Attack path reasoning method based on attack technique and tactics score
By constructing a malicious behavior traceability map and combining attack technology and tactical scores, the problem of insufficient quantitative evaluation in traditional APT attack path inference is solved, and more accurate attack path identification and false alarm rate reduction are achieved, improving the accuracy of security decisions.
Patent Information
- Application Number
- CN202510488225.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-08
AI Technical Summary
Traditional APT attack path inference methods lack quantitative evaluation of potential attack paths, making it difficult to describe the causal relationship between attack events, and the existing technology ignores the characteristics of key nodes in the traceability graph, resulting in poor detection results.
Using a method based on attack technology and tactical scoring, a malicious behavior traceability map is constructed, combined with an attack technology sequence pattern tree, the edges in the traceability map are scored, and the total score of candidate attack paths is calculated based on node inclusion and departure and timestamp information to achieve accurate attack path inference.
It realizes more accurate attack path reasoning, reduces the false alarm rate of threat detection system, and improves the decision-making and handling efficiency of security personnel.
Smart Images

Figure CN120281548A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to artificial intelligence and network security technologies, and particularly to a method for inferring attack paths. Background Art
[0002] Modern network attackers usually adopt host-based attack methods, such as program attacks, malware implantation, etc. Among them, APT attack detection researchers usually use the rich context information in the data source of the traceability graph to detect threats in the host. The traceability graph is a directed acyclic graph constructed from system audit data. The nodes in it represent system entities, such as processes and files, and the edges represent system call events in the information flow direction. However, traditional research methods usually focus on the characteristics of the entire traceability graph, but lack attention to the quantity and detailed characteristics of threat-related entities, making it difficult to achieve good detection effects. Through node-level detection of the traceability graph and combining APT path inference with scoring rules, extracting features at the node level can better help analyze the threat possibilities in the traceability graph, and the scoring of event edges in the graph helps to better evaluate potential attack paths in the traceability graph.
[0003] Traditional APT attack path inference usually relies on the experience of experts and prior rules, lacking an overall quantitative evaluation of potential attack paths. It is prone to deviation for subjectivity and cannot provide a quantitative scoring standard to support decision-making. Especially in the traceability graph, for the identification of multiple potential paths and the ranking of priorities, it is very likely to miss key paths or overestimate the threat of a certain path, resulting in problems such as ambiguous priorities.
[0004] Moreover, existing path inference technologies are not very sensitive to the causal relationship and time sequence between events, making it difficult to depict the causal relationship between attack events, thus affecting the accuracy and efficiency of traceability. Existing technologies are often formulated according to known attack patterns and behaviors, often ignoring the characteristics of key nodes in the traceability graph, namely attributes such as the TTP type to which the node belongs and the in-degree and out-degree information of the node. However, by comparing the similarity and correlation between the TTP types to which the nodes belong, the implicit association between event edges can be found, and the in-degree and out-degree (activity frequency) of the node can reflect its activity level and importance, which can better quantify the weight of event edges. When searching for potential attack paths in the subsequent graph, it provides an accurate and objective judgment standard, so as to more accurately and quickly extract suspicious attack paths in the traceability graph. Summary of the Invention
[0005] To achieve more accurate attack path inference and reduce the alarm fatigue problem caused by a large number of false alarms in existing threat detection systems, the invention proposes an attack path inference method based on attack technique and tactic scoring, which combines attack techniques and tactics to obtain attack paths with higher information content, and can better support the decision-making and handling of security personnel.
[0006] The technical solution adopted by the present invention to solve its technical problems is as follows: An attack path inference method based on attack technique and tactic scoring, referring to Figure 1 , includes the following steps: (1) Malicious behavior traceability graph construction: Construct an original traceability graph based on system log data, detect abnormal nodes from it, identify the attack techniques and tactics of the abnormal nodes, and finally form a malicious behavior traceability graph by retaining the abnormal nodes.
[0007] (2) Attack technique sequence pattern extraction: Extract attack technique sequences from a large amount of threat intelligence and construct an attack technique sequence pattern tree.
[0008] (3) Edge scoring of the malicious behavior traceability graph: Considering both attack tactics and techniques, score each edge in the malicious behavior traceability graph.
[0009] (4) Attack path inference based on the malicious behavior traceability graph: Based on the edge scores, sample candidate attack paths, and on this basis, calculate the total score of the entire candidate attack path by combining information such as node in-degree, out-degree, and timestamp to achieve the screening of attack paths.
