack type corresponding to the attack behavior, analyzing the target attack type, determining simulated response information, and sending the simulated response information to the attacker terminal that issues the attack behavior. It can be seen that implementing the present invention can determine attack information and analyze the target attack type of the attack, which is beneficial to improving the accuracy and effectiveness of capturing network attacks, and can feedback the determined simulated response information to the attacker terminal, which is beneficial to enhancing the security protection ability of Internet of Things devices against network attacks.
[0005] The Chinese patent "CN114499915A A Trap Attack Method, Device and System Combining Virtual Nodes and Honeypots" discloses a trap attack method, device and system combining virtual nodes and honeypots. A trap attack method combining virtual nodes and honeypots includes receiving attack behaviors detected by the honeypot against the virtual nodes; analyzing the attack behaviors to determine whether they belong to threat perception; when it is determined that they do not belong to threat perception, ignoring this attack behavior; when it is determined that they belong to threat perception, calling the honeypot to simulate a real device to make corresponding responses to trap the attacker into continuing the attack. After it is determined as dangerous perception, the honeypot encrypts the virtual data packet to achieve the effect of trapping the attacker. At this time, the virtual node is mainly the carrier of the virtual data packet, and the honeypot is mainly used to obtain the attack behavior. The combination of the two enables the virtual node to also make a trap response to the attacker during the process of trapping the attacker into attacking, making the virtual node more real and the trap attack more effective.
[0006] The Chinese patent "CN114915493A A Trap Deployment Method for Network Attacks on Power Monitoring Systems" discloses a trap deployment method for network attacks on power monitoring systems, including: building a power monitoring system network honeypot system based on the honeypot technology; designing baits based on the honeypot system, and the honeypots are interconnected through the baits to form a honeynet; analyzing and tracing the attack events captured by the system, and real-time monitoring of dangerous nodes to form system alarms. The present invention provides a trap deployment method for network attacks on power monitoring systems, doping camouflage information implemented by the honeypot technology in the information sources frequently used by attackers, inducing the attackers to collect incorrect information during the preparation stage and aiming the attack target at the honeypot. The present invention supports data push to achieve message linkage, can push the hacker threat data fields recorded by the honeypot platform to other security visualization platforms as needed, can provide source logs for sufficient threat intelligence data analysis, realizes the advantages of linkage with other third-party devices, and discovers attacks and alarms in a timely manner.
[0007] Compared with the prior art, the prominent technical solution of the present invention is an attack perception method for APT family analysis. By means of the APT malicious behavior gene model and the gene similarity detection algorithm, a malicious behavior gene library is constructed to identify malicious attack behaviors. On this basis, a graph neural network is used to predict the attack path of the APT malicious behavior chain; further, a guidance method based on attack path prediction is studied to guide the attack to migrate to deceptive security resources to attract the attacker to detect, attack and utilize them. Summary of the Invention
[0008] Aiming at the deficiencies of the prior art, the present invention provides a network attack perception and guidance method, which solves the problems raised in the above background technology.
[0009] To achieve the above objectives, the present invention is implemented through the following technical solutions: A network attack perception and induction method, comprising the following steps:
[0010] Step 101: Obtain the APT malware gene model, analyze the behaviors generated during the operation of the malware to obtain the malware gene sequence, summarize the malware gene sequences to obtain the malware gene dataset, classify the malware gene dataset, and construct the APT family gene library;
[0011] Step 102: Obtain the APT family gene library, classify and extract the APT family gene library, use similarity calculation, and construct a malicious behavior chain in chronological order to obtain the APT malicious behavior gene library;
[0012] Step 103: Obtain the APT malicious behavior gene library, identify APT attack behaviors, construct a state set of the attack path, distinguish between two types of states, hidden state and observable state, establish an attack path prediction model, determine the APT attack path and predict the next APT activity;
[0013] Step 104: Identify the decoy most similar to the predicted next attack target through the target similarity detection method, guide the attack to migrate to the decoy, and attract the attacker to attack the decoy.
