Supervision method applied to network security emergency linkage system

By analyzing the viral vector characteristics and graph neural networks of the system's threat attack path, a multi-dimensional feature extraction and virus database are built, which solves the problem of low accuracy in camouflage attachment detection, and improves the accuracy of virus scanning and response efficiency.

CN120281569AInactive Publication Date: 2025-07-08SICHUAN AEROSPACE POLYTECHNIC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510747811.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When facing camouflage attachments, the existing network security emergency linkage system has low detection accuracy and reliability, making it difficult to effectively identify malicious files, resulting in false alarms or missed reports, affecting the system's response efficiency.

Method used

By analyzing the viral vector characteristics of the system's threat attack path, combining graph neural network algorithms, multi-dimensional feature extraction and virus databases are built, camouflage attachment forms are identified, virus evasion mechanisms are located, and multi-dimensional feature fusion and directed graph topology analysis are used to achieve accurate positioning of camouflage attachments and improved the accuracy of virus scanning.

Benefits of technology

It improves the accuracy of virus scanning, reduces false alarms and missed reports, enhances the response efficiency and reliability of the network security emergency linkage system, and can detect known viruses and new and variant malicious programs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281569A_ABST
    Figure CN120281569A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security supervision, and discloses a supervision method applied to a network security emergency linkage system, which comprises the following steps of: determining data damage and deletion time of a system threatening an attack path by monitoring network traffic abnormity in real time and capturing the attack path and data damage behavior of an invasion virus; analyzing a virus propagation path and variation characteristics, and determining an infection range; determining a virus escape mechanism in combination with data corruption and deletion time and an infection range; constructing a multi-dimensional virus feature database, and identifying a disguise attachment form of a virus in a storage medium; positioning a malicious file storage position based on an attack target, a disguise form and an escape mechanism; and the accuracy of the existing virus scanning rule is evaluated through missing report / false report analysis. Through the closed-loop process of attack path tracing, dynamic behavior analysis, intelligent feature matching and defense effect verification, the response speed of the system to novel virus and variant attacks is remarkably improved, and the overall protection reliability is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security supervision, and in particular to a supervision method applied to a network security emergency linkage system. Background Art

[0002] In a network security emergency linkage system, the application of a supervision method aims to improve the detection and response efficiency for network attacks, malicious file propagation, and abnormal behaviors. By performing real-time monitoring and analysis on network traffic, file transfers, and system operations, potential threats can be quickly identified, and a linkage mechanism can be triggered for emergency response. Such systems usually combine multiple security technologies, such as intrusion detection systems (IDS), antivirus software, behavior analysis tools, etc., to ensure the security of the network environment. However, with the continuous evolution of network attack methods, especially when attackers use camouflage techniques for malicious file propagation, traditional virus scanning mechanisms face great challenges.

[0003] Camouflaged attachments are an important hidden danger in network security. Attackers often modify file extensions, encrypt file contents, or disguise themselves as legitimate files to avoid detection by traditional security tools. For example, malicious programs may disguise themselves as pictures, documents, or software update packages, and even hide through compressed files, making it difficult for standard virus scanning and file analysis methods to accurately identify these malicious attachments. Especially in large-scale distribution and diverse attacks, the use of camouflage techniques makes it difficult for malicious files to be effectively detected through a single signature library or file fingerprint recognition method, resulting in detection blind spots and vulnerabilities.

[0004] The main problem caused by such camouflaged attachments is that although existing dynamic balance virus scanning and supervision methods can detect known malicious behaviors and files to a certain extent, due to the diversity and complexity of file camouflage, the accuracy and reliability of the system are very low. Especially during real-time scanning, the camouflage of malicious attachments often bypasses detection methods based on signature matching, resulting in false positives or false negatives, thereby affecting the response efficiency of the entire network security emergency linkage system. Since malicious files can lurk in seemingly normal files, the accuracy of virus scanning is greatly limited, and the security of the system cannot be fully guaranteed. Summary of the Invention

[0005] In order to overcome the deficiencies of the prior art, the present invention provides a supervision method applied to a network security emergency linkage system, and the network security supervision method can fully guarantee the security of the network system.

[0006] The present invention proposes a supervision method applied to a network security emergency linkage system, including the following steps executed by the network security emergency linkage system: S100. When the network security emergency linkage system detects abnormal traffic, it captures the attack path information corresponding to different protocols and ports in the network and defines it as the system threat attack path; integrates the intrusion virus information on the system threat attack path as the system threat data, and determines the time node of data corruption or deletion on the system threat attack path by analyzing the virus carrier characteristics on the system threat attack path; S200. Analyze the virus behavior characteristics and variant code structure of the system threat data, and screen out paths that are different from the protocols or ports of the system threat attack path but have similar propagation efficiency and have temporal correlation within a preset time window as the same category of attack paths; determine the infection range of the system threat data according to the system threat attack path and the same category of attack paths of the system threat data; S300. Statistically analyze the time of data corruption and deletion of the system threat attack path and the time of data corruption and deletion of the same category of attack paths, and analyze the virus attack timing fingerprint in combination with the infection range, so as to identify the virus evasion mechanism of the system threat data based on the analysis of the virus attack timing fingerprint; S400. Extract multi-dimensional features of the intrusion virus information and construct multiple virus databases; divide the protection range for each virus database and capture the virus variant characteristics through a dynamic update mechanism; calculate the disguised attachment form of the system threat data in combination with the virus storage medium characteristics of the virus database and the protection rules of the virus database.