[0010] Further, in the step (1), the construction of the malicious behavior traceability graph depends on the NOI detection and node-level TTP type detection methods, and the steps are as follows: Construct an initial traceability graph: Given the collected system log data SLD, construct an initial traceability graph ITG = (IV, IE), where IV is the node set of the initial traceability graph, and each node iv k represents a system entity (such as a process, a file); IE is the edge set of the initial traceability graph, and each edge ie k represents a system event ie k = ( u k , v k , t k , e k ), where the four components are the source node, the target node, the timestamp, and the event type, and both the source node and the target node come from IV.
[0011] (1-2) Malicious node detection: First, calculate the characteristics of the nodes in the initial traceability graph ITG (such as the distribution of neighbor node types, out-degree, in-degree), and use iForest to train an anomaly detection model. Then, use the trained anomaly detection model to detect the nodes in ITG to obtain a list of abnormal nodes.
[0012] (1-3) Identification of abnormal node attack techniques and tactics: First, use the existing ATT&CK attack technique and tactic identification rule base (such as HOLMES) to identify the attack techniques for each abnormal node, and record the identification results in the attributes of the abnormal node. For example, if the attack technique identification result for a certain abnormal node is T1203, then the attack technique attribute tech_type of this abnormal node = T1203. Then, associate the attack tactics corresponding to the node attack techniques. For example, the attack tactic attribute tac_type of the above abnormal node = Execution.
[0013] (1-4) Construction of malicious behavior traceability graph: Retain all abnormal nodes in ITG to obtain the node set MV. For any two abnormal nodes av i and av j , if av i and av j have an edge in ITG, then retain this edge; if av i and av j do not have an edge in ITG, but av i and av j are reachable in ITG, and there are no other abnormal nodes in the path, then create an edge for av i and av j according to the direction of the path. Finally, obtain the edge set ME. Then the malicious behavior traceability graph MTG = (MV, ME).
[0014] Furthermore, in step (2), the extraction of the attack technique sequence pattern is implemented based on the prefix tree technique, and the steps are as follows: (2-1) Extraction of attack technique and tactic sequences: Given a threat intelligence with ATT&CK attack technique descriptions D k , use the regular expression "T\d{4}" to identify the ATT&CK attack technique numbers and organize them into an attack technique sequence in order. Extract for all threat intellences to obtain the attack technique sequence library TES .
[0015] (2-2) Construction of the attack technique sequence pattern tree: First, create a root node to initialize the attack technique sequence pattern tree TecTree . Then, for each attack technique sequence TES in tes k , in the currentTecTree Search in it. If tes k Any prefix of cannot match TecTree Any branch in, then tes k Is inserted as a new branch under the root node; if tes k A certain prefix of can match TecTree A certain branch in, then tes k The part removing this prefix is inserted at the end of this branch, Figure 3 Give an example.
[0016] Furthermore, in step (3), for an edge of the malicious behavior traceability graph me = ( u , v ), the malicious behavior traceability graph edge scoring includes two parts: attack tactic scoring and attack technique scoring. The steps are as follows: (3-1) Attack tactic scoring: ATT&CK currently contains 14 attack tactics (as Figure 4 shown). Although the attacker does not necessarily execute these attack tactics strictly in sequence, there is still a sequential relationship among them. For example, after the attacker executes the attack tactic "Initial Access", it does not necessarily execute the adjacent attack tactic "Execution", but usually executes the attack tactics arranged behind "Initial Access" (such as "Lateral Movement"). Based on this idea, the specific steps of attack tactic scoring are as follows: Construct a tactic list, given a benchmark score C. Assume that the attack tactics to which the abnormal nodes u and v in the edge me = (u, v) belong are u.tac_type = TAu and v.tac_type = TAv respectively. If TAu and TAv are the same or adjacent attack tactics, the score is C; if TAu and TAv are not adjacent but conform to the sequential relationship, the score is gradually reduced according to their distance in the list; if TAu and TAv are not adjacent and do not conform to the sequential relationship, the lowest score is uniformly given. Denote the attack tactic score of the edge me as taScore(u, v).
[0017] (3-2) Attack technique scoring: The number of attack techniques included in ATT&CK is large and complex, and it is difficult to pre-define a scoring rule table. Therefore, use the attack technique sequence pattern tree TecTree obtained in step (2-2) to assist in scoring.
[0018] (3-3) Total score calculation: The total score of the edge me is score ( u, v ) = taScore ( u , v ) + teScore ( u , v ). The weights of the two scoring rules can be changed by adjusting the benchmark scores of the attack tactic score and the attack technique score.