[0014] Optionally, the APT malware gene model in Step 101 is used to describe and analyze the characteristics, behaviors, and evolution methods of APT (Advanced Persistent Threat) malware;
[0015] In the model, malware is defined as an entity with genetic characteristics, and its characteristics and functions are regarded as "genes", and "genes" represent the core components of malware, including but not limited to its code structure, propagation mechanism, evasion technology, target selection strategy, and C&C (Command and Control) communication protocol.
[0016] Optionally, the key elements of the gene model are specifically as follows:
[0017] Gene sequence: Corresponding to a specific functional code block or behavior pattern of malware, specifically encryption algorithms, vulnerability exploitation codes, and persistence mechanisms;
[0018] Mutation and evolution: APT malware evades detection by modifying and recombining its gene sequence, developing new evasion techniques or enhancing existing functions;
[0019] Family similarity: Malware of the same APT organization or series shares similar gene characteristics, enabling security researchers to trace and classify different malware samples into corresponding families;
[0020] Genomic analysis: By deeply analyzing malware samples, extracting their genetic features, and constructing a genetic map of malware to help identify unknown threats and predict future variants of malware;
[0021] Immune countermeasures: Developing targeted defense strategies and tools based on genetic models;
[0022] Among them,
[0023] A five-tuple is used to represent the genetic model, Gene = <MD5, env., obj1, obj2, action>, where MD5 represents the name of the malware, env. is the software running environment, obj1 and obj2 respectively represent the object and path of the software execution action, and action represents the execution action of the malware;
[0024] Obtain the behaviors generated during the operation of the malware, extract and arrange them in chronological order according to the genetic model, describe the malware behaviors using a genetic sequence, obtain the malware gene sequence, and summarize the malware gene sequences to obtain a malware gene dataset;
[0025] Classify the malware gene dataset, and aggregate the malware gene datasets belonging to the same APT family to obtain a gene library of the APT family.
[0026] Optionally, in step 101, classify the malware gene dataset, aggregate the malware gene datasets belonging to the same APT family to obtain an aggregated result dataset;
[0027] Optimize the aggregated result dataset, filter out duplicate malware gene datasets, malware gene datasets containing invalid information, and malware gene datasets with high similarity;
[0028] Retain the optimized malware gene dataset to obtain a gene library of the APT family.
[0029] Optionally, the APT (Advanced_Persistent_Threat) malicious behavior gene library in step 102 is a database or knowledge base that stores APT attack characteristics, behavior patterns, malware samples, and their variant information;
[0030] The APT malicious behavior gene library is specifically as follows:
[0031] Attack signature: Unique code snippets or behavior patterns that can identify specific APT attacks or malware families;
[0032] Behavior pattern: Tactics, techniques, and procedures (TTPs) of APT attacks;
[0033] Malware samples: Samples of malware used in known APT attacks, including their various variants and versions;
[0034] IOC (Indicators of Compromise): Including domain names, IP addresses, and file hash values, used to detect and respond to known APT activities;
[0035] Threat intelligence: Background information on the attacker's motives, targets, known activity times, and geographical distribution;
[0036] Analysis report: An in-depth analysis report on a specific APT attack case, including a detailed description of the attack path, tools, and techniques used;
[0037] The specific steps are as follows:
[0038] (1) Obtain the APT family gene library, extract the malware gene sequences in the APT family gene library for similarity calculation;
[0039] (2) Select malware gene sequences with high similarity and construct a malicious behavior chain in chronological order;
[0040] (3) Use a gene similarity detection algorithm to calculate the similarity between gene libraries, between samples, and between samples and gene libraries, and extract malicious behavior genes to identify current attack behaviors;
[0041] (4) Obtain the APT malicious behavior gene library.