[0007] Furthermore, it also includes S500. Based on the statistics of the virus database: the infection targets of the viruses matching the system threat data in the system threat attack path, and use the graph neural network algorithm to obtain the attack targets of the system threat data; combine the attack targets, disguised attachment form and virus evasion mechanism characteristics of the system threat data to locate the target storage location of the system threat data and obtain the target disguised attachment storage location of the system threat data; judge the virus scanning accuracy of the network security emergency linkage system according to the accuracy result of the storage location of the target disguised attachment.

[0008] The present invention has the following beneficial effects: The present invention proposes a supervision method applied to a network security emergency linkage system. By locally analyzing intrusion virus information, the time of data corruption and deletion is determined based on system threat data and the categories of network virus carriers with different protocols and ports. Based on the standard impedance analysis technology, by constructing a multi-point impedance mean calculation model, the interference of random impedance fluctuations to the detection accuracy of disguised attachments can be effectively suppressed. Combining the time of data corruption and deletion of the system threat attack path, the infection range of the system threat data, and the time of data corruption and deletion of all attack paths of the same category, the virus evasion mechanism of the system threat data is determined. The method can analyze all attack paths of the same category locally from multiple angles, so as to obtain a more reliable virus evasion mechanism. By extracting signal features, different virus types to be supervised are analyzed to obtain the disguised attachment form of the system threat attack path. Furthermore, a three-dimensional correlation model of attack vector-disguised feature-evasion mechanism is constructed to fuse multi-dimensional features of the attack target, disguised attachment form, and virus evasion mechanism. By analyzing the access characteristics of file storage nodes in the threat propagation path through the directed graph topology analysis algorithm, high-risk storage paths with hidden storage characteristics are determined, and accurate positioning of disguised attachment storage nodes in the system threat attack path is achieved. The present invention can judge the virus scanning accuracy of the network security emergency linkage system according to the storage location of the target disguised attachment, improve the accuracy of virus scanning within different protocols and ports. The present invention can effectively improve the attack path recognition effect and enhance the security and accuracy of network supervision. Compared with the traditional virus scanning method relying on the feature library, this supervision method can not only detect known viruses, but also detect new and variant malicious programs through abnormal behaviors or abnormal signs of file structures. In addition, combined with the graph neural network algorithm, complex and changeable attack means can be analyzed more effectively. This detailed analysis method greatly enhances the detection ability of the system in the face of disguised attachments, improves the accuracy of virus scanning, reduces the occurrence of false positives and false negatives, and further enhances the response efficiency and reliability of the network security emergency linkage system. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The drawings described herein are used to provide a further understanding of the embodiments of the present invention, form a part of this application, and do not limit the embodiments of the present invention. In the drawings: Figure 1 It is a flowchart of a supervision method applied to a network security emergency linkage system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0010] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0011] As Figure 1 shown, to understand the supervision method applied to the network security emergency linkage system disclosed in the embodiments of the present application, in this embodiment, the network security emergency linkage system may be a system running based on one or more computer devices through a computer-readable medium; the method is executed by the network security emergency linkage system: S100. When the network security emergency linkage system detects abnormal traffic, it captures the attack path information corresponding to different protocols and ports in the network, and defines it as the system threat attack path; integrates the intrusion virus information on the system threat attack path as the system threat data, and determines the time node of data corruption or deletion of the system threat attack path by analyzing the virus carrier characteristics on the system threat attack path.

[0012] Exemplarily, in some application scenarios, the center point of the network security emergency linkage system can be determined, and the intrusion virus situation of the center point of the network security emergency linkage system during abnormal traffic is collected to obtain the intrusion virus information.

[0013] Exemplarily, the network security emergency linkage system arbitrarily selects an attack path from the cycles matched by the extracted intrusion virus information as the system threat attack path, and the intrusion virus information of the system threat attack path is used as the system threat data. Then, the system threat attack path and the system threat data are analyzed to traverse all the intrusion virus information and achieve the overall analysis of the intrusion virus information.

[0014] Furthermore, considering that the attack path usually has the characteristic of large local fluctuations.

[0015] Therefore, the time of data corruption and deletion of the system threat attack path can be determined according to the system threat data and the categories of network virus carriers of different protocols and ports, which may include: using the categories of network virus carriers of different protocols and ports as the reference matching information; counting the feature matching degrees between the system threat data and each reference matching information; and taking the attack time of the virus with the highest feature matching degree as the time of data corruption and deletion of the system threat attack path.

[0016] For example, the category of the network virus carrier on the path of the system threat attack path at different protocols and ports is used as the reference matching information. When the system threat attack path is an endpoint at different protocols and ports, the reference matching information for matching is two data of the same category of endpoints; when the system threat attack path is not an endpoint at different protocols and ports, the reference matching information for matching is the data matched by the attack paths of the same category on the left and right of the system threat attack path. The data of the system threat attack path is locally analyzed through the reference matching information, and then the time of data corruption and deletion of the system threat attack path is analyzed.

[0017] Combined with the above example, S100 can be implemented through the following steps: S110. Monitor traffic information in real time and check whether there is a traffic anomaly.

[0018] S120. Intercept the intrusion virus information when the traffic is abnormal.

[0019] S130. Use the attack paths at different protocols and ports when the traffic is abnormal as the system threat attack path, and the intrusion virus information on the system threat attack path as the system threat data.

[0020] S140. Use the category of the network virus carrier at different protocols and ports as the reference matching information.

[0021] S150. Calculate the feature matching degree between the system threat data and each reference matching information respectively.

[0022] S160. Use the attack time of the virus with the highest feature matching degree as the time of data corruption and deletion of the system threat attack path.