[0019] In step (3-2), the attack technique score builds an attack technique sequence pattern tree TecTree , assuming the edge me = ( u , v ), the attack techniques to which the abnormal nodes u , v belong are respectively u .tech_type = TE u , v .tech_type = TE v , and the steps are as follows: (3-2-1) Starting from the root node, traverse using the depth-first search algorithm TecTree .
[0020] (3-2-2) If the current branch successively searches for TE u node and TE v node, then calculate the attack technique score of the current branch. The specific method is: given the benchmark score B, if there are 0 or 1 nodes between TE u and TE v in this branch, the score is B; if there are 2 or 3 nodes between TE u and TE v in this branch, the score is 0.8B; if there are 4 or 5 nodes between TE u and TE v in this branch, the score is 0.6B; if there are more than 5 nodes between TE u and TE v in this branch, the score is 0.4B.
[0021] (3-2-3) After traversing all branches, take the branch with the highest score as the attack technique score of the edge me , denoted as teScore (u , v )。
[0022] Furthermore, step (4) combines step (3) and information such as the in-degree and out-degree of nodes and timestamps, and infers the attack path based on the malicious behavior traceability graph. The steps are as follows: (4-1) Sampling of candidate attack paths: For each leaf node with an out-degree of 0 in the malicious behavior traceability graph MTG, based on the graph traversal algorithm, trace back forward along the reverse direction of the edge, and each time select the edge with the highest total score for backtracking until a leaf node with an in-degree of 0 is traced back, forming a candidate attack path. Denote the set of all candidate attack paths obtained by backtracking all leaf nodes with an out-degree of 0 as CPS . An example is given.
[0023] (4-2) Attack path inference: For each candidate attack path CPS in cp k , calculate its suspiciousness score cScore ( cp k ).
[0024] For step (4-2) above, calculate the path suspiciousness score. The steps are as follows: (4-2-1) Calculation of node influence score: Based on formula (1), calculate the influence score cp k of each node iv i in the attack path impact i . In formula (1), piv i is the parent node of iv i in cp k , and children ( piv i ) is the set of child nodes of node piv i in the original traceability graph.
[0025] In formula (2), impactE (∙) is the influence score function of the edge, pu is the parent node of u , ie ( u , v ). t is from node u to vThe timestamps of the edges, η To prevent the denominator from being 0, the idea is: for a node u The time it generates and the node v The closer the generation times are, the higher the correlation between the two events, and the higher the influence score.
[0026] In formula (3), Oc ( u ) is the diffusion score of node u . The idea is: if the number of incoming edges of node u is u . indegree Much greater than the number of outgoing edges u . outdegree , it is considered that u Obtains a large amount of information from other nodes and centrally affects ie ( u , v ) through the edge, then the diffusion score is high. v ( Ic ) is the diffusion score of node v . The idea is: if the number of incoming edges of node v is v Much less than the number of outgoing edges v . indegree , it is considered that v . outdegree , it is considered that v Is highly dependent on u , and widely affects other nodes with this dependence, then the diffusion score is high.
[0027] (4-2-2) Calculation of the technical and tactical score of a node: Based on formula (4), calculate the technical and tactical score cp k of each node iv i in the attack path score i . Among them, piv i is iv i in cp k 's parent node. (4-2-3) Suspiciousness score of candidate paths: For each candidate attack path CPS in cp k , calculate its suspiciousness score cScore ( cp k ) based on formula (5). Among them, ei is cp k a node in α and β is a weight parameter, score i is e i the technical and tactical score of impact i is e i the influence score of (4 - 2 - 4) Malicious path screening: Retain candidate paths with a suspicion score higher than a predefined threshold as real attack paths.
[0028] The beneficial effects of the present invention are mainly manifested in: (1) achieving more accurate attack path reasoning; (2) reducing the alarm fatigue problem caused by a large number of false alarms in existing threat detection systems; (3) obtaining higher attack path information content by combining attack techniques and tactics, which can better support the decision - making and handling of security personnel. Description of the Drawings
[0029] Figure 1 is a flow chart of an APT attack path reasoning method based on attack technique and tactic scores; Figure 2 is an example of edge creation during the construction of a malicious behavior traceability graph (NOI refers to an abnormal node); Figure 3 is an example of an attack technique score; Figure 4 is an example of candidate attack path search based on a malicious behavior traceability graph. Detailed Embodiment
[0030] The present invention will be further described below with reference to the accompanying drawings.