[0042] Optionally, the attack path prediction model in step 103 is constructed based on an improved KGAT model. Through the proposed weight training strategy, it realizes the reduction of the search space required for attack path reasoning, solves the path explosion problem, and improves the reasoning efficiency. Combining the continuity and relevance between attack events, an attack path prediction model is proposed. The possible attack paths in the scenario network are explored and formed by combining the graph attention mechanism and knowledge graph reasoning. For the weight parameter w required for establishing the path prediction model, an adaptive weight learning strategy based on attack benefits and attack costs is proposed, aiming to discover the optimal solution of the weight parameter w from the attacker's perspective by combining the current network state and vulnerability information;
[0043] Specifically as follows:
[0044] The generation of the weight parameter w is to make the information utilized in subsequent attack reasoning more focused. From the perspective of the attacker, the severity, exploitation cost, and benefits after exploitation provided by the attributes in the vulnerability entity are used for the subsequent adaptive learning of the weight parameter w. For vulnerabilities and attacks, different weights are assigned to each vulnerability according to its severity. Through the learning strategy of adaptive weights, appropriate weights can be assigned to each vulnerability, thus providing support for the reasoning of the attack path.
[0045] Re-representation of node features. In knowledge graph reasoning, node embeddings are used for the semantic information of nodes. Different neighbor nodes are aggregated into the feature representation of the node according to the obtained weight parameters above for the re-representation of node features. The updated node features aggregate the surrounding information with different weights.
[0046] Attack path prediction. The model uses the Path_Ranking random walk algorithm to predict the possible attack types that a node may be subjected to based on the re-representation results of node features. After completing the attack prediction, the query function of the graph database is used with the start and end entities and the relationship path between them as conditions, and the attacks are associated to form an attack path according to the vulnerabilities exploited by the attacks and the pre- and post-conditions of the attacks.
[0047] Improvement and optimization of the KGAT model. Aiming at the problems of large search scope and path explosion caused by the large number of hosts and vulnerabilities in the scenario network, the KGAT model is correspondingly improved and innovated by combining the semantic features of network attacks. The KGAT model is elaborated in detail from two aspects: the principle and the optimization and improvement of the model.
[0048] Optionally, the improvement and optimization of the KGAT model are as follows:
[0049] (1) Breaking symmetry. By sampling neighbors of nodes, the learning algorithm can see different subsets of nodes, so that different nodes in the graph have different representations.
[0050] For the knowledge graph constructed in the present invention, the graph attention network (GAT) is used for graph representation learning. In GAT, the representation vector of each node is a combination of its own features and the features of neighbor nodes. Thus, the symmetry is broken by sampling neighbors.
[0051] Specifically, for each node i, the update formula in GAT is as follows:
[0052]
[0053] where, h iis the representation vector of node i at the first layer, W0 is the weight matrix of the i-th layer, σ is the activation function, represents the set of neighbors of node i in this formula, and is the normalization factor to prevent the node degree from having too much influence on the representation vector; to break the symmetry or equivalence between nodes, a neighbor sampling operation needs to be introduced into the formula, that is, randomly sample a certain number of nodes S from h i and then perform a weighted average on the representation vectors of these nodes
[0054]
[0055] where S is the sampling quantity; by sampling neighbors, it is ensured that each node can see different neighbor subsets, thus avoiding symmetry or equivalence between nodes;
[0056] (2) Design multi-head attention. Use multiple attention heads, and each head learns different weight assignments. In the multi-head attention mechanism, the input vector is first mapped to different vector spaces by multiple linear mapping layers, then the operations with a single-head attention mechanism are performed in each vector space, and finally the results in different vector spaces are concatenated as the final output vector;
[0057] Thus, a new representation of node feature vectors is obtained. These vectors not only contain the features of the nodes themselves, but also are assigned different weights according to the features of different types of nodes and relationships around them. Subsequently, the updated node feature representations above are used to perform attack prediction and attack path generation using the Path_Ranking algorithm.
[0058] Optionally, in step 104, the attracting attacker probes, attacks, and utilizes the decoy;
[0059] When an attacker attempts to invade, scan, attack, and utilize the decoy, record the attacker's behavior and collect key attack information, such as the attack source IP address, attack method, tools used, and vulnerability exploitation methods.