[0023] Thus, by statistically calculating the feature matching degree between the system threat data and each reference matching information respectively; using the virus attack time with the highest feature matching degree as the time of data corruption and deletion of the system threat attack path, by statistically calculating the system threat data and performing feature matching with the reference information, the matching degree between the current state of the system and the normal reference state can be calculated, and then the time of virus attack can be inferred. When the feature matching degree is relatively high, it indicates that the system may be attacked, and the time node of virus intrusion is determined. Subsequently, this attack time is used as the key node of the subsequent attack path to mark the time of data corruption or deletion, helping to track virus behavior and analyze data destruction and trace clearing during the attack.

[0024] Moreover, the time distribution characteristics of data corruption and deletion operations have a strong correlation with the file storage location in the attack path, and can also characterize the probability of the existence of disguised attachments in this path. Therefore, the longer the cumulative time of data corruption and deletion, the greater the possibility that the system threat data is the data of the attack path.

[0025] S200. Analyze the virus behavior characteristics and variant code structures of the system threat data, and screen out paths that are different from the protocols or ports of the system threat attack paths but have similar propagation efficiencies and have temporal correlations within a preset time window as the same category of attack paths; determine the infection scope of the system threat data based on the system threat attack paths and the same category of attack paths of the system threat data.

[0026] In some embodiments, the infection scope of the system threat attack path can be determined according to the virus activation and variant conditions in the transmission media of the system threat attack path and the same category of attack paths. Correspondingly, S200 specifically includes: S210. Input the system threat data into a virus behavior recognition model based on sandbox dynamic analysis, and extract the virus activation trigger conditions and variant evolution characteristics by monitoring system call sequences such as registry modification and process injection.

[0027] S220. Screen out paths in the network that are different from the protocols or ports of the system threat attack paths but have similar propagation efficiencies as the same category of attack paths.

[0028] S230. Determine the infection scope of the system threat data based on the system threat attack paths and the same category of attack paths of the system threat data. Among them, the virus activation and variant conditions can be determined by means of script file filtering, that is, perform script file filtering processing on the intrusion virus information to obtain the virus activation and variant conditions. And use paths with the same efficiency of spreading network virus vectors as the system threat attack paths on different protocols and ports as the same category of attack paths.

[0029] Specifically, it includes: counting the virus activation and variant conditions of the system threat data, the transmission media information on the system threat attack paths and the same category of attack paths, and determining the infection scope of the system threat attack paths by analyzing this information. In this way, by analyzing the virus behavior characteristics and variant code structures of the system threat data, screen out paths that are different from the protocols or ports of the system threat attack paths but have similar propagation efficiencies as the same category of attack paths. Determine the infection scope of the system threat data based on the system threat attack paths and the same category of attack paths of the system threat data.

[0030] S300. Count the time of data corruption and deletion on the system threat attack paths and the time of data corruption and deletion on the same category of attack paths, and analyze the virus attack timing fingerprint in combination with the infection scope to identify the virus evasion mechanism of the system threat data based on the analysis of the virus attack timing fingerprint.

[0031] Specifically, based on the time of data corruption and deletion in the system threat attack path and the infection range, the propagation trajectory and attack behavior of the virus in the system can be inferred.

[0032] Thus, in some embodiments, S300 includes: S310. By counting the time of data corruption and deletion in the system threat attack path and the time of data corruption and deletion in the attack paths of the same category.

[0033] S320 combines the infection range to analyze the virus attack timing fingerprint and identify the virus evasion mechanism of the system threat data, including: S321. Conduct a time series analysis on the script files of the virus in the attack paths of the same category, and extract the time characteristics of its data corruption or deletion operations as the disguised attachment index. For example, count the average value of the cumulative duration of data corruption and deletion of the intrusion virus information in the attack paths of the same category and the script files of the system threat data as the disguised attachment index; count the fine-grained virus attack time of the disguised attachment index and the infection range as the disguised attachment form.

[0034] S322. Combine the infection range of the system threat data to analyze the virus attack timing fingerprint. Specifically, use a clustering algorithm in the time series to analyze the temporal correlation between the disguised attachment index and the infection range, and establish a fine-grained attack time model to obtain the disguised attachment form. S323. Obtain the directed graph model of the disguised attachment form, the time of data corruption and deletion, and the virus evasion mechanism, input the disguised attachment form into the directed graph model, and obtain the virus evasion mechanism of the system threat data based on the mapping relationship of the directed graph model.

[0035] There is a one-to-many relationship between the attack target and the target disguised attachment storage location of the system threat data. Input the disguised attachment form and the virus evasion mechanism into the directed graph model to obtain the target disguised attachment storage location of the system threat data, and the target disguised attachment storage location is the temporary folder.

[0036] Based on the above example, it can be seen that first, by analyzing the time of data corruption and deletion of each node in the attack path, the key behaviors of the virus during the attack are determined. For example, file destruction, log deletion, etc. These behaviors are usually used to conceal the existence of the virus and avoid detection.

[0037] Secondly, by collecting all the intrusion virus information related to the attack paths of the same category, especially their damage and deletion times, the virus transmission patterns and infection scopes can be further revealed. By comparing the similar behaviors in these attack paths, the common evasion mechanisms of the virus in different paths can be summarized. For example, some viruses may cover up their attack traces by deleting system logs or tampering with file contents at specific time points, or prevent virus detection by encrypting files.

[0038] Thus, by combining this information, the virus evasion mechanisms in the system threat attack paths can be determined, so as to optimize the security protection measures and improve the detection and defense capabilities against virus behaviors.