[0031] Referring to Figures 1 - 4 , an attack path reasoning method based on attack technique and tactic scores includes the following steps: (1) Malicious behavior traceability graph construction: Construct an original traceability graph based on system log data, detect abnormal nodes from it, identify the attack techniques and tactics of the abnormal nodes, and finally form a malicious behavior traceability graph by retaining the abnormal nodes.
[0032] (2) Attack technique sequence pattern extraction: Extract attack technique sequences from a large amount of threat intelligence and construct an attack technique sequence pattern tree.
[0033] (3) Malicious behavior traceability graph edge scoring: Score each edge in the malicious behavior traceability graph by comprehensively considering attack tactics and attack techniques.
[0034] (4) Attack path reasoning based on the malicious behavior traceability graph: Sampling of candidate attack paths is realized based on edge scoring. On this basis, the total score of the entire candidate attack path is calculated by combining information such as node in-degree, out-degree, and timestamp to realize the screening of attack paths.
[0035] Refer to Figure 2 , in the step (1), all abnormal nodes are retained in the construction process of the malicious behavior traceability graph and the traceability graph is streamlined. The steps are as follows: Construct the initial traceability graph: Given the collected system log data SLD, construct the initial traceability graph ITG = (IV, IE), where IV is the node set of the initial traceability graph, and each node iv k represents a system entity (such as a process, a file); IE is the edge set of the initial traceability graph, and each edge ie k represents a system event ie k = ( u k , v k , t k , e k ), where the four components are the source node, the target node, the timestamp, and the event type, and both the source node and the target node come from IV.
[0036] (1-2) Malicious node detection: First, calculate the characteristics of the nodes in the initial traceability graph ITG (such as the distribution of neighbor node types, out-degree, in-degree), and use iForest to train the anomaly detection model. Then, use the trained anomaly detection model to detect the nodes in ITG to obtain a list of abnormal nodes.
[0037] (1-3) Identification of attack techniques and tactics for abnormal nodes: First, use the existing ATT&CK attack technique and tactic identification rule library (such as HOLMES) to identify the attack techniques for each abnormal node, and record the identification results in the attributes of the abnormal nodes. For example, if the attack technique identification result for an abnormal node is T1203, then the attack technique attribute tech_type of this abnormal node = T1203. Then, associate the attack tactics corresponding to the node attack techniques. For example, the attack tactic attribute tac_type of the above abnormal node = Execution.
[0038] (1-4) Construction of the malicious behavior traceability graph: Retain all abnormal nodes in ITG to obtain the node set MV. For any two abnormal nodes av i and av j , ifav i and av j If there is an edge in the ITG, then keep this edge; if av i and av j there is no edge in the ITG, but av i and av j it is reachable in the ITG and there are no other abnormal nodes in the path, then create an edge according to the direction of the path for av i and av j Finally, obtain the edge set ME. Then the malicious behavior traceability graph MTG = (MV, ME), and an example of edge creation in the malicious behavior traceability graph is as Figure 2 shown.
[0039] In the above step (2), the extraction of the attack technology sequence pattern is implemented based on the prefix tree technology, and the steps are as follows: (2-1) Attack technique and tactic sequence extraction: Given a threat intelligence with ATT&CK attack technology descriptions D k , use the regular expression "T\d{4}" to identify the ATT&CK attack technology numbers and organize them into an attack technology sequence in order. Extract from all threat intellences to obtain the attack technology sequence library TES .
[0040] (2-2) Construction of the attack technology sequence pattern tree: First, create a root node to initialize the attack technology sequence pattern tree TecTree . Then, for TES each attack technology sequence tes k in TecTree , search in the current tes k . If no prefix of TecTree can match any branch in tes k , then insert tes k as a new branch under the root node; if a certain prefix of TecTree can match a certain branch in tes k , then insert the part of
[0041] after removing this prefix at the end of this branch. TES The following gives an example: Assume that tes 1= [T1583] [T1059] [T1587] [T1566] [T1608] [T1204], tes 2 = [T1583] [T1584] [T1587] [T1189] [T1105] [T1588] [T1608], tes 3 = [T1583] [T1560] [T1005] [T1030] [T1568] [T1105], tes 4 = [T1071] [T1584] [T1587] [T1573] [T1190] [T1056] [T1095] [T1505], where [T1583], [T1059], [T1587], etc. are attack technology numbers, then the constructed attack technology sequence pattern tree TecTree process.