[0060] The present invention provides a network attack perception induction method, which has the following beneficial effects:
[0061] This network attack perception induction method, by constructing and utilizing the gene model of APT malware, security experts can more effectively identify, track, and defend against such complex and continuously changing threats, while improving the response speed and protection efficiency; this method emphasizes the understanding of the deep characteristics of malware, rather than just the traditional signature-based detection method;
[0062] Obtain the APT malware gene model, analyze the behaviors generated during the operation of the malware to obtain the malware gene sequence, summarize the malware gene sequences to obtain the malware gene dataset, classify the malware gene dataset, and construct the APT family gene library; obtain the APT family gene library, perform classification extraction on the APT family gene library, use similarity calculation, and construct the malicious behavior chain in chronological order to obtain the APT malicious behavior gene library; obtain the APT malicious behavior gene library, identify APT attack behaviors, construct the state set of the attack path, distinguish two types of states, the hidden state and the observable state, establish an attack path prediction model, determine the APT attack path and predict the next APT activity; identify the decoy most similar to the predicted next attack target through the target similarity detection method, guide the attack to migrate to the decoy, and attract the attacker to attack the decoy; the network attack perception induction of the present invention can induce attack behaviors, take the initiative to attack, perceive various types of network attacks, can capture attack information more comprehensively, greatly improve the defense ability against network attacks, and maintain network security. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 It is a flowchart of the network attack perception induction method of the present invention;
[0064] Figure 2 It is a process diagram for constructing the state set of APT attack path prediction of the present invention;
[0065] Figure 3 It is a schematic diagram of the process of the attack path prediction model of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0066] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.
[0067] In the description of the present invention, unless otherwise specified, the meaning of "a plurality" is two or more; the terms "upper", "lower", "left", "right", "inner", "outer", "front end", "backend", "head", "tail", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. In addition, the terms "first", "second", "third", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0068] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "connected" and "connected" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0069] Please refer to Figure 1 , the present invention provides a technical solution: a network attack perception and induction method. For multiple types of APT attacks, it integrates the ATT&CK model and the power system vulnerability pattern, and studies a network attack perception and induction method based on graph neural networks; this method refers to the software gene idea, studies an attack perception method for APT family analysis, constructs a malicious behavior gene library with the help of the APT malicious behavior gene model and the gene similarity detection algorithm, identifies malicious attack behaviors, and on this basis, uses graph neural networks to predict the attack path of the APT malicious behavior chain; further, studies an induction method based on attack path prediction, guides the attack to migrate to a deceptive security resource, and attracts the attacker to detect, attack, and utilize it.
[0070] First, define the APT malware gene model and construct the gene library; use a five-tuple to represent the gene model, Gene = <MD5, env., obj1, obj2, action>, where MD5 represents the malware name, env. is the software running environment, obj1 and obj2 respectively represent the object and path of the software execution action, and action represents the execution action of the malware; by extracting the behaviors generated during the malware operation according to the gene model and arranging them in chronological order, the malware behavior can be described by a series of gene sequences; the set of malware genes under the same APT family is called the gene library of an APT family; in order to ensure the quality of the gene library, add the following rules to streamline and optimize each gene library: 1) Ensure the independence of each gene: 2) Ensure that each gene does not contain invalid information; 3) Ensure that the gene library does not contain more than two highly similar genes.
[0071] Secondly, construct the APT malicious behavior gene library; after constructing the APT family gene library, the malicious behavior gene library can be further condensed from the malicious genes; specifically, extract the gene sequences from the malware and calculate the similarity with this malicious behavior gene library, select the gene sequences with high similarity and construct the malicious behavior chain in chronological order, and calculate the similarity between the gene library and the gene library, between the sample and the sample, and between the sample and the gene library through the gene similarity detection algorithm, and extract the malicious behavior genes to identify the current attack behavior.