[0039] It can be understood that a local threat analysis model based on the association between virus behavior characteristics and transmission paths is constructed. By extracting virus activation conditions and variant characteristics, and combining the transmission protocols and script file transmission characteristics of the attack paths of the same category, a feature vector of the infection scope is generated. A dynamic behavior clustering algorithm is used to perform spatio-temporal correlation analysis on the abnormal operation sequences of script files, and the core features representing the local attack surface are extracted through principal component dimensionality reduction, and a dual verification mechanism of protocol type and file operation trajectory is established. Based on the method of this embodiment, by matching the virus behavior fingerprints of the attack paths with the script structure characteristics of the transmission medium, the feature interference caused by disguised attachments can be effectively suppressed, the accurate definition of the local infection scope can be realized, and the reliability of threat analysis in a complex network environment can be improved.

[0040] S400. Extract multi-dimensional features from the intrusion virus information to construct multiple virus databases; divide the protection scope for each virus database, and capture the virus variant characteristics through a dynamic update mechanism; calculate the disguised attachment form of the system threat data in combination with the virus storage medium characteristics of the virus database and the virus database protection rules.

[0041] Among them, the extraction of multi-dimensional features from the intrusion virus information includes: extracting multi-dimensional data such as the protocol features, port features, code fingerprints, and behavior patterns of the intrusion virus.

[0042] Among them, dividing the protection scope for each virus database and capturing the virus variant characteristics through a dynamic update mechanism; calculating the disguised attachment form of the system threat data in combination with the virus storage medium characteristics of the virus database and the virus database protection rules includes: A virus database established based on virus characteristics is divided into a protection scope for each such virus database. The virus characteristics obtained are used to update each virus database to capture virus variant characteristics, and a security level assessment is performed on the protection scope of the virus database to obtain the protection level of the protection scope. Specifically, based on the business importance and historical attack frequency of each server, the protection areas covered by the virus database are divided into security levels to determine their corresponding protection security levels. Among them, the security level value = business importance weight × business impact coefficient + historical attack frequency risk value. The business importance weight: core business = 0.6, key business = 0.3, general business = 0.1. The business impact coefficient is determined by the actual impact degree of the specific business type on the system. The historical attack frequency risk value can be set as follows: high risk = 0.3: the number of attacks in the past 90 days ≥ 5 times. Medium risk = 0.1: the number of attacks in the past 90 days is 2 - 4 times. Low risk = 0: the number of attacks in the past 90 days ≤ 1 time. Among them, the business importance of the server is as follows: core business that will cause system paralysis or major security risks once interrupted, key business that affects some functions of the system but does not directly cause collapse, and general business that has a relatively small impact on the core functions of the system.

[0043] According to the characteristics of all virus storage media and the protection rules of the virus database, the form of a disguised attachment is calculated. Specifically, the characteristics of the virus storage media include: storage location characteristics, file structure characteristics, and data operation characteristics. Among them, the storage location characteristics can be high - risk storage location characteristics, such as the temporary folder. The file structure characteristics can be abnormal extension name disguise or compression package nested levels, etc. The data operation characteristics can be frequent file deletion operations, etc. Specifically, the protection rules of the virus database include: feature matching rules, dynamic behavior analysis rules, and security level and threat assessment rules. Among them, the feature matching rules can be protocol / port feature matching, code fingerprint matching, etc. Among them, the dynamic behavior analysis rules can be modifying the registry to start automatically, spatio - temporal feature analysis, etc. Among them, the security level and threat assessment rules can be the business importance of the server, the intensity of threat hazards, etc. Among them, the calculation of the form of the disguised attachment matches the virus storage media characteristics through regular expressions, combines the known disguise patterns in the protection rule library, generates a feature vector of the form of the disguised attachment, and obtains the form of the disguised attachment.

[0044] More specifically, a threat feature analysis model for constructing a protocol and port combination protection domain is built to dynamically identify potential system threats by matching the abnormal file features of virus vectors recorded in the virus database in the storage medium; a multi-dimensional threat assessment framework is established to conduct a fine-grained correlation analysis of the security levels of each protection area and the intensity of potential threats, forming the dynamic optimization objective of the network security emergency linkage system; based on historical attack time series data, temporal pattern mining is performed on the optimization parameter set, and a mapping model between the propagation characteristics of the disguised attachment and the attack time window is established to achieve the spatio-temporal feature modeling of disguised attacks. Among them, the intensity of potential threats can be calculated using 0.4×protocol abnormality + 0.3×file operation entropy deviation rate + 0.3×storage node risk value. When the intensity is greater than or equal to 0.7, it is classified as a high threat, triggering real-time monitoring and multiple verification mechanisms; when the intensity is between 0.4 and 0.7, it is a medium threat, initiating regular scanning and signature matching upgrades; when the intensity is less than 0.4, it is a low threat, maintaining the conventional detection strategy. Among them, the multi-dimensional threat assessment framework includes a comprehensive threat assessment model formed by determining the weights of each dimension using the Analytic Hierarchy Process (AHP) based on multiple dimensions such as the protocol abnormality of network attacks, file operation entropy value, and storage node risk level.

[0045] In some examples, S400 specifically includes the following steps: S410. Extract multi-dimensional features from the system threat data to obtain the virus features of the system threat data; S420. Establish a hierarchical virus database based on the virus features and divide a protection range for each virus database; S430. Update each virus database according to the obtained virus features to capture virus variant features; evaluate the security level of the protection range of the virus database to obtain the protection level of the protection range; S440. By analyzing the traffic data under different network protocol and port protection strategies, combined with the virus signature library, identify the virus vector types associated with the system threat attack path, and detect the abnormal file features in its storage medium, so as to locate potential threat hazards, set the system threat hazards and the fine-grained protection levels of the protection range as the core optimization objectives of the network security emergency linkage system, and analyze the influence law of the disguised attachment form on the system optimization objectives in each protection range during virus attacks.