[0042] Refer to Figure 3 , Figure 3 In Case 1: The TEu node and the TEV node can be searched in the branch, and the benchmark score of 0.8B is given according to the scoring rule. In Case 2: The TEu node and the TEv node cannot be searched in the branch, and no benchmark score is given. In step (3), for the attack and tactical technology scoring steps are as follows: (3 - 1) Attack tactic scoring: ATT&CK currently contains 14 attack tactics. Although an attacker does not necessarily execute these attack tactics strictly in sequence, there is still a sequence relationship among them. For example, after an attacker executes the attack tactic "Initial Access", they do not necessarily execute the adjacent attack tactic "Execution", but usually execute the attack tactics arranged after "Initial Access" (such as "Lateral Movement"). Based on this idea, the specific steps of attack tactic scoring are: Given the benchmark score C, assume the edge me = ( u ,v ) The abnormal nodes u , v The respective attack tactics to which they belong are u .tac_type = TA u , v .tac_type = TA v . If TA u and TA v are the same or adjacent attack tactics, the score is C; if TA u and TA v are not adjacent but conform to the sequential relationship, the score is gradually reduced according to their distance in the list; if TA u and TA v are not adjacent and do not conform to the sequential relationship, the lowest score is uniformly given. Denote the attack tactic score of edge me as taScore ( u , v ).
[0043] (3-2) Attack technique scoring: The number of attack techniques included in ATT&CK is large and complex, and it is difficult to pre-define a scoring rule table. Therefore, use the attack technique sequence pattern tree TecTree obtained in step (2-2) to assist in scoring. Assume that in edge me =( u , v ) the abnormal nodes u , v The respective attack techniques to which they belong are u .tech_type = TE u , v .tech_type = TE v . The specific steps for attack technique scoring are as follows: (3-2-1) Starting from the root node, traverse using the depth-first search algorithm TecTree .
[0044] (3-2-2) If the current branch sequentially searches for TE u node and TE v node, then calculate the attack technique score of the current branch. The specific method is: Given a reference score B, if in this branch TE u andTE v contains 0 or 1 node, the score is B; if in this branch TE u and TE v contains 2 or 3 nodes, the score is 0.8B; if in this branch TE u and TE v contains 4 or 5 nodes, the score is 0.6B; if in this branch TE u and TE v contains more than 5 nodes, the score is 0.4B.
[0045] (3 - 2 - 3) After traversing all branches, take the branch with the highest score as the attack technology score of the edge me , denoted as teScore ( u , v ). The following gives an example (as shown in Figure 3 ): Given the attack technology sequence pattern tree TecTree 1 (where A, B, C,... represent attack technology numbers), for the edge me = ( u , v ), and the attack technologies to which the abnormal nodes u , v belong are respectively u .tech_type = TE u , v .tech_type = TE v , in the attack technology sequence pattern tree TecTree 1, during the scoring, when traversing to the branch A B TE u K ... TE v search for TE u and TE v , and TE u and TE v contains 5 nodes, the score is 0.6B, when traversing to the branch F TE u N ... TE v searched in TE u and TE v and TE u and TE v There are 3 nodes between them, with a score of 0.8B. Select the highest score of 0.8B as the edge me = ( u , v ) for the attack technology score. Similarly, given the attack technology sequence pattern tree TecTree 2, since after traversing all branches, TE u and TE v cannot be searched in any branch, the score is 0.
[0046] (3-3) Total score calculation: The total score of edge me is score ( u , v ) = taScore ( u , v ) + teScore ( u , v ). The weights of the two scoring rules can be changed by adjusting the benchmark scores of the attack tactic score and the attack technology score.