[0072] Next, an attack path prediction method; it is constructed based on an improved KGAT model. Through the proposed weight training strategy, it realizes the reduction of the search space required for attack path reasoning, solves the path explosion problem, and improves the reasoning efficiency. Combining the continuity and relevance between attack events, an attack path prediction model is proposed. For the possible attack paths in the scenario network, a method combining graph attention mechanism and knowledge graph reasoning is used to discover and form them. For the weight parameter w required for establishing the path prediction model, an adaptive weight learning strategy based on attack benefit and attack cost is proposed, aiming to discover the optimal solution of the weight parameter w from the perspective of the attacker by combining the current network state and vulnerability information (as Figure 3 shown);
[0073] Construct a state set for attack paths, distinguishing two types of states: hidden states and observable states; malware behavior is the observable state set. To extract the corresponding hidden state set, the correspondence between malicious behavior and hidden states needs to be constructed, and it is necessary to consider which elements are used to represent these hidden states to accurately describe the attacker's attack path; the process of constructing the state set for APT attack path prediction is as Figure 2 shown;
[0074] Referring to the diamond model, an APT attack consists of four core elements: "attacker", "victim", "capability", and "infrastructure". The "attacker" is the direct executor of the attack event. The "victim" is the target of the attack, and the entity referred to as the victim is different in different scenarios. The "capability" is the tool or technology used by the attacker. From detection to the achievement of the ultimate goal, "techniques" exist in every stage of the attack, and the technical details corresponding to each malicious action can reflect the corresponding strategic intent. The "infrastructure" is the channel or carrier through which the attacker maintains privilege control. Further referring to the concept of TTP (Tactics, Techniques, and Procedures), "tactics" refer to the attack strategies adopted by the attacker from information collection to trace cleaning. Attack targets, attack purposes, information collection methods, finding entry points into target systems, payload delivery, data filtering, etc. can all be classified as tactical indicators. "Techniques" refer to the various techniques used by the attacker to achieve the attack goal in specific events, aiming to break through defenses, maintain C2 (Command and Control) communication, move laterally, obtain information, data, etc. The "process" means that when the attacker plans an operation, they cannot rely solely on careful tactics and excellent techniques, but also need carefully planned tactical actions to achieve the goal, and the goal is to restore the attack path containing tactical information. Further, through the analysis of the malicious behavior gene pool and raw data, 19 observable states are summarized, such as the behavior of DRKV (delete_registry_kev_value) to delete key registry information, CKO (create-kernel-object): the behavior of creating a kernel object, CP (create_process): the behavior of creating a file, MMP (modify_memory_property), etc. These observable states all come from the gene pool of malicious behavior genes and do not contain gene segment attribute information. To ensure the computable attributes of observable states, only the action names at the gene tails are retained to construct observable sequences. The 19 observable states form an observable state set, which are connected to each other in chronological order to form an observable state chain, representing a series of actions completed by the attacker during this period. After encoding historical attack behaviors and inputting them into a graph neural network for training, an attack path prediction model is established to determine the APT attack path and predict the next APT activity.
[0075] Finally, through the target similarity detection method, the decoy most similar to the predicted next attack target is identified, guiding the attack to migrate to this decoy to attract the attacker to detect, attack, and exploit it.
[0076] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, making equivalent substitutions or changes, shall be covered by the protection scope of the present invention.
Claims
1. A method for perceiving and inducing network attacks, characterized in that, It includes the following steps: Step 101: Obtain the APT malware gene model, analyze the behaviors generated during the operation of the malware to obtain the malware gene sequence, summarize the malware gene sequences to obtain the malware gene dataset, classify the malware gene dataset, and construct the APT family gene library; Step 102: Obtain the APT family gene library, classify and extract the APT family gene library, use similarity calculation, and construct the malicious behavior chain in chronological order to obtain the APT malicious behavior gene library; Step 103: Obtain the APT malicious behavior gene library, identify the APT attack behavior, construct the state set of the attack path, distinguish two types of states, the hidden state and the observable state, establish the attack path prediction model, determine the APT attack path and predict the next APT activity; Step 104: Identify the decoy most similar to the predicted next attack target through the target similarity detection method, guide the attack to migrate to the decoy, and attract the attacker to attack the decoy.