[0046] Furthermore, the method further includes: S500. The virus database counts the infection targets of the viruses that match the system threat data in the system threat attack path, and uses the graph neural network algorithm to obtain the attack targets of the system threat data; combine the attack targets of the system threat data, the disguised attachment form, and the virus evasion mechanism features to locate the target storage location of the system threat data, and obtain the target disguised attachment storage location of the system threat data; according to the accuracy result of the storage location of the target disguised attachment, judge the virus scanning accuracy of the network security emergency linkage system.

[0047] Among them, judging the virus scanning accuracy of the network security emergency linkage system according to the accuracy result of the storage location of the target camouflaged attachment includes: According to the matching situation between the storage location of the target camouflaged attachment and the storage location of the actual malicious file, it is divided into 5 different matching types: complete match, directory match, adjacent path match, false alarm, and missed alarm. Weights of 1.0, 0.7, 0.3, -1.0, and -2.0 are given to the samples respectively, and the score of the storage location accuracy is obtained according to the positioning accuracy score = (Σ (matching weight × number of samples)) / total number of test samples × 100%.

[0048] For example, S500 includes the following steps: S510. Through the graph attention network, count the infection targets of viruses in each virus database on different attack paths to obtain the propagation topology map of the virus database.

[0049] S520. Use the multi-head attention mechanism to extract the spatio-temporal features of the network communication script files on each propagation path, and determine the core attack carrier of the intrusion virus as the script cluster whose appearance frequency within a specific time window is higher than the preset threshold, the execution time is regular, or the homologous IP exceeds 70%.

[0050] It can be understood that in the virus scanning accuracy evaluation system, this method innovatively establishes a dynamic mapping model between the attack path characteristics and the scanning efficiency: based on the protocol-port combination characteristics of the attack path and the spatio-temporal distribution pattern of the file storage nodes, a path credibility evaluation index is constructed, and at the same time, the ontology characteristics of the intrusion virus are integrated. Through the random forest classifier, multi-dimensional weight matching is performed on the path characteristics and the virus characteristics to achieve accurate identification of the threat propagation path, ensuring that the analysis result of the virus scanning accuracy not only conforms to the network protocol interaction characteristics but also adapts to the virus behavior pattern, thereby improving the adaptability of the detection mechanism in complex attack scenarios. The specific process is described in the subsequent embodiments.

[0051] To further illustrate the above-mentioned supervision method applied to the network security emergency linkage system, in some embodiments:[[]] Construct a camouflaged attachment recognition model based on the time series complexity, which specifically includes:[[]] Extract the time series of data corruption / deletion operations for attack paths of the same category, calculate the time window overlap degree and the randomness index of operation intervals, and generate time feature complexity parameters; synchronously extract the script file structure features in the system threat data and establish a feature vector for disguised attachments. Through a dynamic weight assignment algorithm, fuse the time feature complexity parameters and the script feature vectors in multiple dimensions to generate a fine-grained disguised attachment index, where the complexity of the time series is positively correlated with the abnormality degree of the script structure. Based on the network protocol interaction features, construct a standard impedance baseline model. When the time fluctuation features of local attack paths form a collaborative verification with the standard impedance deviation value, the system automatically raises the confidence level of disguised attachment determination, realizes the dynamic matching of the attack time window and the file storage features, and ensures the adaptability of the disguised attachment detection mechanism in a complex network environment.

[0052] Subsequently, obtain the virus evasion mechanism according to the form of the disguised attachment and the time of data corruption and deletion. The form of the disguised attachment and the virus evasion mechanism have a directed graph structure relationship, and the time of data corruption and deletion and the virus evasion mechanism have a directed graph structure relationship. In the directed graph, the directed graph structure relationship between the form of the disguised attachment and the virus evasion mechanism describes how the attacker bypasses the virus detection mechanism through the disguised attachment. The form of the disguised attachment can be that malicious files are disguised as seemingly normal files in different ways, such as changing the file extension, encrypting the file content, or hiding malicious code through a compressed package. The virus evasion mechanism refers to the attacker using these disguised attachments to avoid being detected by common security protection measures (such as antivirus software, IDS). Direction: In this directed graph, the form of the disguised attachment can be regarded as the starting point, which points to the virus evasion mechanism through different disguise techniques (such as extension disguise, encryption, compression, etc.). That is, the attacker triggers or supports the virus evasion mechanism through the form of the disguised attachment, increasing the difficulty of detecting malicious code. Relationship: The form of the disguised attachment is a means or strategy of the virus evasion mechanism. The attacker first takes the way of the disguised attachment to hide or confuse the malicious file, and then further ensures that these disguised files are not discovered when being scanned through the virus evasion mechanism, thus completing the spread or execution of the malicious file. Example: A malicious attachment is disguised as a PDF file, but in fact it is an executable file containing malicious scripts. Due to the disguise of the file extension, the antivirus software may ignore it, thus successfully bypassing the virus detection.