[0047] Refer to Figure 4 , Figure 4 is the malicious behavior traceability graph MTG. The red path in the graph is the suspicious path searched by the malicious traceability graph. In step (4), the candidate attack path search steps based on the malicious behavior traceability graph are as follows: (4-1) Candidate attack path sampling: For each leaf node with an out-degree of 0 in the malicious behavior traceability graph MTG, based on the graph traversal algorithm, trace back forward along the reverse direction of the edge, and each time select the edge with the highest total score for backtracking until a leaf node with an in-degree of 0 is traced back, forming a candidate attack path. Denote the set of all candidate attack paths obtained by backtracking all leaf nodes with an out-degree of 0 as CPS. An example is given: For a malicious behavior tracing graph MTG, there are a total of 13 malicious nodes, namely mv1, mv2, mv3,..., mv13, and the malicious event edges between each two nodes have been edge-scored according to step (3). First, find three leaf nodes (i.e., the nodes mv3, mv11, mv13 with out-degree 0); perform reverse forward tracing on these leaf nodes respectively. For the leaf node mv3, it has only one source node mv2, and for mv2, it has only one source node mv1. So, an attack path sp1 = mv1 is constructed mv2 mv3. For the leaf node mv11, it has three source nodes, namely mv4, mv7, and mv9. Select the source node mv7 with the highest edge score and perform forward tracing. For mv7, it has only the source node mv5, for mv5, it has only the source node mv2, and for mv2, it has only the source node mv1. So, the constructed attack path is sp2 = mv1 mv2 mv5 mv7 mv11. For the leaf node mv13, it has three source nodes, namely mv12, mv10, and mv8. The corresponding source node with the highest edge score is mv10. Select mv10 and perform forward tracing. For mv10, it has 2 source nodes, namely mv9 and mv5. The corresponding source node with the highest edge score is mv9. Select mv9 and perform forward tracing. For mv9, it has only the source node mv7, for mv7, it has only the source node mv5, for mv5, it has only the source node mv2, and for mv2, it has only the source node mv1. The constructed attack path is sp3 = mv1 mv2 mv5 mv7 mv9 mv10 mv13. Finally, add these three attack paths to the candidate attack path set CPS in.
[0048] (4-2) Attack path reasoning: For CPS each candidate attack path in cp k , calculate its suspiciousness score according to the following steps cScore ( cp k ).
[0049] (4-2-1) Node influence score calculation: Based on formula (1), calculate each node in the attack path cp k iv i Influence score impact i 。 In formula (1), piv i is iv i in cp k the parent node of, children ( piv i ) is the set of child nodes of node piv i in the original traceability graph.
[0050] In formula (2), impactE (∙) is the influence score function of the edge, pu is u the parent node of, ie ( u , v ). t is the timestamp of the edge from node u to v , which is used to prevent the denominator from being zero. The idea is that the closer the generation time of node η and the generation time of node u , the higher the correlation between the two events, and the higher the influence score. v
[0051] In formula (3), Oc ( u ) is the diffusion score of node u . The idea is that if the number of incoming edges of node u u . indegree is much larger than the number of outgoing edges u . outdegree , it is considered that u obtains a large amount of information from other nodes and centrally influences ie ( u , v ) v , then the diffusion score is high. Ic ( v ) is the diffusion score of node v . The idea is that if the number of incoming edges of node v v . indegree is much smaller than the number of outgoing edges v . outdegree , it is considered that v is highly dependent on u If this dependency widely affects other nodes, the diffusion score is high.
[0052] (4-2-2) Calculation of node technical and tactical scores: Based on formula (4), calculate the technical and tactical scores of each node cp k in iv i the attack path. score i . Among them, piv i is iv i the parent node of cp k in. (4-2-3) Suspect score of candidate path: For each candidate attack path CPS in cp k , calculate its suspect score based on formula (5) cScore ( cp k ). Among them, e i is cp k a node in α , β are weight parameters, score i is e i the technical and tactical score of impact i , e i is the influence score of (4-2-4) Screening of malicious paths: Retain the candidate paths with suspect scores higher than the predefined threshold as the real attack paths.
Claims
1. An attack path inference method based on attack technique and tactics scoring, characterized in that Extract attack technique and tactic sequence patterns using the ATT&CK knowledge base framework, construct a threat degree scoring rule for the traceability graph, and better perform the attack path reasoning work. The method includes the following steps: (1) Construction of malicious behavior traceability graph: Construct an original traceability graph based on system log data, detect abnormal nodes from it, identify the attack techniques and tactics of the abnormal nodes, and finally form a malicious behavior traceability graph by retaining the abnormal nodes; (2) Extraction of attack technique sequence patterns: Extract attack technique sequences from a large amount of threat intelligence and construct an attack technique sequence pattern tree; (3) Edge scoring of malicious behavior traceability graph: Comprehensively consider attack tactics and attack techniques to score each edge in the malicious behavior traceability graph; (4) Attack path reasoning based on malicious behavior traceability graph: Implement sampling of candidate attack paths based on edge scoring, and on this basis, calculate the total score of the entire candidate attack path by combining information such as node in-degree, out-degree, and timestamp to implement the screening of attack paths.