2. The network attack perception and induction method according to claim 1, characterized in that: The APT malware gene model in Step 101 is used to describe and analyze the characteristics, behaviors, and evolution methods of APT malware; In the model, the malware is defined as an entity with genetic characteristics, whose characteristics and functions are regarded as "genes", and the "genes" represent the core components of the malware, including but not limited to its code structure, propagation mechanism, evasion techniques, target selection strategies, and C&C communication protocols.
3. A network attack perception and induction method according to claim 2, characterized in that: The key elements of the gene model are specifically as follows: Gene sequence: Corresponding to the specific functional code block or behavior pattern of the malware, specifically encryption algorithms, vulnerability exploitation codes, and persistence mechanisms; Mutation and evolution: APT malware evades detection by modifying and recombining its gene sequences, developing new evasion techniques or enhancing existing functions; Family similarity: Malware of the same APT organization or series shares similar gene characteristics, enabling security researchers to trace and classify different malware samples into the corresponding families; Genome analysis: Through in-depth analysis of malware samples, extract their gene characteristics, construct the gene map of the malware, and help identify unknown threats and predict future variants of the malware; Immune countermeasures: Develop targeted defense strategies and tools based on the gene model; Among them, The gene model is represented by a five-tuple, Gene = <MD5, env., obj1, obj2, action>, where MD5 represents the malware name, env. is the software running environment, obj1 and obj2 respectively represent the objects and paths of the software execution actions, and action represents the execution action of the malware; Obtain the behaviors generated during the operation of the malware, extract and arrange them in chronological order according to the gene model, describe the malware behaviors using the gene sequence to obtain the malware gene sequence, and summarize the malware gene sequences to obtain the malware gene dataset; Classify the malware gene dataset, aggregate the malware gene datasets belonging to the same APT family to obtain the gene library of the APT family.
4. A network attack perception and induction method according to claim 1, characterized in that: In step 101, the malware gene dataset is classified, and the malware gene datasets belonging to the same APT family are grouped to obtain a set result dataset; The set result dataset is optimized by screening and removing duplicate malware gene datasets, malware gene datasets containing invalid information, and highly similar malware gene datasets; The optimized malware gene dataset is retained to obtain the gene library of the APT family.
5. A network attack perception and induction method according to claim 1, characterized in that: The APT malicious behavior gene library in step 102 is a database or knowledge base storing APT attack features, behavior patterns, malware samples and their variant information; The APT malicious behavior gene library is specifically as follows: Attack feature code: Unique code fragments or behavior patterns that can identify specific APT attacks or malware families; Behavior pattern: Tactics, techniques and processes of APT attacks; Malware sample: Samples of malware used in known APT attacks, including various variants and versions thereof; IOC: Including domain names, IP addresses, file hash values, used to detect and respond to known APT activities; Threat intelligence: Background information about the attacker's motivation, target, known activity time and geographical distribution; Analysis report: In-depth analysis report of a specific APT attack case, including detailed descriptions of the attack path, tools and techniques used; The specific steps are as follows: (1) Obtain the APT family gene library, extract the malware gene sequences in the APT family gene library for similarity calculation; (2) Select highly similar malware gene sequences and construct a malicious behavior chain in chronological order; (3) Adopt a gene similarity detection algorithm to calculate the similarity between gene libraries, between samples, and between samples and gene libraries, and extract malicious behavior genes to identify the current attack behavior; (4) Obtain the APT malicious behavior gene library.