[0053] The directed graph structure relationship between the time of data corruption and deletion and the virus evasion mechanism involves the connection between the time of data corruption and deletion and the virus evasion mechanism. Viruses may modify or delete files in the target system during their propagation to prevent them from being discovered or reverse-engineered. Direction: In this directed graph, the time of data corruption and deletion is a node, which describes when the virus affects the target system by modifying or deleting files. The virus evasion mechanism is the other end of this process. The virus evasion mechanism may include quickly destroying or deleting traces after the malicious code is executed to avoid being found by security testers or antivirus software. Relationship: During the virus infection process, the virus hides its existence by corrupting or deleting data (such as deleting log files, covering up infection traces, etc.). This behavior is part of the virus evasion mechanism, which uses means such as disguising, modifying, and deleting data to prevent detection or timely removal. Example: Some ransomware viruses encrypt files after infecting a computer, and at the same time delete the original files or relevant log information to cover up the attack path and attack time of the virus, increasing the difficulty of recovery. This behavior supports the virus evasion mechanism by maliciously deleting and corrupting data, preventing analysis and countermeasures.

[0054] Construct a dynamic analysis model of the virus evasion mechanism based on local attack characteristics, and achieve accurate detection through the following technical processes: Extract the time series characteristics in the form of disguised attachments and the structural characteristics of script files to construct a dynamic behavior feature library. Use the graph diffusion algorithm to perform correlation analysis on adjacent nodes of the system threat attack path, and generate a spatio-temporal correlation map of the local attack area through the collaborative verification mechanism of the file storage location access pattern and network protocol interaction anomalies. This map calculates the path behavior entropy value to dynamically calibrate the storage nodes of high-confidence disguised attachments, and establish a path feature mapping model, enabling the detection mechanism of the network security emergency linkage system to real-time perceive the behavior evolution characteristics of the local attack surface and effectively identify the evasion strategies implemented by the virus through time obfuscation and protocol disguise.

[0055] In S400, signal feature extraction is performed on the system threat data to obtain the virus database of the infected device. Each virus database is set with a protection range, and database updates are performed on each virus database to obtain the virus type; according to the protection range of the virus database and the storage medium of the virus type that matches the network virus carrier of the system threat attack path in the virus database, the disguised attachment form of the system threat attack path is statistically analyzed.

[0056] Specifically, an attack feature analysis model based on the activity of storage nodes is constructed, and the detection optimization of disguised attachments is realized through the following technical associations: During the system operation monitoring process, the access activity of the disguised attachment storage nodes is positively correlated with the attack intensity. Specifically, when the spatio-temporal activity index of the storage node is detected, the system automatically associates and marks two types of threat features - high-frequency intrusion features and covert intrusion features. A dynamic analysis framework is established based on the similarity of protocol clusters and the overlap degree of time windows. Through a two-dimensional evaluation model of file structure abnormality and behavior pattern entropy value, a threat propagation map with path weight distribution is generated. This map dynamically adjusts the detection threshold of disguised attachments through a collaborative verification mechanism of storage node activity and protocol interaction abnormality, enabling the network security emergency linkage system to accurately identify the composite attack patterns of high-frequency encrypted attacks and covert penetration attacks.

[0057] Furthermore, in some embodiments of the present invention, according to the protection scope of the virus database and the storage medium of the virus types matching the network virus carriers in the system threat attack path in the virus database, the disguised attachment forms of the system threat data are statistically analyzed, including: evaluating the security level of the protection scope of the virus database to obtain the protection level of the protection scope; by analyzing the traffic data under different network protocol and port protection strategies, combining with the virus feature library, identifying the virus carrier types associated with the system threat attack path, and detecting the file abnormality features in their storage media, so as to locate potential threat hazards, setting the system threat hazards and the fine-grained protection level of the protection scope as the core optimization objectives of the network security emergency linkage system, and analyzing the influence law of the disguised attachment forms during virus attacks on the system optimization objectives within each protection scope.

[0058] In the embodiments of the present invention, by evaluating the security level of the protection scope of the virus database, the protection level of the protection scope is obtained, so as to retain the information of the virus database with stronger high-frequency information and enhance the reliability of the protection level of the protection scope.

[0059] Construct a dynamic detection optimization model based on risk level linkage, and realize the accurate identification of disguised attachments through the following technical associations: Establish a system threat hazard assessment matrix, including protocol abnormality of the attack path, file operation entropy value, and protection scope level. When the threat hazard index exceeds the dynamic threshold, the system automatically activates a multi-dimensional verification mechanism. This model extracts the protocol interaction features and file structure features of disguised attachments through time window sliding analysis, and generates a detection strategy library with spatio-temporal evolution characteristics, enabling the emergency linkage system to dynamically optimize the detection rules according to the real-time threat situation and improve the recognition accuracy of complex disguise techniques such as cross-protocol penetration and multi-stage attacks.

[0060] System threat hidden dangers refer to the impact hidden dangers of system threat data on the virus database within the matching protection scope. It can be understood that due to the resonance effect of the attack path and the normal intrusion virus frequency, a matching hidden danger attack path will be generated, making the amplitude of the intrusion virus very large, and thus leading to the effect of hidden dangers. Therefore, by analyzing the system threat hidden dangers around the system threat attack path, the impact of the hidden danger attack path can be accurately determined.

[0061] In S500, the virus database counts the infection targets of viruses that match the system threat data in the system threat attack path, and uses the graph neural network algorithm to obtain the attack targets of the system threat data; combining the attack targets of the system threat data, the form of the disguised attachment and the characteristics of the virus evasion mechanism, locate the target storage location of the system threat data; according to the accuracy of the target disguised attachment storage location, judge the virus scanning accuracy of the network security emergency linkage system.