2. The attack path inference method based on attack technique and tactic scoring according to claim 1, wherein Extract attack technique and tactic sequence patterns using the ATT&CK knowledge base framework, construct a threat degree scoring rule for the traceability graph, and better perform the attack path reasoning work. In step (1) above, the construction of the malicious behavior traceability graph depends on the NOI detection and node-level TTP type detection methods. The steps are as follows: Construct the initial traceability graph: Given the collected system log data SLD, construct the initial traceability graph ITG = (IV, IE), where IV is the node set of the initial traceability graph, and each node iv k represents a system entity; IE is the edge set of the initial traceability graph, and each edge ie k represents a system event ie k = ([[]] u k , v k , t k , e k ), where the four components are the source node, the target node, the timestamp, and the event type, and both the source node and the target node come from IV; (1-2) Malicious node detection: First, calculate the characteristics of the nodes in the initial traceability graph ITG, and use iForest to train an anomaly detection model. Then, use the trained anomaly detection model to detect the nodes in ITG to obtain a list of abnormal nodes; (1-3) Identification of attack techniques and tactics of abnormal nodes: First, use the existing ATT&CK attack technique and tactic identification rule library to identify the attack techniques of each abnormal node, and record the identification results in the attributes of the abnormal nodes. If the attack technique identification result of a certain abnormal node is T1203, then the attack technique attribute tech_type of this abnormal node = T1203. Then, associate the attack tactics corresponding to the node attack techniques. The attack tactic attribute tac_type of the above abnormal node = Execution; (1-4) Malicious behavior traceability graph construction: Retain all abnormal nodes in ITG to obtain the node set MV. For any two abnormal nodes av i and av j , if av i and av j have an edge in ITG, then retain this edge; if av i and av j do not have an edge in ITG, but av i and av j are reachable in ITG, and there are no other abnormal nodes in the path, then create an edge for av i and av j according to the direction of the path. Finally, obtain the edge set ME, then the malicious behavior traceability graph MTG = (MV, ME).
3. The attack path inference method based on attack technique and tactic scoring according to claim 1, wherein Extract attack technique and tactic sequence patterns using the ATT&CK knowledge base framework, construct a threat degree scoring rule for the traceability graph, and better perform the attack path reasoning work. In step (2) above, the extraction of attack technique sequence patterns is implemented based on the prefix tree technique. The steps are as follows: (2-1) Attack Technique and Tactics Sequence Extraction: Given threat intelligence with ATT&CK attack technique descriptions D k , use the regular expression "T\d{4}" to identify ATT&CK attack technique numbers, organize them into an attack technique sequence in order, extract all threat intelligence, and obtain an attack technique sequence library TES ; (2-2) Construction of the attack technology sequence pattern tree: First, create a root node to initialize the attack technology sequence pattern tree TecTree , then, for each attack technology sequence TES in tes k , search in the current TecTree . If no prefix of tes k can match any branch in TecTree , then insert tes k as a new branch under the root node; if a certain prefix of tes k can match a certain branch in TecTree , then insert the part of tes k after removing this prefix at the end of this branch.
4. The attack path inference method based on attack technique and tactics scoring according to claim 1, characterized in that Extract the attack technique and tactic sequence pattern using the ATT&CK knowledge base framework, construct the threat degree scoring rules for the traceability graph, and better perform the attack path reasoning work. In step (3), for an edge in the malicious behavior traceability graph me = ( u , v ), the edge scoring of the malicious behavior traceability graph includes two parts: attack tactic scoring and attack technique scoring. The steps are as follows: (3-1) Attack Tactics Scoring: ATT&CK currently contains 14 attack tactics. Although attackers do not necessarily execute these attack tactics strictly in sequence, there is still a sequential relationship among them. After an attacker executes the attack tactic "InitialAccess", they do not necessarily execute the adjacent attack tactic "Execution", but usually execute the attack tactics arranged after "InitialAccess". The specific steps for attack tactics scoring are as follows: Construct a tactics list, given a benchmark score C. Assume that the attack tactics to which the abnormal nodes u and v in the edge me = (u, v) belong are u.tac_type = TAu and v.tac_type = TAv respectively. If TAu and TAv are the same or adjacent attack tactics, the score is C; if TAu and TAv are not adjacent but conform to the sequential relationship, the score is gradually reduced according to their distance in the list; if TAu and TAv are not adjacent and do not conform to the sequential relationship, the lowest score is uniformly given, and the attack tactic score of the edge me is denoted as taScore(u, v). (3-2) Attack technique scoring: There are a large number of complex attack techniques included in ATT&CK, and it is difficult to pre-define a scoring rule table. Therefore, the attack technique sequence pattern tree obtained in step (2-2) TecTree is used to assist in scoring; (3-3) Total score calculation: side me The total score of score ( u , v ) = taScore ( u , v ) + teScore ( u , v ). The weights of the two scoring rules can be changed by adjusting the benchmark scores of the attack tactics score and the attack technique score.