6. The network attack perception and induction method according to claim 1, wherein: The attack path prediction model in step 103 is constructed based on the improved KGAT model. Through the proposed weight training strategy, the search space required for attack path reasoning is reduced, the path explosion problem is solved, and the reasoning efficiency is improved. Combining the continuity and relevance between attack events, an attack path prediction model is proposed. For the possible attack paths in the scenario network, a method combining graph attention mechanism and knowledge graph reasoning is used to explore and form. For the weight parameter w required for establishing the path prediction model, an adaptive weight learning strategy based on attack benefit and attack cost is proposed, aiming to find the optimal solution of the weight parameter w from the perspective of the attacker by combining the current network state and vulnerability information; Specifically as follows: Generation of the weight parameter w. To make the information used in subsequent attack reasoning more focused, from the perspective of the attacker, the severity, exploitation cost, and benefit after exploitation provided by the attributes in the vulnerability entity are used for subsequent adaptive learning of the weight parameter w; For vulnerabilities and attacks, different weights are assigned to each vulnerability according to the severity of the vulnerability; through the adaptive weight learning strategy, appropriate weights can be assigned to each vulnerability, thus providing support for the reasoning of the attack path; Re-representation of node features. In knowledge graph reasoning, node embeddings are used for the semantic information of nodes. Different neighbor nodes are aggregated into the feature representation of the node according to the obtained weight parameters above for re-representation of node features. The updated node features aggregate their surrounding information using different weights; Attack path prediction. The model uses the Path_Ranking random walk algorithm to predict the possible types of attacks that a node may be subjected to based on the result of the re-representation of node features. After completing the attack prediction, the query function of the graph database is used to form an attack path by associating attacks with the start and end entities and the relationship path between them as conditions, based on the vulnerabilities exploited by the attacks and the pre- and post-conditions of the attacks; Improvement and optimization of the KGAT model. Aiming at the problems of large search scope and path explosion caused by the large number of hosts and vulnerabilities in the scenario network, the KGAT model is correspondingly improved and innovated by combining the semantic features of network attacks. The KGAT model is elaborated in detail from two aspects: principle and optimization improvement of the model.
7. A network attack perception induction method according to claim 6, characterized in that: The improvement and optimization of the KGAT model are as follows: (1) Breaking symmetry. By sampling neighbors of nodes, the learning algorithm sees different subsets of nodes, so that different nodes in the graph have different representations; For the knowledge graph constructed in the present invention, a graph attention network is used for graph representation learning; in GAT, the representation vector of each node is a combination of its own features and the features of neighbor nodes, so the symmetry is broken by sampling neighbors; Specifically, for each node i, the update formula in GAT is as follows: Among them, h i is the representation vector of node i at the first layer, W0 is the weight matrix of the i-th layer, σ is the activation function, represents the set of neighbors of node i in this formula, and is the normalization factor to prevent the node degree from having too much influence on the representation vector; in order to break the symmetry or equivalence between nodes, a neighbor sampling operation needs to be introduced into the formula, that is, randomly sample a certain number of nodes S from h i and then perform a weighted average on the representation vectors of these nodes Among them, S is the sampling amount; by sampling neighbors, it is ensured that each node can see different subsets of neighbors, thus avoiding symmetry or equivalence between nodes; (2) Designing multi-head attention. Multiple attention heads are adopted, and each head learns different weight assignments. In the multi-head attention mechanism, the input vector is first mapped to different vector spaces by multiple linear mapping layers, and then operations with a single-head attention mechanism are performed in each vector space. Finally, the results in different vector spaces are concatenated as the final output vector; Thus, a new representation of node feature vectors is obtained. These vectors not only contain the features of the nodes themselves, but also are given different weights according to the features of different types of nodes and relationships around them. Subsequently, the updated node feature representations above are used to perform attack prediction and attack path generation using the Path_Ranking algorithm.
8. A network attack perception and induction method according to claim 1, characterized in that: In step 104, attract the attacker to detect, attack, and exploit the decoy; When the attacker attempts to invade, scan, attack, and exploit the decoy, record the attacker's behavior and collect key attack information, such as the attack source IP address, attack method, tools used, and vulnerability exploitation method.
Citation Information
Patent Citations
Network attack induction method and device based on honeypot of Internet of Things
CN114157450A
Virtual node and honeypot combined trapping attack method, device and system
CN114499915A
Trapping deployment method based on power monitoring system network attack
CN114915493A
Cited By
System optimization method and device, electronic equipment, storage medium and program
CN120803877A
System optimization method, device, electronic equipment, storage medium and program
CN120803877B
APT attack active defense method based on four-honey system
CN121037132A
Multi-view small sample Android malicious software classification method based on optimal guide matching
CN121744010A