[0062] In some embodiments of the present invention, the attack targets of the intrusion virus information are counted through the infection targets of each virus database in different attack paths. It includes: using the graph neural network to count the infection targets of the viruses in each virus database in different attack paths to obtain the propagation topology map of the virus database; using the graph attention mechanism to extract the spatio-temporal characteristics of the network communication script files on each propagation path, and determining the script cluster with a frequency higher than the preset threshold, a regular execution time or a homologous IP exceeding 70% within a specific time window as the core attack carrier of the intrusion virus.

[0063] The graph neural network algorithm is a well-known algorithm in the art. Using the graph neural network algorithm, the attack targets of the sequence can be counted. Therefore, the present invention uses the graph neural network algorithm to respectively count the propagation topology maps of each virus database, and uses the graph attention mechanism to extract the spatio-temporal characteristics of the network communication script files on each propagation path, and determines the script cluster with a frequency higher than the preset threshold, a regular execution time or a homologous IP exceeding 70% within a specific time window as the core attack carrier of the intrusion virus.

[0064] Of course, in some other embodiments of the present invention, various other possible implementation methods can also be used to determine the attack targets, such as using the method of trend feature extraction to extract the trend features of the intrusion virus information, obtaining the periodic terms, and analyzing the periodic terms, etc., which are not limited herein.

[0065] In some embodiments of the present invention, the relationship between the attack target and the target disguised attachment storage location of the system threat attack path is one-to-many. The form of the disguised attachment, the virus evasion mechanism and the target disguised attachment storage location of the system threat attack path have a directed graph structure relationship, and the target disguised attachment storage location is a temporary folder.

[0066] That is to say, a dynamic association model of virus behavior characteristics based on the directed graph topology is constructed, and threat path analysis is realized through the multiple mapping relationship between the attack target node and the disguised attachment storage node. The weight attribute of the attack target node is dynamically generated based on the number of associated service ports and the access request frequency. When the node weight value exceeds the dynamic threshold, the probability of the disguised attachment corresponding to the node is negatively correlated with the periodic characteristics of the attack traffic. The spatial distribution density of the disguised attachment form node is jointly determined by the file structure complexity and the storage path risk level, and its confidence level is calculated through the dynamic balance mechanism of the in-edge weight and the out-edge density. The virus evasion mechanism is used as the directed edge attribute to connect the source attack target node and the target storage node, forming a multi-edge topology structure. The model updates the directed graph edge weight parameters in real time through the cooperative verification mechanism of the protocol type and the file operation track. When a high-weight attack node is detected to be associated with a low-complexity evasion edge, the storage node degradation strategy is automatically triggered to effectively maintain the dynamic balance of the disguised attachment detection mechanism in complex attack scenarios.

[0067] In the embodiment of the present invention, after obtaining the storage location of the target disguised attachment through statistics, the virus scanning accuracy of the network security emergency linkage system can be analyzed and judged according to the storage location of the target disguised attachment.

[0068] The present invention determines the time of data corruption and deletion by locally analyzing the information of the invading virus and based on the system threat data and the categories of network virus carriers of different protocols and ports. Since the analysis of the standard impedance can adopt the average impedance amount of each surrounding point, the influence of the impedance amount of accidental impedance on the analysis result of the disguised attachment can be reduced. Combining the time of data corruption and deletion, the infection range, and the time of data corruption and deletion of the invading virus information of all the same-category attack paths, the virus evasion mechanism of the system threat data is determined. It can analyze all the same-category attack paths locally from multiple angles, so as to obtain a more reliable detection method for the virus evasion mechanism. Then, an analysis model based on the frequency-domain characteristics of attack behaviors is constructed. For the time-frequency characteristics of high-frequency attack paths, the frequency-domain characteristics of protocol interaction signals are extracted, and a frequency-domain fingerprint library of attack paths is established. By matching the energy distribution of characteristic frequency bands generated by different virus types in the protocol handshake stage and the payload transmission stage, a multi-dimensional feature fusion matrix is constructed in combination with the time-domain characteristics of the attack paths. This model dynamically adjusts the detection sensitivity parameter through the frequency-domain energy threshold, enabling the system to effectively distinguish high-frequency encrypted attacks from covert channel attacks, improving the type recognition accuracy of polymorphic viruses in a complex network environment, and thus obtaining the disguised attachment form of the system threat data. By counting the attack targets of the invading virus information according to the infection targets of each virus database in different attack paths, due to the non-periodic characteristics of the attack paths, and then based on the attack targets, the disguised attachment form, and the virus evasion mechanism, the storage location of the target disguised attachment of the system threat attack path is obtained, enabling the storage location of the target disguised attachment to more accurately represent the disguised attachment situation of the system threat data. Compared with directly using filtering to determine the attack path, the present invention combines the impedance characteristics, frequency characteristics, energy distribution characteristics, and periodic characteristics of local invading viruses to specifically and effectively analyze the disguised attachment situation, realizing the accurate identification of the interference attack path of the network security emergency linkage system. Furthermore, the virus scanning accuracy of the network security emergency linkage system can be judged based on the storage location of the target disguised attachment, improving the analysis effect of the virus scanning accuracy. In summary, the present invention can effectively improve the attack path recognition effect, and further improve the accuracy and reliability of the dynamic balance virus scanning supervision.

[0069] It should be noted that the above sequence of the embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0070] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the key point of each embodiment is to illustrate the differences from other embodiments.