5. The attack path inference method based on attack technique and tactics scoring according to claim 4, characterized in that Extract the attack technique and tactic sequence patterns using the ATT&CK knowledge base framework, construct the threat degree scoring rules for the traceability graph, and better perform the attack path inference work. In step (3-2), an attack technique scoring is used to establish an attack technique sequence pattern tree TecTree , assuming the edge me = ([[]] u , v ), the abnormal nodes u 、 v belong to the attack techniques u .tech_type = TE u 、 v .tech_type= TE v , then the detailed steps are as follows: (3-2-1) Starting from the root node, traverse using the depth-first search algorithm TecTree ; (3-2-2) If the current branch searches for TE u nodes and TE v nodes successively, calculate the attack technology score of the current branch. The specific method is as follows: Given a reference score B, if there are TE u and TE v with 0 or 1 node between them in this branch, the score is B; if there are TE u and TE v with 2 or 3 nodes between them in this branch, the score is 0.8B; if there are TE u and TE v with 4 or 5 nodes between them in this branch, the score is 0.6B; if there are TE u and TE v with more than 5 nodes between them in this branch, the score is 0.4B; (3-2-3) After traversing all branches, use the branch with the highest score as the attack technology score of the edge me and denote it as teScore ( u , v ).
6. The attack path inference method based on attack technique and tactic scoring according to claim 1, characterized in that Extract the attack technique and tactic sequence pattern using the ATT&CK knowledge base framework, construct the threat degree scoring rule for the traceability graph, and better perform the attack path reasoning work. The steps of the attack path reasoning based on the malicious behavior traceability graph in step (4) are as follows: (4-1) Candidate Attack Path Sampling: For each leaf node with an out-degree of 0 in the malicious behavior traceability graph MTG, based on the graph traversal algorithm, trace back forward along the reverse direction of the edge, and each time select the edge with the highest total score for backtracking until a leaf node with an in-degree of 0 is traced back, forming a candidate attack path. Denote the set of all candidate attack paths obtained by backtracking all leaf nodes with an out-degree of 0 as CPS ; (4-2) Attack path reasoning: For CPS each candidate attack path in cp k , calculate its suspiciousness score cScore ( cp k ).
7. The attack path inference method based on attack technique and tactic scoring according to claim 6, characterized in that Extract the attack technique and tactic sequence pattern using the ATT&CK knowledge base framework, construct the threat degree scoring rule for the traceability graph, and better perform the attack path reasoning work. The steps of calculating the path suspiciousness score in step (4-2) are as follows: (4-2-1) Node influence score calculation: Based on formula (1), calculate the influence score of each node in the attack path cp k in iv i the attack path impact i , In formula (1), piv i is iv i the cp k parent node in children ( piv i ) is the set of child nodes of node piv i in the original traceability graph, In formula (2), impactE (∙) is the influence score function of the edge, pu is u the parent node of ie ( u , v ). t is the timestamp of the edge from node u to v . η is used to prevent the denominator from being zero. The idea is that the closer the generation time of node u and the generation time of node v , the higher the correlation between the two events, and the higher the influence score. In formula (3), Oc ( u ) is the diffusion degree score of node u . The idea is that if the number of incoming edges of node u u . indegree is much greater than the number of outgoing edges u . outdegree , it is considered that u obtains a large amount of information from other nodes and centrally affects ie ( u , v ) through the edge, then the diffusion degree score is high. v Ic ( v ) is the diffusion degree score of node v . The idea is that if the number of incoming edges of node v v . indegree is much less than the number of outgoing edges v . outdegree , it is considered that v is highly dependent on u and widely affects other nodes with this dependence, then the diffusion degree score is high. (4-2-2) Node Technical and Tactical Score Calculation: Based on formula (4), calculate the technical and tactical scores of each node cp k in the attack path iv i where score i is the parent node of piv i in iv i ; cp k (4-2-3) Candidate Path Suspectability Scoring: For CPS each candidate attack path in cp k , calculate its suspectability score based on formula (5) cScore ( cp k ), where e i is cp k a node in α , β are weight parameters, score i is e i 's technical and tactical score, impact i is e i 's influence score, (4-2-4) Malicious Path Screening: Retain the candidate paths with suspiciousness scores higher than the predefined threshold as the real attack paths.
Citation Information
Cited By
Electric power monitoring system based on artificial intelligence
CN120602236A
Information system APT attack process tracing method and system and medium
CN121309222A
An information system APT attack process tracing method, system and medium
CN121309222B