Claims

1. A supervision method applied to a network security emergency response linkage system, characterized in that, Including those performed through a network security emergency response linkage system: S100. When the network security emergency response linkage system detects abnormal traffic, it captures the attack path information corresponding to different protocols and ports in the network and defines it as the system threat attack path; integrates the intrusion virus information on the system threat attack path as system threat data, and determines the time node of data corruption or deletion on the system threat attack path by analyzing the virus carrier characteristics on the system threat attack path. S200. Analyze the virus behavior characteristics and variant code structure of the system threat data, and screen out paths that are different from the protocols or ports of the system threat attack path but have similar propagation efficiency and temporal correlation within a preset time window as the same category of attack paths; determine the infection range of the system threat data based on the system threat attack path and the same category of attack paths of the system threat data. S300. Statistically analyze the time of data corruption and deletion of the system threat attack path and the time of data corruption and deletion of the same category of attack paths, and analyze the virus attack timing fingerprint in combination with the infection range, so as to identify the virus evasion mechanism of the system threat data based on the analyzed virus attack timing fingerprint. S400. Extract multi-dimensional features from the intrusion virus information to construct multiple virus databases; divide the protection range for each virus database, and capture virus variant characteristics through a dynamic update mechanism; calculate the disguised attachment form of the system threat data in combination with the virus storage medium characteristics of the virus database and the protection rules of the virus database.

2. The supervision method applied to the network security emergency linkage system according to claim 1, characterized in that It also includes: S500. The virus database statistically analyzes the infection targets of viruses that match the system threat data in the system threat attack path, and uses a graph neural network algorithm to obtain the attack targets of the system threat data; combines the attack targets, disguised attachment form, and virus evasion mechanism characteristics of the system threat data to locate the target storage location of the system threat data and obtain the target disguised attachment storage location of the system threat data; judge the virus scanning accuracy of the network security emergency response linkage system according to the accuracy result of the storage location of the target disguised attachment.

3. The supervision method applied to the network security emergency linkage system according to claim 1 or 2, characterized in that, The determining the time node of data corruption or deletion on the system threat attack path by analyzing the virus carrier characteristics on the system threat attack path includes: Taking different categories of network virus carriers in paths with different protocols and ports as reference matching information; calculating the feature matching degree between the system threat data and each piece of reference matching information through cosine similarity; taking the attack time of the virus with the highest feature matching degree as the time of data corruption or deletion on the system threat attack path.

4. The supervision method applied to the network security emergency linkage system according to claim 1 or 2, characterized in that, The determining the infection range of the system threat data based on the system threat attack path and the same category of attack paths of the system threat data includes: Count the virus activation and variant conditions of the system threat data, the system threat attack path, and the transmission medium information on the same category of attack paths, and determine the infection range of the system threat attack path by analyzing this information.

5. A supervision method applied to a network security emergency linkage system according to claim 1 or 2, characterized in that, Analyze the virus attack timing fingerprint in combination with the infection range to identify the virus evasion mechanism of the system threat data based on the analysis of the virus attack timing fingerprint, including: Perform time series analysis on the script files of the viruses in the same category of attack paths, extract the time characteristics of their data corruption or deletion operations as the disguised attachment metrics; use the clustering algorithm on the time series to analyze the temporal correlation between the disguised attachment metrics and the infection range, establish a fine-grained attack time model to obtain the disguised attachment form; thus obtain the directed graph model of the disguised attachment form, the time of data corruption and deletion, and the virus evasion mechanism, and obtain the virus evasion mechanism according to the directed graph model.

6. A supervision method applied to a network security emergency linkage system as claimed in claim 1 or 2, characterized in that, Divide the protection range for each virus database and capture virus variant characteristics through a dynamic update mechanism; combine the virus storage medium characteristics of the virus database and the protection rules of the virus database to calculate the disguised attachment form of the system threat data, including: Based on the business importance of each server and the historical attack frequency, divide the security levels of the protection areas covered by the virus database to determine their corresponding protection security levels; Construct a threat feature analysis model for the protocol and port combination protection domain, dynamically identify system threat hidden dangers by matching the abnormal file characteristics of the virus carriers recorded in the virus database in the storage medium; establish a multi-dimensional threat assessment framework, conduct fine-grained correlation analysis on the security levels of each protection area and the intensity of threat hidden dangers to form the dynamic optimization goal of the network security emergency linkage system; based on the historical attack time series data, perform temporal pattern mining on the optimization parameter set, establish a mapping model between the propagation characteristics of the disguised attachment and the attack time window, and realize the spatio-temporal feature modeling of the disguised attack.

7. The supervision method for a network security emergency linkage system according to claim 2, wherein The virus database counts the infection targets of the viruses that match the system threat data in the system threat attack path, and uses the graph neural network algorithm to obtain the attack targets of the system threat data, including: Use the graph neural network to count the infection targets of the viruses in each virus database on different attack paths to obtain the propagation topology map of the virus database; use the graph attention mechanism to extract the spatio-temporal characteristics of the network communication script files on each propagation path, and determine the script cluster with a frequency higher than the preset threshold, a regular execution time, or a homologous IP exceeding 70% within a specific time window as the core attack carrier of the invading virus.

8. A supervision method applied to a network security emergency linkage system according to claim 2, characterized in that, The relationship between the attack target and the storage location of the target disguised attachment of the system threat data is one-to-many, and the relationship between the disguised attachment form, the virus evasion mechanism, and the storage location of the target disguised attachment of the system threat data is a directed graph structure, and the storage location of the target disguised attachment is the temporary folder.

Citation Information

Patent Citations

  • Automatic analysis method for fine-grained malicious behaviors in Internet of Things malicious software

    CN117610001A

  • Virus monitoring and early warning method based on deep analysis of network traffic

    CN119583215A

  • Method and system for collecting network security threat information

    CN119743335A

  • EDR-oriented traceability model and behavior chain storage mechanism thereof

    CN119995955A